StackRadar

CVE-2025-27363

HighKEV

Advisory

Published 11 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.278
98th percentile
CISA KEV
Listed
since 6 May 2025
Charts affected
622
of 17,787 indexed, latest versions
Container images
581
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: freetype security update

Carried by container images the latest versions of 622 of 17,787 indexed charts deploy, on 581 images.

Affected packageAffected versionsFixed inImages
freetypedeb2.6.1-0.1ubuntu2.3, 2.6.1-0.1ubuntu2.4, 2.8.1-2ubuntu2, 2.8.1-2ubuntu2.1+11 more2.6.1-0.1ubuntu2.5+esm2, 2.8.1-2ubuntu2.2+esm1, 2.10.1-2ubuntu0.4, 2.10.4+dfsg-1+deb11u2+2 more523
freetyperpm2.8-12.el7_6.1, 2.8-14.el7, 2.8-14.el7_9.1, 2.9.1-4.el8+4 more0:2.8-15.el7_9.1, 0:2.9.1-5.el8_2.1, 0:2.9.1-6.el8_6.3, 0:2.9.1-7.el8_4+4 more58
OSV records
DEBIAN-CVE-2025-27363RHSA-2025:3382RHSA-2025:3383RHSA-2025:3384RHSA-2025:3385RHSA-2025:3386RHSA-2025:3393RHSA-2025:3395RHSA-2025:3421UBUNTU-CVE-2025-27363DLA-4104-1
Also known as
DSA-5880-1, RHSA-2025:3407, USN-7352-1, USN-7352-2

Charts affected

622 by stars
ChartLatestAffected imagesRadar Score
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4

Open the chart page →

45,392
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4

Open the chart page →

14,383
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3

Open the chart page →

9,396
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4

Open the chart page →

10,801
pagesvictor-pages1.0.02 of 3See more

pages victor-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
flyway/flyway:6.4.422d97ceb0c47
freetype@2.8.1-2ubuntu2
2.8.1-2ubuntu2.2+esm1

Open the chart page →

20,233
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

3,392
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
flyway/flyway:6.4.422d97ceb0c47
freetype@2.8.1-2ubuntu2
2.8.1-2ubuntu2.2+esm1

Open the chart page →

20,233
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,132
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

9,399
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4

Open the chart page →

14,420
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
freetype@2.9.1-4.el8_3.1
0:2.9.1-7.el8_4

Open the chart page →

28,699
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

7,552
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3

Open the chart page →

9,296
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3

Open the chart page →

14,172
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
freetype@2.9.1-4.el8_3.1
0:2.9.1-10.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4

Open the chart page →

7,685
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
freetype@2.9.1-9.el8
0:2.9.1-10.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

1,838

Container images carrying it

581 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
freetype@2.9.1-9.el8
0:2.9.1-10.el8_10
1
ghcr.io/linuxoid69/motion:4.7.0-0.1.0f0f000c3fc47
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2+esm1
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/mroxso/pollstr:latest0b4f97faa3d0
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/navikt/mock-oauth2-server:2.1.1065d4ed47ce09
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/open-telemetry/demo:1.12.0-frauddetectionservice77cefdab4d5c
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
ghcr.io/privacyengineering/hawk-monitor:master13309f068a56
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
public.ecr.aws/jtekt-corporation/annotation-tool:ef974ad9abd817eb6845
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
public.ecr.aws/jtekt-corporation/polygonal-annotation-tool:a3fa936056efd38500d6
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.