StackRadar

CVE-2025-27611

High

Advisory

Published 30 Apr 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

Homograph attack allows Unicode lookalike characters to bypass validation.

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
base-xnpm3.0.8, 3.0.9, 3.0.10, 4.0.03.0.11, 4.0.114
OSV records
GHSA-xq7p-g2vc-g82p

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
umamiwaldo-visionVerified publisher0.0.11 of 1See more

umami waldo-vision 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v1.39.560fa8875aff8
base-x@4.0.0
4.0.1

Open the chart page →

1,255
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
base-x@3.0.9
3.0.11

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
base-x@3.0.8
3.0.11

Open the chart page →

3,260
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
base-x@3.0.9
3.0.11

Open the chart page →

4,756
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
base-x@3.0.9
3.0.11

Open the chart page →

3,320
galoy-paygaloymoney0.11.481 of 2See more

galoy-pay galoymoney 0.11.48

1 of the 2 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
krtk6160/galoy-nostrdigest-pinnedcc82a694f818
base-x@3.0.9
3.0.11

Open the chart page →

2,528
galoy-paygaloymoney20.11.481 of 2See more

galoy-pay galoymoney2 0.11.48

1 of the 2 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
krtk6160/galoy-nostrdigest-pinnedcc82a694f818
base-x@3.0.9
3.0.11

Open the chart page →

2,528
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
base-x@3.0.8
3.0.11

Open the chart page →

3,003
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
base-x@3.0.8
3.0.11

Open the chart page →

4,944
interbtc-hydrainterlay0.1.151 of 4See more

interbtc-hydra interlay 0.1.15

1 of the 4 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
base-x@3.0.9
3.0.11

Open the chart page →

6,831
interlay-firesquidinterlay0.1.111 of 4See more

interlay-firesquid interlay 0.1.11

1 of the 4 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
base-x@3.0.9
3.0.11

Open the chart page →

4,667
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
base-x@3.0.9
3.0.11

Open the chart page →

2,919
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
mishtinetwork/operator:latestbb3fe67a5f7c
base-x@3.0.10
3.0.11

Open the chart page →

3,999
ungatep2p-avs0.1.01 of 3See more

ungate p2p-avs 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
base-x@3.0.10
3.0.11

Open the chart page →

27,373
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
base-x@3.0.9
3.0.11

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
base-x@3.0.9
3.0.11

Open the chart page →

16,620
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-27611.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
base-x@3.0.8
3.0.11

Open the chart page →

3,118

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ethersphere/bee-localchain:latest0558799ca992
base-x@3.0.9
3.0.11
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
base-x@3.0.9
3.0.11
2
krtk6160/galoy-nostrcc82a694f818
base-x@3.0.9
3.0.11
2
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
base-x@3.0.8
3.0.11
1
ethersphere/bzz-token-service:latest7624f11a72ad
base-x@3.0.8
3.0.11
1
ethersphere/onboarding-faucet:0.3.0513154aab230
base-x@3.0.9
3.0.11
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
base-x@3.0.9
3.0.11
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
base-x@3.0.9
3.0.11
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
base-x@3.0.8
3.0.11
1
mishtinetwork/operator:latestbb3fe67a5f7c
base-x@3.0.10
3.0.11
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
base-x@3.0.10
3.0.11
1
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
base-x@3.0.8
3.0.11
1
ghcr.io/umami-software/umami:postgresql-v1.39.560fa8875aff8
base-x@4.0.0
4.0.1
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
base-x@3.0.9
3.0.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.