StackRadar

CVE-2025-27516

High

Advisory

Published 5 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
393
of 17,781 indexed, latest versions
Container images
421
deployed by those charts
Fix available
3 of 3
affected packages

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

Carried by container images the latest versions of 393 of 17,781 indexed charts deploy, on 421 images.

Affected packageAffected versionsFixed inImages
jinja2deb2.7.2-2, 2.10.1-2, 3.0.3-1, 3.0.3-1ubuntu0.1+1 more2.7.2-2ubuntu0.1~esm6, 2.10.1-2ubuntu0.5, 3.0.3-1ubuntu0.413
py3-jinja2apk3.1.2-r23.1.6-r01
jinja2pypi2.7.2, 2.8, 2.8.1, 2.9.4+17 more3.1.6421
OSV records
ALPINE-CVE-2025-27516UBUNTU-CVE-2025-27516GHSA-cpwx-vrp4-4pq7
Also known as
PYSEC-2026-1471, USN-7343-1

Charts affected

393 by stars
ChartLatestAffected imagesRadar Score
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
jinja2@3.0.0
3.1.6

Open the chart page →

13,852
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
jinja2@3.1.4
3.1.6
aristidetm/k8s-hub:3.3.7ccb516cb8474
jinja2@3.1.3
3.1.6

Open the chart page →

16,604
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
clsen2024/daejeon_2-3:latest1156cd87c8fb
jinja2@3.1.4
3.1.6

Open the chart page →

1,141
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
jinja2@3.1.2
3.1.6

Open the chart page →

6,179
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
jinja2@3.1.5
3.1.6

Open the chart page →

5,062
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
jinja2@2.10.1
3.1.6

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
jinja2@2.11.2
3.1.6

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
jinja2@3.1.5
3.1.6

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
jinja2@3.1.5
3.1.6

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
jinja2@2.10.1
3.1.6

Open the chart page →

22,405
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
jinja2@2.10.1
3.1.6

Open the chart page →

24,335
kube-web-viewdecayofmind0.0.41 of 1See more

kube-web-view decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
jinja2@2.11.2
3.1.6

Open the chart page →

2,264
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
jinja2@2.11.2
3.1.6

Open the chart page →

4,422
prometheus-aws-costs-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-aws-costs-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
jinja2@2.10
3.1.6

Open the chart page →

3,553
testdeploymentapp0.1.01 of 1See more

test deploymentapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
cbanuka/pythonapp:latestc742770d4247
jinja2@2.11.3
3.1.6

Open the chart page →

409
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
jinja2@3.1.2
3.1.6

Open the chart page →

14,856
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
jinja2@3.1.1
3.1.6

Open the chart page →

1,333
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
jinja2@3.1.4
3.1.6

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
jinja2@3.1.4
3.1.6

Open the chart page →

9,607
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
jinja2@3.1.5
3.1.6
langgenius/dify-sandbox:0.2.009b7e8705673
jinja2@3.1.4
3.1.6

Open the chart page →

19,224
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
jinja2@3.1.4
3.1.6

Open the chart page →

14,627
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
codecov/self-hosted-worker:24.4.1837f546b479b
jinja2@3.1.3
3.1.6

Open the chart page →

24,917
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
jinja2@3.1.2
3.1.6

Open the chart page →

4,550
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
jinja2@2.11.3
3.1.6

Open the chart page →

1,990
amundsenduyet1.1.03 of 7See more

amundsen duyet 1.1.0

3 of the 7 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
jinja2@2.11.1
3.1.6
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
jinja2@2.11.2
3.1.6
amundsendev/amundsen-search:2.4.099dda9502c3e
jinja2@2.11.2
3.1.6

Open the chart page →

11,174
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
jinja2@2.10.1
3.1.6

Open the chart page →

5,055
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
jinja2@3.1.2
3.1.6

Open the chart page →

25,122
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
jinja2@3.1.2
3.1.6

Open the chart page →

9,334
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
jinja2@3.1.2
3.1.6

Open the chart page →

4,085
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
jinja2@2.10.1
3.1.6

Open the chart page →

14,673
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
jinja2@3.1.3
3.1.6

Open the chart page →

12,454
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
jinja2@3.1.5
3.1.6

Open the chart page →

7,691
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
jinja2@3.1.4
3.1.6

Open the chart page →

5,704
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
jinja2@2.11.2
3.1.6

Open the chart page →

3,186
ishare-satellitefiware1.3.21 of 1See more

ishare-satellite fiware 1.3.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
jinja2@3.1.2
3.1.6

Open the chart page →

1,778
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
jinja2@3.1.4
3.1.6

Open the chart page →

5,704
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
jinja2@3.1.5
3.1.6

Open the chart page →

4,073
flaskappflaskwebapp0.1.01 of 1See more

flaskapp flaskwebapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
nabinchhetri/flask-app:v2.0be189fbf3411
jinja2@3.1.2
3.1.6

Open the chart page →

512
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-webapp-angular:release2ed7d720878ac
jinja2@2.10
3.1.6

