StackRadar

CVE-2025-26519

High

Advisory

Published 14 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,058
of 17,787 indexed, latest versions
Container images
1,129
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,058 of 17,787 indexed charts deploy, on 1,129 images.

Affected packageAffected versionsFixed inImages
musldeb1.2.2-4no fix listed1
muslapk1.2.3-r0, 1.2.3-r1, 1.2.3-r2, 1.2.3-r3+10 more1.2.3-r4, 1.2.3-r6, 1.2.4_git20230717-r5, 1.2.4-r3+2 more1,128
OSV records
ALPINE-CVE-2025-26519UBUNTU-CVE-2025-26519

Charts affected

1,058 by stars
ChartLatestAffected imagesRadar Score
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
musl@1.2.4-r2
1.2.4-r3

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
musl@1.2.3-r0
1.2.3-r4

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
musl@1.2.3-r5
1.2.3-r6
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
musl@1.2.3-r5
1.2.3-r6

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
musl@1.2.4-r1
1.2.4-r3

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
musl@1.2.4-r0
1.2.4-r3

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
musl@1.2.3-r4
1.2.3-r6
zahoriaut/zahori-server:0.1.17b2de13916f3e
musl@1.2.3-r4
1.2.3-r6

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
musl@1.2.4-r2
1.2.4-r3

Open the chart page →

1,588
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5

Open the chart page →

569

Container images carrying it

1,129 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
aquasec/harbor-scanner-trivy:0.31.26e790e233872
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
aquasec/kube-bench:v0.6.176672264accce
musl@1.2.4-r0
1.2.4-r3
1
aquasec/kube-bench:v0.6.9c329d73fea58
musl@1.2.3-r0
1.2.3-r4
1
aquasec/postee:2.12.0-amd640795cba777e7
musl@1.2.4-r0
1.2.4-r3
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
musl@1.2.4-r0
1.2.4-r3
1
aquasec/trivy:0.43.1944a04445179
musl@1.2.4-r0
1.2.4-r3
1
aquasec/trivy:0.32.0973d0df16189
musl@1.2.3-r0
1.2.3-r4
1
artifacthub/db-migrator:v1.19.02a746b289fcd
musl@1.2.5-r0
1.2.5-r1
1
artifacthub/hub:v1.19.0111918d8c399
musl@1.2.5-r0
1.2.5-r1
1
artifacthub/scanner:v1.19.0323d026e78c3
musl@1.2.5-r0
1.2.5-r1
1
asonix/pictrs:0.4.0-beta.19480d36cd97e5
musl@1.2.3-r2
1.2.3-r4
1
asonix/relay:0.3.82779e10f6f5bb
musl@1.2.3-r2
1.2.3-r4
1
assistiot/composite-services-manager_agent-http-mqtt:latest16d21bc5e42e
musl@1.2.4-r1
1.2.4-r3
1
assistiot/composite-services-manager_agent-mqtt-http:latest27d58b8911cd
musl@1.2.4-r1
1.2.4-r3
1
assistiot/fl_orchestrator:ui-latest20338b353aaf
musl@1.2.3-r0
1.2.3-r4
1
assistiot/monitoring_notifying:2.0.068324d0fa5bb
musl@1.2.3-r4
1.2.3-r6
1
assistiot/open_api_kong:1.0.03fe850384689
musl@1.2.3-r2
1.2.3-r4
1
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
musl@1.2.4-r2
1.2.4-r3
1
assistiot/resource-provisioning_im:1.0.0a942dc14030a
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
assistiot/semantic_translation:latest2a2587804717
musl@1.2.4-r1
1.2.4-r3
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
musl@1.2.3-r4
1.2.3-r6
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
musl@1.2.3-r4
1.2.3-r6
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
musl@1.2.3-r4
1.2.3-r6
1
assistiot/tacticle_dashboard:db-latest02bc92348156
musl@1.2.3-r0
1.2.3-r4
1
assistiot/tacticle_dashboard:web-latest25fc9f373524
musl@1.2.3-r0
1.2.3-r4
1
assistiot/traffic-classification_api:2.0.0e32b87786142
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
b4bz/homer:v22.07.248a81e130470
musl@1.2.3-r0
1.2.3-r4
1
b4bz/homer:v24.12.14b44a4a9e329
musl@1.2.5-r0
1.2.5-r1
1
b4bz/homer:v22.11.1678ac390d7c9
musl@1.2.3-r0
1.2.3-r4
1
behnambm/docker-sample:v1bd3ad88afff9
musl@1.2.5-r0
1.2.5-r1
1
belirta/beli-docker:v1.0.0f65ad0e23b4d
musl@1.2.3-r5
1.2.3-r6
1
beopenit/door-agent:v3.0.5d24c323fe7c3
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
bicarus/http-https-echo:2785dd6a7e805e
musl@1.2.3-r1
1.2.3-r4
1
bicarus/wg-access-server:v0.8.206cab48e9334
musl@1.2.3-r0
1.2.3-r4
1
binwiederhier/ntfy:v1.27.219eeaec60fda
musl@1.2.3-r0
1.2.3-r4
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
binwiederhier/ntfy:v2.6.283e2e43d9956
musl@1.2.4-r0
1.2.4-r3
1
blipai/deckard:0.0.28737d5d19a312
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
blockscout/blockscout:5.1.5c365a8f2dc12
musl@1.2.3-r2
1.2.3-r4
1
bnwokoye/nodejswebapp:latest74de7dc7ebfb
musl@1.2.3-r4
1.2.3-r6
1
btungut/azure-keyvault-secret-operator:1.7.04a072e2edf71
musl@1.2.4-r1
1.2.4-r3
1
burganbank/vault-initializer:v19259c34e4037
musl@1.2.5-r0
1.2.5-r1
1
caarlos0/domain_exporter:v1.23.0d11dec138900
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
carlosmz87/test_helm_frontend:latest79f4b528f42a
musl@1.2.5-r0
1.2.5-r1
1
casbin/casdoor:v1.224.066f836ef778b
musl@1.2.3-r4
1.2.3-r6
1
casbin/casdoor:v1.753.0770ad9ec3190
musl@1.2.5-r0
1.2.5-r1
1
catalysm/csmm:latestf003b35f54d9
musl@1.2.4-r1
1.2.4-r3
1
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
musl@1.2.4-r2
1.2.4-r3
1
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
musl@1.2.4-r1
1.2.4-r3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.