StackRadar

CVE-2025-27363

HighKEV

Advisory

Published 11 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.278
98th percentile
CISA KEV
Listed
since 6 May 2025
Charts affected
614
of 17,787 indexed, latest versions
Container images
575
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: freetype security update

Carried by container images the latest versions of 614 of 17,787 indexed charts deploy, on 575 images.

Affected packageAffected versionsFixed inImages
freetypedeb2.6.1-0.1ubuntu2.3, 2.6.1-0.1ubuntu2.4, 2.8.1-2ubuntu2, 2.8.1-2ubuntu2.1+11 more2.6.1-0.1ubuntu2.5+esm2, 2.8.1-2ubuntu2.2+esm1, 2.10.1-2ubuntu0.4, 2.10.4+dfsg-1+deb11u2+2 more519
freetyperpm2.8-12.el7_6.1, 2.8-14.el7, 2.9.1-4.el8, 2.9.1-4.el8_3.1+3 more0:2.8-15.el7_9.1, 0:2.9.1-5.el8_2.1, 0:2.9.1-6.el8_6.3, 0:2.9.1-7.el8_4+4 more56
OSV records
DEBIAN-CVE-2025-27363RHSA-2025:3382RHSA-2025:3383RHSA-2025:3384RHSA-2025:3385RHSA-2025:3386RHSA-2025:3393RHSA-2025:3395RHSA-2025:3421UBUNTU-CVE-2025-27363DLA-4104-1
Also known as
DSA-5880-1, RHSA-2025:3407, USN-7352-1, USN-7352-2

Charts affected

614 by stars
ChartLatestAffected imagesRadar Score
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,132
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

9,397
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
freetype@2.9.1-4.el8_3.1
0:2.9.1-7.el8_4

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

7,552
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3

Open the chart page →

9,248
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
freetype@2.9.1-4.el8_3.1
0:2.9.1-10.el8_10

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4

Open the chart page →

7,673
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
freetype@2.9.1-9.el8
0:2.9.1-10.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-27363.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2

Open the chart page →

1,838

Container images carrying it

575 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kubebb/hello-world:0.1.0b746824819f3
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
kusionstack/kusion:v0.14.0126c8f0b0976
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
langgenius/dify-api:0.6.11fca918260dd6
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
library/cassandra:3.11.10b095ff3248c6
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
library/flink:1.14.6-scala_2.122461f02672b3
freetype@2.11.1+dfsg-1ubuntu0.1
2.11.1+dfsg-1ubuntu0.3
1
library/kibana:7.17.150172f1c538e7
freetype@2.10.1-2ubuntu0.3
2.10.1-2ubuntu0.4
1
library/kibana:7.17.8c5781ba340ef
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
library/kibana:7.17.3e2e2031c15be
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
library/matomo:5.1.2-apache2415789e1602
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
library/monica:3.7.0-apacheceb1ba4196ab
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
library/nginx:1.23.03536d368b898
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
library/nginx:1.25.167f9a4f10d14
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
library/nginx:1.25.49ff236ed47fe
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
library/nginx:1.23.2ab589a3c466e
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
library/nginx:1.23.3f4e3b6489888
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
library/nginx:1.23f5747a42e3ad
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
library/nginx:1.27.3fb197595ebe7
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
library/python:3.8d41127070014
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
library/solr:8.7.0d124efd81fbb
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
library/sonarqube:10.7.0-community0842dcd4c8f8
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
library/sonarqube:10.0.0-communityef9723cf4fe4
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
library/wordpress:6.0.0-php8.0-apache277c6c25980f
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
library/wordpress:6.4.3-apache8ae66efb09a2
freetype@2.12.1+dfsg-5
2.12.1+dfsg-5+deb12u4
1
library/zookeeper:3.8-temurin55d1e5b2e601
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2+esm1
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
linuxserver/codimd:latestb801bbcf6386
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2+esm1
1
linuxserver/deluge:18.04.10ac871624394
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2+esm1
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2+esm1
1
linuxserver/jellyfin:10.7.72427dde159a2
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.4
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2+esm1
1
linuxserver/unifi-controller:8.0.240ae315a3a456
freetype@2.10.1-2ubuntu0.3
2.10.1-2ubuntu0.4
1
linuxserver/unifi-controller:7.3.83ab105cc50322
freetype@2.10.1-2ubuntu0.3
2.10.1-2ubuntu0.4
1
livekit/ingress:v1.2.21ab01641b366
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
lmscommunity/logitechmediaserver:8.5.27434f3a6c9cb
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
lnbitsdocker/lnbits-legend:latest26fae6327477
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
logiqai/flash:v3.10.265b996bc7bdc
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
maissacrement/pock8snodejs:0.0.16da0db1159da
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
mbround18/valheim:3.1.070bd4da591cd
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
mediagis/nominatim:3.7c15e941485ef
freetype@2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.4
1
mediagis/nominatim:4.2d0eae7b51374
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
merlos/zookeeper:3.9.3a38fc7e09ed7
freetype@2.12.1+dfsg-5+deb12u3
2.12.1+dfsg-5+deb12u4
1
mide/minecraft-overviewer:latest4eee0dcb715f
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
mlikiowa/napcat-docker:latest1336a777f9a4
freetype@2.11.1+dfsg-1ubuntu0.2
2.11.1+dfsg-1ubuntu0.3
1
mnaggar3396/python-app:latest371d8ed84b15
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
freetype@2.10.4+dfsg-1
2.10.4+dfsg-1+deb11u2
1
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
freetype@2.10.4+dfsg-1+deb11u1
2.10.4+dfsg-1+deb11u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.