StackRadar

CVE-2025-27516

High

Advisory

Published 5 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
393
of 17,781 indexed, latest versions
Container images
421
deployed by those charts
Fix available
3 of 3
affected packages

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

Carried by container images the latest versions of 393 of 17,781 indexed charts deploy, on 421 images.

Affected packageAffected versionsFixed inImages
jinja2deb2.7.2-2, 2.10.1-2, 3.0.3-1, 3.0.3-1ubuntu0.1+1 more2.7.2-2ubuntu0.1~esm6, 2.10.1-2ubuntu0.5, 3.0.3-1ubuntu0.413
py3-jinja2apk3.1.2-r23.1.6-r01
jinja2pypi2.7.2, 2.8, 2.8.1, 2.9.4+17 more3.1.6421
OSV records
ALPINE-CVE-2025-27516UBUNTU-CVE-2025-27516GHSA-cpwx-vrp4-4pq7
Also known as
PYSEC-2026-1471, USN-7343-1

Charts affected

393 by stars
ChartLatestAffected imagesRadar Score
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
jinja2@3.0.0
3.1.6

Open the chart page →

13,852
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
jinja2@3.1.4
3.1.6
aristidetm/k8s-hub:3.3.7ccb516cb8474
jinja2@3.1.3
3.1.6

Open the chart page →

16,604
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
clsen2024/daejeon_2-3:latest1156cd87c8fb
jinja2@3.1.4
3.1.6

Open the chart page →

1,141
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
jinja2@3.1.2
3.1.6

Open the chart page →

6,179
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
jinja2@3.1.5
3.1.6

Open the chart page →

5,062
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
jinja2@2.10.1
3.1.6

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
jinja2@2.11.2
3.1.6

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
jinja2@3.1.5
3.1.6

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
jinja2@3.1.5
3.1.6

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
jinja2@2.10.1
3.1.6

Open the chart page →

22,405
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
jinja2@2.10.1
3.1.6

Open the chart page →

24,335
kube-web-viewdecayofmind0.0.41 of 1See more

kube-web-view decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
jinja2@2.11.2
3.1.6

Open the chart page →

2,264
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
jinja2@2.11.2
3.1.6

Open the chart page →

4,422
prometheus-aws-costs-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-aws-costs-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
jinja2@2.10
3.1.6

Open the chart page →

3,553
testdeploymentapp0.1.01 of 1See more

test deploymentapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
cbanuka/pythonapp:latestc742770d4247
jinja2@2.11.3
3.1.6

Open the chart page →

409
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
jinja2@3.1.2
3.1.6

Open the chart page →

14,856
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
jinja2@3.1.1
3.1.6

Open the chart page →

1,333
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
jinja2@3.1.4
3.1.6

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
jinja2@3.1.4
3.1.6

Open the chart page →

9,607
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
jinja2@3.1.5
3.1.6
langgenius/dify-sandbox:0.2.009b7e8705673
jinja2@3.1.4
3.1.6

Open the chart page →

19,224
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
jinja2@3.1.4
3.1.6

Open the chart page →

14,627
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
codecov/self-hosted-worker:24.4.1837f546b479b
jinja2@3.1.3
3.1.6

Open the chart page →

24,917
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
jinja2@3.1.2
3.1.6

Open the chart page →

4,550
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
jinja2@2.11.3
3.1.6

Open the chart page →

1,990
amundsenduyet1.1.03 of 7See more

amundsen duyet 1.1.0

3 of the 7 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
jinja2@2.11.1
3.1.6
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
jinja2@2.11.2
3.1.6
amundsendev/amundsen-search:2.4.099dda9502c3e
jinja2@2.11.2
3.1.6

Open the chart page →

11,174
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
jinja2@2.10.1
3.1.6

Open the chart page →

5,055
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
jinja2@3.1.2
3.1.6

Open the chart page →

25,122
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
jinja2@3.1.2
3.1.6

Open the chart page →

9,334
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
jinja2@3.1.2
3.1.6

Open the chart page →

4,085
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
jinja2@2.10.1
3.1.6

Open the chart page →

14,673
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
jinja2@3.1.3
3.1.6

Open the chart page →

12,454
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
jinja2@3.1.5
3.1.6

Open the chart page →

7,691
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
jinja2@3.1.4
3.1.6

Open the chart page →

5,704
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
jinja2@2.11.2
3.1.6

Open the chart page →

3,186
ishare-satellitefiware1.3.21 of 1See more

ishare-satellite fiware 1.3.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
jinja2@3.1.2
3.1.6

Open the chart page →

1,778
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
jinja2@3.1.4
3.1.6

Open the chart page →

5,704
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
jinja2@3.1.5
3.1.6

Open the chart page →

4,073
flaskappflaskwebapp0.1.01 of 1See more

flaskapp flaskwebapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
nabinchhetri/flask-app:v2.0be189fbf3411
jinja2@3.1.2
3.1.6

Open the chart page →

512
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-webapp-angular:release2ed7d720878ac
jinja2@2.10
3.1.6

Open the chart page →

24,296
kube-ops-viewfluent-operatorVerified publisher0.1.21 of 1See more

kube-ops-view fluent-operator 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
jinja2@2.11.2
3.1.6

