StackRadar

CVE-2025-27587

Medium

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
801
of 17,787 indexed, latest versions
Container images
879
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 801 of 17,787 indexed charts deploy, on 879 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.9-1, 3.0.11-1~deb12u1, 3.0.11-1~deb12u2, 3.0.13-1~deb12u1+12 moreno fix listed879
OSV records
DEBIAN-CVE-2025-27587

Charts affected

801 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-27587.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

2,674

Container images carrying it

879 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
no fix listed
11
ethpandaops/xatu:latest74d4cf2c436c
openssl@3.0.20-1~deb12u2
no fix listed
10
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
openssl@3.0.20-1~deb12u2
no fix listed
7
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
openssl@3.0.16-1~deb12u1
no fix listed
6
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
openssl@3.0.17-1~deb12u1
no fix listed
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
openssl@3.0.17-1~deb12u2
no fix listed
6
library/redis:6:6.2143f7bfc2358
openssl@3.0.20-1~deb12u2
no fix listed
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
6
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
openssl@3.0.11-1~deb12u2
no fix listed
5
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
openssl@3.0.20-1~deb12u1
no fix listed
5
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
no fix listed
5
library/redis:7.2:7.2-bookworm74566c6910d1
openssl@3.0.20-1~deb12u2
no fix listed
5
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
openssl@3.0.17-1~deb12u2
no fix listed
4
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
openssl@3.0.17-1~deb12u1
no fix listed
4
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
no fix listed
4
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
openssl@3.0.17-1~deb12u2
no fix listed
4
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
openssl@3.0.16-1~deb12u1
no fix listed
4
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
no fix listed
4
library/redis:7:7.4:7.4.1171da9275c5f3
openssl@3.0.20-1~deb12u2
no fix listed
4
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
no fix listed
4
shashkist/flask-contacts-app:latest581de1fd6084
openssl@3.0.15-1~deb12u1
no fix listed
4
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
openssl@3.0.20-1~deb12u2
no fix listed
4
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
openssl@3.0.20-1~deb12u2
no fix listed
4
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
openssl@3.0.20-1~deb12u2
no fix listed
4
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
openssl@3.0.20-1~deb12u2
no fix listed
4
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
openssl@3.0.20-1~deb12u2
no fix listed
4
apache/superset:6.1.0:latest16b50bbef664
openssl@3.0.20-1~deb12u2
no fix listed
3
bitnamilegacy/kubectl:latestcd354d5b2556
openssl@3.0.16-1~deb12u1
no fix listed
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
openssl@3.0.17-1~deb12u2
no fix listed
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
openssl@3.0.15-1~deb12u1
no fix listed
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
openssl@3.0.11-1~deb12u2
no fix listed
3
library/node:ltsbe23f54a88d3
openssl@3.0.20-1~deb12u2
no fix listed
3
mcp/grafana:latest9362bcf6aa0e
openssl@3.0.20-1~deb12u2
no fix listed
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
openssl@3.0.15-1~deb12u1
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
openssl@3.0.9-1
no fix listed
3
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
openssl@3.0.20-1~deb12u2
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
no fix listed
3
ghcr.io/kubevault/vault-operator:v0.25.0c8e042b5cee8
openssl@3.0.20-1~deb12u2
no fix listed
3
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
openssl@3.0.20-1~deb12u2
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
no fix listed
3
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
openssl@3.0.20-1~deb12u2
no fix listed
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
openssl@3.0.17-1~deb12u2
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
openssl@3.0.15-1~deb12u1
no fix listed
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
openssl@3.0.17-1~deb12u2
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
openssl@3.0.14-1~deb12u2
no fix listed
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
openssl@3.0.17-1~deb12u2
no fix listed
2
bitnamilegacy/redis:latest5927ff3702df
openssl@3.0.16-1~deb12u1
no fix listed
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.