StackRadar

CVE-2025-26519

High

Advisory

Published 14 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,058
of 17,787 indexed, latest versions
Container images
1,129
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,058 of 17,787 indexed charts deploy, on 1,129 images.

Affected packageAffected versionsFixed inImages
musldeb1.2.2-4no fix listed1
muslapk1.2.3-r0, 1.2.3-r1, 1.2.3-r2, 1.2.3-r3+10 more1.2.3-r4, 1.2.3-r6, 1.2.4_git20230717-r5, 1.2.4-r3+2 more1,128
OSV records
ALPINE-CVE-2025-26519UBUNTU-CVE-2025-26519

Charts affected

1,058 by stars
ChartLatestAffected imagesRadar Score
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
musl@1.2.4-r2
1.2.4-r3

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
musl@1.2.3-r0
1.2.3-r4

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
musl@1.2.3-r5
1.2.3-r6
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
musl@1.2.3-r5
1.2.3-r6

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
musl@1.2.4-r1
1.2.4-r3

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
musl@1.2.4-r0
1.2.4-r3

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
musl@1.2.3-r4
1.2.3-r6
zahoriaut/zahori-server:0.1.17b2de13916f3e
musl@1.2.3-r4
1.2.3-r6

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
musl@1.2.4-r2
1.2.4-r3

Open the chart page →

1,588
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5

Open the chart page →

569

Container images carrying it

1,129 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
musl@1.2.3-r5
1.2.3-r6
1
kyleslugg/klusterview:latestba8c36dfdfbd
musl@1.2.3-r4
1.2.3-r6
1
kyso/imagebox:latest68091eace89c
musl@1.2.3-r4
1.2.3-r6
1
kyso/jupyter-diff:latest82299a9e5a86
musl@1.2.3-r5
1.2.3-r6
1
kyso/kyso-front:lateste52595c5c16f
musl@1.2.3-r0
1.2.3-r4
1
kyso/kyso-nbdime:latest4aa9d38ee81d
musl@1.2.3-r4
1.2.3-r6
1
lachlanevenson/k8s-kubectl:v1.22.1638b7962cd016
musl@1.2.3-r4
1.2.3-r6
1
laly9999/node-app-dockerized:latest75ae77a20c6c
musl@1.2.3-r5
1.2.3-r6
1
langgenius/dify-web:0.6.11a2a294743634
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
lavandadelpatio/tmdb:latestded9377636e9
musl@1.2.4-r1
1.2.4-r3
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
musl@1.2.3-r4
1.2.3-r6
1
leantime/leantime:3.3.3ad4bfb0699d3
musl@1.2.5-r0
1.2.5-r1
1
leonardomulticloud/svc-vault:v1.0.0e4acd2fbb7b1
musl@1.2.3-r5
1.2.3-r6
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
musl@1.2.5-r0
1.2.5-r1
1
leonardomulticloud/webhook:v1.0.0d119918900e8
musl@1.2.3-r5
1.2.3-r6
1
library/alpine:3.18.002bb6f428431
musl@1.2.4-r0
1.2.4-r3
1
library/alpine:3.18.282d1e9d7ed48
musl@1.2.4-r0
1.2.4-r3
1
library/bash:5.2.21a422913be6a4
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
library/caddy:2.660fb54d36b4b
musl@1.2.3-r3
1.2.3-r4
1
library/docker:24.0.2-dind1d148deae16a
musl@1.2.4-r0
1.2.4-r3
1
library/docker:20.10.21-dind3153fa63f546
musl@1.2.3-r4
1.2.3-r6
1
library/docker:23.0.6-dindafa5d5134900
musl@1.2.4-r1
1.2.4-r3
1
library/docker:23.0.1-dindd9a0fd8bdd15
musl@1.2.3-r4
1.2.3-r6
1
library/docker:26.1-dinddd43b430341a
musl@1.2.5-r0
1.2.5-r1
1
library/eclipse-mosquitto:2.0.15bbac73a740f4
musl@1.2.4-r1
1.2.4-r3
1
library/eclipse-mosquitto:2.0.18d12c8f80dfc6
musl@1.2.4-r2
1.2.4-r3
1
library/haproxy:2.2-alpine20d5eaf7187e
musl@1.2.3-r3
1.2.3-r4
1
library/influxdb:2.7.4-alpinea10d46445d68
musl@1.2.4-r2
1.2.4-r3
1
library/memcached:1.6.32-alpine0a27d9d5084f
musl@1.2.5-r0
1.2.5-r1
1
library/memcached:1.6.29-alpine462ae4a35c26
musl@1.2.5-r0
1.2.5-r1
1
library/memcached:1.6.26-alpine8906e7654a20
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
library/memcached:1.6.24-alpineeff78098089f
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
library/nats:2.10.17-alpineb7752304692b
musl@1.2.5-r0
1.2.5-r1
1
library/nats:2.10.12-alpinebca70839d953
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
library/nats:2.9.11-alpineccbe811b8575
musl@1.2.3-r4
1.2.3-r6
1
library/nats:2.9-alpined402af4147fc
musl@1.2.4-r2
1.2.4-r3
1
library/nats:2.9.20-alpined6c6ae7df4a0
musl@1.2.4-r0
1.2.4-r3
1
library/nats:2.9.6-alpine3.16f576cdc17cc3
musl@1.2.3-r1
1.2.3-r4
1
library/nginx:1.25.5-alpine-slim22414422d1ba
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
library/nginx:1.25.4-alpine31bad00311cb
musl@1.2.4-r2
1.2.4-r3
1
library/nginx:1.23.2-alpine455c39afebd4
musl@1.2.3-r1
1.2.3-r4
1
library/php:7-fpm-alpine0aeb129a60da
musl@1.2.3-r1
1.2.3-r4
1
library/postgres:12.14-alpine3.174b100eafe128
musl@1.2.3-r4
1.2.3-r6
1
library/postgres:16.4-alpine5660c2cbfea5
musl@1.2.5-r0
1.2.5-r1
1
library/postgres:12.15-alpine73ea9cdd4a9d
musl@1.2.4-r1
1.2.4-r3
1
library/postgres:12-alpine7c8f48705831
musl@1.2.5-r8
1.2.5-r9
1
library/postgres:17.2-alpine7e5df973a748
musl@1.2.5-r8
1.2.5-r9
1
library/postgres:16.2-alpine951bfda46030
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
library/postgres:15.3-alpine3.17f3e018bec283
musl@1.2.3-r5
1.2.3-r6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.