StackRadar

CVE-2025-27363

HighKEV

Advisory

Published 11 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.278
98th percentile
CISA KEV
Listed
since 6 May 2025
Charts affected
614
of 17,781 indexed, latest versions
Container images
575
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: freetype security update

Carried by container images the latest versions of 614 of 17,781 indexed charts deploy, on 575 images.

Affected packageAffected versionsFixed inImages
freetypedeb2.6.1-0.1ubuntu2.3, 2.6.1-0.1ubuntu2.4, 2.8.1-2ubuntu2, 2.8.1-2ubuntu2.1+11 more2.6.1-0.1ubuntu2.5+esm2, 2.8.1-2ubuntu2.2+esm1, 2.10.1-2ubuntu0.4, 2.10.4+dfsg-1+deb11u2+2 more519
freetyperpm2.8-12.el7_6.1, 2.8-14.el7, 2.9.1-4.el8, 2.9.1-4.el8_3.1+3 more0:2.8-15.el7_9.1, 0:2.9.1-5.el8_2.1, 0:2.9.1-6.el8_6.3, 0:2.9.1-7.el8_4+4 more56
OSV records
DEBIAN-CVE-2025-27363RHSA-2025:3382RHSA-2025:3383RHSA-2025:3384RHSA-2025:3385RHSA-2025:3386RHSA-2025:3393RHSA-2025:3395RHSA-2025:3421UBUNTU-CVE-2025-27363DLA-4104-1
Also known as
DSA-5880-1, RHSA-2025:3407, USN-7352-1, USN-7352-2

Charts affected

614 by stars
ChartLatestAffected imagesRadar Score
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,132
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

9,397
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
freetype@2.9.1-4.el8_3.1
0:2.9.1-7.el8_4

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

7,552
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3

Open the chart page →

9,248
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
freetype@2.9.1-4.el8_3.1
0:2.9.1-10.el8_10

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4

Open the chart page →

7,673
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
freetype@2.9.1-9.el8
0:2.9.1-10.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

1,838

Container images carrying it

575 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hazegoodlife/haaze:veggiesite50f02d2d5d4d
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
hazegoodlife/haaze:milksite8d4c63169e14
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
hazelcast/management-center:5.3.2f9d34300d330
freetype@2.9.1-9.el8
0:2.9.1-10.el8_8
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
heywood8/redisinsight:2.28.00bc9ab313d37
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
hiboxsystems/marge-bot:0.11.07235809b43b3
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
hiboxsystems/marge-bot:0.12.1a96c10b61a59
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
freetype@2.11.1+dfsg-1ubuntu0.1
2.11.1+dfsg-1ubuntu0.3
1
hmediade/printserver:latest481a552c8e1c
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
housewrecker/gaps:latestf417dd0a7547
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2+esm1
1
hugohg34/toposervice:0.0.2812a03b3f274
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
freetype@2.6.1-0.1ubuntu2.3
2.6.1-0.1ubuntu2.5+esm2
1
iamdorsah/bastillion:v0.1db83a0254d81
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
freetype@2.8-12.el7_6.1
0:2.8-15.el7_9.1
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
freetype@2.8-12.el7_6.1
0:2.8-15.el7_9.1
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
freetype@2.8-14.el7
0:2.8-15.el7_9.1
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
freetype@2.8-14.el7
0:2.8-15.el7_9.1
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
freetype@2.8-14.el7
0:2.8-15.el7_9.1
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
jacobalberty/unifi:v7.1.664a3616625dda
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2+esm1
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
freetype@2.8.1-2ubuntu2.2
2.8.1-2ubuntu2.2+esm1
1
jacobalberty/unifi:5.10.19c409924e2463
freetype@2.6.1-0.1ubuntu2.3
2.6.1-0.1ubuntu2.5+esm2
1
jakowenko/double-take:1.6.0b858bac9e32a
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
jellyfin/jellyfin:10.8.1305a9734d7e83
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
jellyfin/jellyfin:10.10.696b09723b22f
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
jellyfin/jellyfin:10.8.1ee24f4459a40
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
freetype@2.10.1-2ubuntu0.3
2.10.1-2ubuntu0.4
1
josh5/unmanic:0.2.64d49c4816260
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
knspar/phronetis-operator:0.1.60c4f0543ee58
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
kobotoolbox/kobocat:2.022.24ab15679454415
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
kong/httpbin:latesta6ac46531193
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.