Open the chart page →

24,296
kube-ops-viewfluent-operatorVerified publisher0.1.21 of 1See more

kube-ops-view fluent-operator 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
jinja2@2.11.2
3.1.6

Open the chart page →

1,848
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
jinja2@2.11.3
3.1.6

Open the chart page →

2,188
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
jinja2@3.0.3
3.1.6

Open the chart page →

1,958
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
jinja2@2.11.3
3.1.6

Open the chart page →

4,428
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
jinja2@3.1.5
3.1.6

Open the chart page →

2,183
spectergaloymoney0.3.11 of 1See more

specter galoymoney 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
jinja2@3.1.1
3.1.6

Open the chart page →

1,691
spectergaloymoney20.3.11 of 1See more

specter galoymoney2 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
jinja2@3.1.1
3.1.6

Open the chart page →

1,691
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
jinja2@3.0.3
3.1.6

Open the chart page →

1,150
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
jinja2@2.11.3
3.1.6

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
jinja2@2.11.3
3.1.6

Open the chart page →

1,950
ihatemoneygeek-cookbookVerified publisher1.1.21 of 1See more

ihatemoney geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ihatemoney/ihatemoney:5.2.0457fda1feb32
jinja2@3.1.1
3.1.6

Open the chart page →

1,526

Container images carrying it

421 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
citizenstig/httpbin:latestb81c818ccb86
jinja2@2.9.4
3.1.6
1
ciuse99/suggestarr:v1.0.20d72768245ef5
jinja2@3.1.5
3.1.6
1
cleveritcz/opencve:1.5.0c75c1636e0b7
jinja2@2.11.3
3.1.6
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
jinja2@3.1.4
3.1.6
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
jinja2@3.1.4
3.1.6
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
jinja2@3.1.4
3.1.6
1
clsen2024/daejeon_2-3:latest1156cd87c8fb
jinja2@3.1.4
3.1.6
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
jinja2@3.1.4
3.1.6
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
jinja2@3.1.4
3.1.6
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
jinja2@3.1.4
3.1.6
1
codecov/self-hosted-worker:24.4.1837f546b479b
jinja2@3.1.3
3.1.6
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jinja2@2.11.2
3.1.6
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jinja2@2.11.2
3.1.6
1
confluentinc/cp-kafka:5.4.01bbda887bc53
jinja2@2.9.6
3.1.6
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jinja2@2.11.3
3.1.6
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
jinja2@3.1.4
3.1.6
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
jinja2@2.11.3
3.1.6
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
jinja2@2.9.6
3.1.6
1
confluentinc/cp-kafka:7.5.1dc9b972db002
jinja2@2.11.3
3.1.6
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jinja2@2.11.2
3.1.6
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jinja2@2.11.2
3.1.6
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
jinja2@3.1.3
3.1.6
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jinja2@2.11.2
3.1.6
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jinja2@2.11.2
3.1.6
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
jinja2@2.11.3
3.1.6
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
jinja2@3.1.4
3.1.6
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
jinja2@2.11.2
3.1.6
1
craigwillis/c2metadata-bd:latestae317d7e4724
jinja2@2.11.2
3.1.6
1
danuk/telegram-sender:0.0.1026560388070
jinja2@3.1.2
3.1.6
1
daskdev/dask:1.1.04ecd7bc35500
jinja2@2.10
3.1.6
1
daskdev/dask-notebook:1.1.0052630f5ca04
jinja2@2.10
3.1.6
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
jinja2@2.11.2
3.1.6
1
datawire/aes:1.13.62beb65062c8b
jinja2@2.11.2
3.1.6
1
datawire/aes:3.11.195ec30b3c732
jinja2@3.1.4
3.1.6
1
datawire/emissary:3.12.21f67a1292d2a
jinja2@3.1.4
3.1.6
1
datawire/emissary:2.0.2-ea9716efbdd24b
jinja2@2.11.2
3.1.6
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
jinja2@3.1.3
3.1.6
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
jinja2@2.11.3
3.1.6
1
devopsgoofy/k8s-platform:latestad865312099f
jinja2@3.1.2
3.1.6
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
jinja2@3.1.1
3.1.6
1
dinutac/jinja2docker:2.1.89340dde8a8a4
jinja2@3.1.2
3.1.6
1
douz/helpdesk:latest4384103d0219
jinja2@3.1.2
3.1.6
1
dpage/pgadmin4:8.418cd5711fc9a
jinja2@3.1.3
3.1.6
1
dpage/pgadmin4:7.537946e4f3e7b
jinja2@3.1.2
3.1.6
1
dpage/pgadmin4:8.13561c1f8f99f2
jinja2@3.1.4
3.1.6
1
dpage/pgadmin4:4.5a5a656e1d5fd
jinja2@2.10.1
3.1.6
1
dpage/pgadmin4:4.22b1f00b8163cf
jinja2@2.11.2
3.1.6
1
drgrove/mtls-server:v0.14.2361721759a2b
jinja2@2.10.1
3.1.6
1
dysnix/pritunl:v1.29-r819951e3e7a32
jinja2@2.10.1
3.1.6
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
jinja2@2.10.3
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.