Open the chart page →

1,848
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
jinja2@2.11.3
3.1.6

Open the chart page →

2,188
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
jinja2@3.0.3
3.1.6

Open the chart page →

1,958
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
jinja2@2.11.3
3.1.6

Open the chart page →

4,428
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
jinja2@3.1.5
3.1.6

Open the chart page →

2,183
spectergaloymoney0.3.11 of 1See more

specter galoymoney 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
jinja2@3.1.1
3.1.6

Open the chart page →

1,691
spectergaloymoney20.3.11 of 1See more

specter galoymoney2 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
jinja2@3.1.1
3.1.6

Open the chart page →

1,691
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
jinja2@3.0.3
3.1.6

Open the chart page →

1,150
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
jinja2@2.11.3
3.1.6

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
jinja2@2.11.3
3.1.6

Open the chart page →

1,950
ihatemoneygeek-cookbookVerified publisher1.1.21 of 1See more

ihatemoney geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-27516.

Container imageDigestPackageFixed in
ihatemoney/ihatemoney:5.2.0457fda1feb32
jinja2@3.1.1
3.1.6

Open the chart page →

1,526

Container images carrying it

421 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
jinja2@3.1.2
3.1.6
1
redash/redash:25.8.000d813437db5
jinja2@3.1.5
3.1.6
1
redash/redash:10.0.0.b503639392753c0376
jinja2@2.10.3
3.1.6
1
redash/redash:26.3.0c5c9148f5c38
jinja2@3.1.5
3.1.6
1
redislabs/redisearch:2.4.1433561794c5c8
jinja2@3.1.2
3.1.6
1
redislabs/redisinsight:1.14.0b03ab1426d0d
jinja2@3.1.2
3.1.6
1
reportportal/service-auto-analyzer:5.7.295ada4a216ce
jinja2@3.1.2
3.1.6
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
jinja2@3.1.2
3.1.6
1
richardchesterwood/k8s-fleetman-webapp-angular:release2ed7d720878ac
jinja2@2.10
3.1.6
1
roadiehq/community-backstage-image:latestef355bf5b639
jinja2@3.0.1
3.1.6
1
robmarkcole/deepstack-ui:latest410275726459
jinja2@3.0.1
3.1.6
1
robotshop/rs-payment:latest774b52c6180d
jinja2@3.0.1
3.1.6
1
rook/ceph:v1.20.72f970c425617
jinja2@2.11.3
3.1.6
1
rook/ceph:v1.19.2944a1dd70496
jinja2@2.11.3
3.1.6
1
saltstack/salt:3006.3e9c7906b7a5c
jinja2@3.1.2
3.1.6
1
samueldg/snappass:latest3987195edbe6
jinja2@2.10.3
3.1.6
1
seafileltd/seafile-mc:9.0.106693911bcc40
jinja2@3.1.2
3.1.6
1
seafileltd/seafile-mc:10.0.170628f29c663
jinja2@3.1.2
3.1.6
1
seafileltd/seafile-mc:9.0.97ac833196f60
jinja2@3.1.2
3.1.6
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
jinja2@3.1.4
3.1.6
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
jinja2@3.0.1
3.1.6
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
jinja2@3.0.1
3.1.6
1
seldonio/locust-core:0.81d0da98a2d76
jinja2@2.10.1
3.1.6
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
jinja2@3.0.2
3.1.6
1
semaphoreui/semaphore:v2.9.645b50bc11833f
py3-jinja2@3.1.2-r2
jinja2@3.1.2
3.1.6-r0
3.1.6
1
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
jinja2@2.11.2
3.1.6
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
jinja2@3.1.4
3.1.6
1
sirrend/helmup-notifications-service:0.1.3997866417011
jinja2@3.1.4
3.1.6
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
jinja2@3.1.2
3.1.6
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
jinja2@3.1.4
3.1.6
1
stackstorm/st2actionrunner:3.888235ba70cad
jinja2@2.11.3
3.1.6
1
stackstorm/st2api:3.86f56d239d280
jinja2@2.11.3
3.1.6
1
stackstorm/st2auth:3.833ecfda16608
jinja2@2.11.3
3.1.6
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
jinja2@2.11.3
3.1.6
1
stackstorm/st2notifier:3.8f190a6212195
jinja2@2.11.3
3.1.6
1
stackstorm/st2rulesengine:3.8259503496ff9
jinja2@2.11.3
3.1.6
1
stackstorm/st2scheduler:3.8b1de2055c362
jinja2@2.11.3
3.1.6
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
jinja2@2.11.3
3.1.6
1
stackstorm/st2stream:3.81c8904a3bf67
jinja2@2.11.3
3.1.6
1
stackstorm/st2timersengine:3.81bf35bfaf00c
jinja2@2.11.3
3.1.6
1
stackstorm/st2workflowengine:3.819fdfffdbba8
jinja2@2.11.3
3.1.6
1
statcan/ckan:2.93921305425b8
jinja2@2.10.1
3.1.6
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
jinja2@3.0.1
3.1.6
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
jinja2@2.11.2
3.1.6
1
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
jinja2@3.0.3
3.1.6
1
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
jinja2@3.0.3
3.1.6
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jinja2@3.0.3
3.1.6
1
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
jinja2@3.0.3
3.1.6
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
jinja2@3.1.2
3.1.6
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
jinja2@3.1.2
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.