StackRadar

CVE-2025-26519

High

Advisory

Published 14 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,058
of 17,787 indexed, latest versions
Container images
1,129
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,058 of 17,787 indexed charts deploy, on 1,129 images.

Affected packageAffected versionsFixed inImages
musldeb1.2.2-4no fix listed1
muslapk1.2.3-r0, 1.2.3-r1, 1.2.3-r2, 1.2.3-r3+10 more1.2.3-r4, 1.2.3-r6, 1.2.4_git20230717-r5, 1.2.4-r3+2 more1,128
OSV records
ALPINE-CVE-2025-26519UBUNTU-CVE-2025-26519

Charts affected

1,058 by stars
ChartLatestAffected imagesRadar Score
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
musl@1.2.4-r2
1.2.4-r3

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
musl@1.2.3-r0
1.2.3-r4

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
musl@1.2.3-r5
1.2.3-r6
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
musl@1.2.3-r5
1.2.3-r6

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
musl@1.2.4-r1
1.2.4-r3

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
musl@1.2.4-r0
1.2.4-r3

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
musl@1.2.3-r4
1.2.3-r6
zahoriaut/zahori-server:0.1.17b2de13916f3e
musl@1.2.3-r4
1.2.3-r6

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
musl@1.2.4-r2
1.2.4-r3

Open the chart page →

1,588
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-26519.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5

Open the chart page →

569

Container images carrying it

1,129 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
musl@1.2.3-r2
1.2.3-r4
10
curlimages/curl:8.5.008e466006f08
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
7
clastix/kubectl:v1.3122918a06c253
musl@1.2.3-r3
1.2.3-r4
6
library/registry:2.8.1dbaa3e69f563
musl@1.2.4-r0
1.2.4-r3
6
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
musl@1.2.5-r0
1.2.5-r1
6
quay.io/devtron/kubectl:latest2ad610626658
musl@1.2.3-r0
1.2.3-r4
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
musl@1.2.4-r0
1.2.4-r3
6
keelhq/keel:latest73714afb4443
musl@1.2.5-r0
1.2.5-r1
5
natsio/nats-box:0.14.1a67913df95f1
musl@1.2.4-r2
1.2.4-r3
5
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
musl@1.2.4-r2
1.2.4-r3
5
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
musl@1.2.3-r3
1.2.3-r4
5
curlimages/curl:8.8.073e4d532ea62
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
4
curlimages/curl:7.87.0:multiarch-7.87.0f7f265d5c64e
musl@1.2.3-r2
1.2.3-r4
4
hyperledger/fabric-orderer:2.46ec3fe59ea55
musl@1.2.3-r2
1.2.3-r4
4
hyperledger/fabric-peer:2.46ff36af21eb1
musl@1.2.3-r2
1.2.3-r4
4
hyperledger/fabric-tools:2.4b1194f509085
musl@1.2.3-r2
1.2.3-r4
4
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
musl@1.2.3-r3
1.2.3-r4
4
jaegertracing/jaeger-collector:1.53.07f1269222903
musl@1.2.3-r3
1.2.3-r4
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
musl@1.2.3-r3
1.2.3-r4
4
library/influxdb:1.8.10-alpine2601e27d6b7e
musl@1.2.3-r5
1.2.3-r6
4
openquantumsafe/openssl3:latest543fb00ce31d
musl@1.2.5-r8
1.2.5-r9
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
musl@1.2.5-r0
1.2.5-r1
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
musl@1.2.4-r0
1.2.4-r3
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
musl@1.2.4-r1
1.2.4-r3
4
alfhou/hammond:v0.0.24c85dc0293aa1
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
3
caddy/ingress:v0.2.118d1366fc0e9
musl@1.2.4-r1
1.2.4-r3
3
derailed/popeye:v0.22.18e68e22c7663
musl@1.2.5-r8
1.2.5-r9
3
getmeili/meilisearch:v1.7.319b825993dbe
musl@1.2.3-r3
1.2.3-r4
3
grafana/grafana:11.0.00dc5a246ab16
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
3
grafana/grafana:11.3.0a0f881232a6f
musl@1.2.5-r0
1.2.5-r1
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
musl@1.2.3-r0
1.2.3-r4
3
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
musl@1.2.5-r0
1.2.5-r1
3
library/docker:20.10-dind:20-dindaf96c680a7e1
musl@1.2.4-r0
1.2.4-r3
3
library/nginx:1.25.5-alpine:1.25-alpine516475cc129d
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
musl@1.2.5-r0
1.2.5-r1
3
library/postgres:10-alpine63cfb6eac6b3
musl@1.2.3-r1
1.2.3-r4
3
library/redis:7.2.4-alpinec8bb255c3559
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
musl@1.2.4-r0
1.2.4-r3
3
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
musl@1.2.4-r2
1.2.4-r3
3
opencsghq/psql:latest57def8e77d0f
musl@1.2.5-r8
1.2.5-r9
3
oryd/hydra:v2.2.02c93beb5e5f2
musl@1.2.4-r2
1.2.4-r3
3
paulkellerman/resultserver-app:1.0381eeccb0618
musl@1.2.3-r1
1.2.3-r4
3
paulkellerman/webserver-app:latest5a37b74f61b9
musl@1.2.3-r1
1.2.3-r4
3
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
musl@1.2.3-r4
1.2.3-r6
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
musl@1.2.4-r2
1.2.4-r3
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
musl@1.2.4-r2
1.2.4-r3
3
quay.io/devtron/devtron-utils:geni-v1.1.4f6269309455a
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r5
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
musl@1.2.5-r8
1.2.5-r9
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
musl@1.2.5-r8
1.2.5-r9
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.