StackRadar

CVE-2025-26465

Medium

Advisory

Published 18 Feb 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.077
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,787 indexed, latest versions
Container images
307
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 308 of 17,787 indexed charts deploy, on 307 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4, 1:7.2p2-4ubuntu2.6, 1:7.2p2-4ubuntu2.7+34 more1:7.2p2-4ubuntu2.10+esm7, 1:7.6p1-4ubuntu0.7+esm4, 1:8.2p1-4ubuntu0.12, 1:8.2p1-4ubuntu0.fips.0.12+5 more266
opensshapk9.3_p1-r3, 9.3_p2-r0, 9.3_p2-r1, 9.3_p2-r2+5 more9.3_p2-r3, 9.6_p1-r2, 9.7_p1-r5, 9.9_p2-r028
opensshrpm8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8, 8.0p1-15.el8_6.3+5 more0:8.0p1-26.el8_10, 0:8.7p1-38.el9_4.5, 0:8.7p1-45.el913
OSV records
ALPINE-CVE-2025-26465DEBIAN-CVE-2025-26465RHSA-2025:16823RHSA-2025:3837RHSA-2025:6993UBUNTU-CVE-2025-26465DLA-4057-1
Also known as
DSA-5868-1, USN-7270-1, USN-7270-2

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
openssh@9.6_p1-r0
9.6_p1-r2

Open the chart page →

2,806
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5

Open the chart page →

14,358
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4

Open the chart page →

3,392
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

9,397
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11

Open the chart page →

14,100
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

1,838

Container images carrying it

307 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u5
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
openssh@9.9_p1-r2
9.9_p2-r0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
openssh@9.3_p2-r0
9.3_p2-r3
1
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
openssh@9.3_p2-r2
9.3_p2-r3
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
openssh@1:8.2p1-4ubuntu0.4
1:8.2p1-4ubuntu0.12
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
openssh@1:9.6p1-3ubuntu13.3
1:9.6p1-3ubuntu13.8
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u5
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
openssh@9.3_p2-r0
9.3_p2-r3
1
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u5
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u5
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u5
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u5
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.11
1
quay.io/aerokube/keygen:1.0.1578934444f04
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.11
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
openssh@8.7p1-38.el9_4.4
0:8.7p1-38.el9_4.5
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.11
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
openssh@1:9.6p1-3ubuntu13.11
1:9.6p1-3ubuntu13.12+Fips1
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.11
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
openssh@8.0p1-6.el8_4.2
0:8.0p1-26.el8_10
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
openssh@8.0p1-19.el8_8
0:8.0p1-26.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
openssh@8.0p1-6.el8_4.2
0:8.0p1-26.el8_10
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
openssh@8.0p1-4.el8_1
0:8.0p1-26.el8_10
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
openssh@8.0p1-25.el8_10
0:8.0p1-26.el8_10
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
openssh@8.0p1-15.el8_6.3
0:8.0p1-26.el8_10
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openssh@1:7.2p2-4ubuntu2.10
1:7.2p2-4ubuntu2.10+esm7
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
openssh@8.7p1-38.el9
0:8.7p1-38.el9_4.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.