StackRadar

CVE-2025-26519

High

Advisory

Published 14 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,058
of 17,787 indexed, latest versions
Container images
1,129
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,058 of 17,787 indexed charts deploy, on 1,129 images.

Affected packageAffected versionsFixed inImages
musldeb1.2.2-4no fix listed1
muslapk1.2.3-r0, 1.2.3-r1, 1.2.3-r2, 1.2.3-r3+10 more1.2.3-r4, 1.2.3-r6, 1.2.4_git20230717-r5, 1.2.4-r3+2 more1,128
OSV records
ALPINE-CVE-2025-26519UBUNTU-CVE-2025-26519

Charts affected

1,058 by stars
ChartLatestAffected imagesRadar Score
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
musl@1.2.4-r2
1.2.4-r3

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
musl@1.2.3-r0
1.2.3-r4

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
musl@1.2.3-r5
1.2.3-r6
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
musl@1.2.3-r5
1.2.3-r6

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
musl@1.2.4-r1
1.2.4-r3

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
musl@1.2.4-r0
1.2.4-r3

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
musl@1.2.3-r4
1.2.3-r6
zahoriaut/zahori-server:0.1.17b2de13916f3e
musl@1.2.3-r4
1.2.3-r6

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
musl@1.2.4-r2
1.2.4-r3

Open the chart page →

1,588
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5

Open the chart page →

569

Container images carrying it

1,129 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
musl@1.2.5-r0
1.2.5-r1
1
gitea/act_runner:0.2.11c57233403eff
musl@1.2.5-r0
1.2.5-r1
1
gitea/gitea:1.22.376f516a1a8c2
musl@1.2.5-r0
1.2.5-r1
1
gitea/gitea:1.21.6ac73e0da341f
musl@1.2.4-r2
1.2.4-r3
1
glenndehaan/api-mapper:latest6ff6310683bf
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
glenndehaan/contentbridge:latest99b9e4f73848
musl@1.2.3-r5
1.2.3-r6
1
glenndehaan/kube-hook:latest0a7116f48bfe
musl@1.2.5-r0
1.2.5-r1
1
glenndehaan/sunflare-tools:latesta5b3f1dd865d
musl@1.2.4-r0
1.2.4-r3
1
glenndehaan/tesbot:latest372b85ef91eb
musl@1.2.4-r2
1.2.4-r3
1
goalert/goalert:v0.32.008d57388b0cb
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
goccx/go-file-server-ui:latest784b35910d52
musl@1.2.5-r0
1.2.5-r1
1
goofball222/pritunl:1.32.3602.807bf26032dfce
musl@1.2.3-r3
1.2.3-r4
1
grafana/grafana:10.1.50679e877ba20
musl@1.2.4-r2
1.2.4-r3
1
grafana/grafana:9.4.71a359d92f40e
musl@1.2.3-r4
1.2.3-r6
1
grafana/grafana:10.1.11b9ca4bbc4a2
musl@1.2.4-r1
1.2.4-r3
1
grafana/grafana:9.5.239c849cebccc
musl@1.2.3-r4
1.2.3-r6
1
grafana/grafana:11.2.2-security-01464eac539793
musl@1.2.5-r0
1.2.5-r1
1
grafana/grafana:11.5.15781759b3d27
musl@1.2.5-r0
1.2.5-r1
1
grafana/grafana:10.2.36b5b37eb35bb
musl@1.2.4-r2
1.2.4-r3
1
grafana/grafana:10.3.38640e5038e83
musl@1.2.4-r2
1.2.4-r3
1
grafana/grafana:11.5.28b37a2f028f1
musl@1.2.5-r0
1.2.5-r1
1
grafana/grafana:11.1.3b23b588cf7cb
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
grafana/grafana:10.4.0f9811e4e687f
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
grafana/grafana:11.3.1fa801ab6e1ae
musl@1.2.5-r0
1.2.5-r1
1
grafana/loki:2.9.1035b02acc6765
musl@1.2.5-r0
1.2.5-r1
1
grafana/loki:2.9.26074e01dbe03
musl@1.2.4-r1
1.2.4-r3
1
grafana/loki:2.9.66ca6e2cd3b6f
musl@1.2.4-r2
1.2.4-r3
1
grafana/loki:3.0.0757b5fadf816
musl@1.2.4-r2
1.2.4-r3
1
grafana/loki:2.8.2b1da1d23037e
musl@1.2.3-r2
1.2.3-r4
1
grafana/loki-canary:3.0.028d7c00588aa
musl@1.2.4-r2
1.2.4-r3
1
grafana/loki-canary:3.1.039baf6d67f85
musl@1.2.4-r2
1.2.4-r3
1
grafana/loki-canary:2.9.24249db29b992
musl@1.2.4-r1
1.2.4-r3
1
grafana/loki-canary:2.9.6549a40203e97
musl@1.2.4-r2
1.2.4-r3
1
grafana/mimir:r292-5f018727476e456c738
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
grafana/phlare:0.5.1330f990cdad9
musl@1.2.3-r1
1.2.3-r4
1
grafana/rollout-operator:v0.14.03409edfb45c7
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
grafana/tempo:2.6.0f55a8a1937ff
musl@1.2.5-r0
1.2.5-r1
1
gresearchdev/siembol-config-editor-ui:latest071e7109a981
musl@1.2.3-r1
1.2.3-r4
1
gresearch/fasttrackml:latest16d1228220fc
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
1
gridgain/community:8.9.11d32d182a0e6a
musl@1.2.5-r0
1.2.5-r1
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
musl@1.2.3-r0
1.2.3-r4
1
guacamole/guacd:1.5.538232cae2713
musl@1.2.4-r2
1.2.4-r3
1
gutmensch/podnat-controller:0.5.2566979793fc4
musl@1.2.4-r2
1.2.4-r3
1
hamid2021/nodejs-dockercli:latest429d99890c3c
musl@1.2.3-r5
1.2.3-r6
1
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
musl@1.2.5-r0
1.2.5-r1
1
hansehe/graphql-gateway:1.0.458e09540afbc
musl@1.2.4-r1
1.2.4-r3
1
haproxytech/haproxy-alpine:2.9.57f3dc8c7e031
musl@1.2.4-r2
1.2.4-r3
1
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
musl@1.2.4-r0
1.2.4-r3
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
musl@1.2.4-r2
1.2.4-r3
1
hashicorp/boundary:0.15.3339b78b61750
musl@1.2.4-r2
1.2.4-r3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.