StackRadar

CVE-2025-26465

Medium

Advisory

Published 18 Feb 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.077
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
306
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 306 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4, 1:7.2p2-4ubuntu2.6, 1:7.2p2-4ubuntu2.7+34 more1:7.2p2-4ubuntu2.10+esm7, 1:7.6p1-4ubuntu0.7+esm4, 1:8.2p1-4ubuntu0.12, 1:8.2p1-4ubuntu0.fips.0.12+5 more265
opensshapk9.3_p1-r3, 9.3_p2-r0, 9.3_p2-r1, 9.3_p2-r2+5 more9.3_p2-r3, 9.6_p1-r2, 9.7_p1-r5, 9.9_p2-r028
opensshrpm8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8, 8.0p1-15.el8_6.3+5 more0:8.0p1-26.el8_10, 0:8.7p1-38.el9_4.5, 0:8.7p1-45.el913
OSV records
ALPINE-CVE-2025-26465DEBIAN-CVE-2025-26465RHSA-2025:16823RHSA-2025:3837RHSA-2025:6993UBUNTU-CVE-2025-26465DLA-4057-1
Also known as
DSA-5868-1, USN-7270-1, USN-7270-2

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5

Open the chart page →

14,358
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4

Open the chart page →

3,392
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

9,397
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11

Open the chart page →

14,100
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

1,838

Container images carrying it

306 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
openssh@8.0p1-9.el8
0:8.0p1-26.el8_10
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
registry.gitlab.com/vicamo/docker-sshd/sshd:3.0-stable22c33d693fe2
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.