StackRadar

CVE-2025-26465

Medium

Advisory

Published 18 Feb 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.077
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
306
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 306 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4, 1:7.2p2-4ubuntu2.6, 1:7.2p2-4ubuntu2.7+34 more1:7.2p2-4ubuntu2.10+esm7, 1:7.6p1-4ubuntu0.7+esm4, 1:8.2p1-4ubuntu0.12, 1:8.2p1-4ubuntu0.fips.0.12+5 more265
opensshapk9.3_p1-r3, 9.3_p2-r0, 9.3_p2-r1, 9.3_p2-r2+5 more9.3_p2-r3, 9.6_p1-r2, 9.7_p1-r5, 9.9_p2-r028
opensshrpm8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8, 8.0p1-15.el8_6.3+5 more0:8.0p1-26.el8_10, 0:8.7p1-38.el9_4.5, 0:8.7p1-45.el913
OSV records
ALPINE-CVE-2025-26465DEBIAN-CVE-2025-26465RHSA-2025:16823RHSA-2025:3837RHSA-2025:6993UBUNTU-CVE-2025-26465DLA-4057-1
Also known as
DSA-5868-1, USN-7270-1, USN-7270-2

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5

Open the chart page →

14,358
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4

Open the chart page →

3,392
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

9,397
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11

Open the chart page →

14,100
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

1,838

Container images carrying it

306 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm7
11
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm7
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u5
6
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm7
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm7
4
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssh@1:8.9p1-3ubuntu0.16
no fix listed
4
library/docker:20.10-dind:20-dindaf96c680a7e1
openssh@9.3_p1-r3
9.3_p2-r3
3
quay.io/devtron/ai-agent:0.0.16545dac92173
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssh@1:8.9p1-3ubuntu0.1
1:8.9p1-3ubuntu0.11
3
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
2
dtzar/helm-kubectl:3.14.455429449408e
openssh@9.6_p1-r0
9.6_p1-r2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u5
2
library/python:3.7eedf63967cdb
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
openssh@1:8.2p1-4ubuntu0.1
1:8.2p1-4ubuntu0.12
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u5
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
openssh@1:7.2p2-4ubuntu2.7
1:7.2p2-4ubuntu2.10+esm7
2
pecan/bety:5.4.1f825d480cd62
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.11
2
uffizzi/controller:latest0344805f267b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
2
yzhou442/equiz:latesta3f7ca69e28d
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
openssh@1:9.6p1-3ubuntu13.11
1:9.6p1-3ubuntu13.12+Fips1
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.11
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssh@1:9.6p1-3ubuntu13.9
1:9.6p1-3ubuntu13.12+Fips1
2
1dev/server:11.9.0cd5b12fe5471
openssh@1:9.6p1-3ubuntu13.11
1:9.6p1-3ubuntu13.12+Fips1
1
aboogie/login_test_backend:new9c41a4483ac8
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
activepieces/activepieces:0.23.0c26188b44e62
openssh@1:8.4p1-5+deb11u3
1:8.4p1-5+deb11u4
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
openssh@1:7.6p1-4ubuntu0.7
1:7.6p1-4ubuntu0.7+esm4
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
apache/airflow:2.8.4-python3.964e58748b6b9
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
apache/airflow:2.8.1e5560ad0b86e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
apache/drill:1.21.11f96558fd292
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
apache/ranger:2.7.076c176e8a0e4
openssh@1:8.9p1-3ubuntu0.13
no fix listed
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
archish27/python-fastapi-postgres:latest6610071a2101
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
aristidetm/basic-notebook:3.6.5469dbc951224
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
aroralalit/student-producer:1.0.02a094f597b36
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
atmoz/sftp:latest0960390462a4
openssh@1:8.4p1-5+deb11u3
1:8.4p1-5+deb11u4
1
atomix/atomix:3.1.127738ff4f5c63
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
avinash263/pyredis263:latestaa2b8727f1a6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.