StackRadar

CVE-2025-29070

High

Advisory

Published 1 Apr 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
221
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 221 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
lcms2deb2.14-2, 2.14-2+deb12u1, 2.16-2, 2.16-2+deb13u2no fix listed206
OSV records
DEBIAN-CVE-2025-29070

Charts affected

221 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
lcms2@2.14-2
no fix listed

Open the chart page →

16,400
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
lcms2@2.14-2
no fix listed

Open the chart page →

16,400
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
lcms2@2.14-2
no fix listed

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
lcms2@2.14-2
no fix listed

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
lcms2@2.14-2
no fix listed

Open the chart page →

11,100
servicexssl-hep1.8.510 of 16See more

servicex ssl-hep 1.8.5

10 of the 16 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
library/python:3.1070c9cc675605
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex_app:v1.8.51d12f943cec5
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
lcms2@2.16-2+deb13u2
no fix listed
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
lcms2@2.16-2+deb13u2
no fix listed

Open the chart page →

66,266
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
lcms2@2.14-2
no fix listed

Open the chart page →

20,223
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
lcms2@2.14-2
no fix listed

Open the chart page →

13,390
flaresolverrsudo-kraken-flaresolverrVerified publisher2.1.41 of 1See more

flaresolverr sudo-kraken-flaresolverr 2.1.4

1 of the 1 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
lcms2@2.14-2
no fix listed

Open the chart page →

33,583
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
lcms2@2.16-2+deb13u2
no fix listed

Open the chart page →

4,674
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
lcms2@2.14-2
no fix listed

Open the chart page →

11,199
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
lcms2@2.14-2
no fix listed

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
lcms2@2.14-2
no fix listed

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
lcms2@2.14-2
no fix listed

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
lcms2@2.14-2
no fix listed

Open the chart page →

28,858
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
lcms2@2.14-2
no fix listed

Open the chart page →

9,616
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
lcms2@2.14-2
no fix listed

Open the chart page →

10,086
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
lcms2@2.14-2
no fix listed

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
lcms2@2.14-2
no fix listed

Open the chart page →

14,358
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
lcms2@2.14-2
no fix listed

Open the chart page →

10,795
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-29070.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
lcms2@2.16-2+deb13u2
no fix listed

Open the chart page →

5,560

Container images carrying it

206 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gotenberg/gotenberg:8.30206a6c708fc6
lcms2@2.16-2
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
lcms2@2.16-2+deb13u2
no fix listed
1
gotenberg/gotenberg:8-chromiuma40f92d7419a
lcms2@2.16-2+deb13u2
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
lcms2@2.14-2
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
lcms2@2.16-2
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
lcms2@2.14-2
no fix listed
1
inventree/inventree:1.5.4a946ec09da3e
lcms2@2.16-2+deb13u2
no fix listed
1
jaedb/iris:latest048cfbf58d57
lcms2@2.14-2
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
lcms2@2.14-2
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
lcms2@2.14-2
no fix listed
1
laly9999/node-app:1dd0e503913e1
lcms2@2.14-2
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
lcms2@2.14-2
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
lcms2@2.14-2
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
lcms2@2.16-2
no fix listed
1
library/node:208f693eaa7e0a
lcms2@2.14-2
no fix listed
1
library/node:latestf5d1cc40abc1
lcms2@2.16-2+deb13u2
no fix listed
1
library/python:3.1070c9cc675605
lcms2@2.16-2+deb13u2
no fix listed
1
library/python:3.8d41127070014
lcms2@2.14-2
no fix listed
1
library/python:3.9da5aee29682d
lcms2@2.16-2
no fix listed
1
library/redmine:6.1.204ac44a2595b
lcms2@2.16-2+deb13u2
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
lcms2@2.14-2
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
lcms2@2.16-2+deb13u2
no fix listed
1
library/wordpress:php8.1-apachef73396626d2f
lcms2@2.16-2
no fix listed
1
louislam/uptime-kuma:2.5.33e24e96c89ef
lcms2@2.14-2+deb12u1
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
lcms2@2.14-2
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
lcms2@2.14-2+deb12u1
no fix listed
1
machines/filestash:latest0b8fc005e52e
lcms2@2.16-2+deb13u2
no fix listed
1
martinhelmich/typo3:12.4c83a4f3fd7ae
lcms2@2.14-2
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
lcms2@2.14-2+deb12u1
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
lcms2@2.14-2
no fix listed
1
mindsdb/mindsdb:latest163011c09299
lcms2@2.16-2
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
lcms2@2.14-2
no fix listed
1
mockserver/mockserver:mockserver-7.6.080b3b1a26f35
lcms2@2.14-2
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
lcms2@2.14-2+deb12u1
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
lcms2@2.14-2
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
lcms2@2.14-2
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
lcms2@2.14-2
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
lcms2@2.14-2
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
lcms2@2.14-2
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
lcms2@2.16-2+deb13u2
no fix listed
1
oneuptime/probe:release6b2d98713711
lcms2@2.14-2+deb12u1
no fix listed
1
oneuptime/runner:release4accc516d800
lcms2@2.16-2+deb13u2
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
lcms2@2.14-2
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
lcms2@2.14-2
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
lcms2@2.14-2
no fix listed
1
opea/speecht5:1.0249afad3d268
lcms2@2.14-2
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
lcms2@2.14-2+deb12u1
no fix listed
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
lcms2@2.16-2+deb13u2
no fix listed
1
openhab/openhab:5.2.1bfd4a60e90da
lcms2@2.16-2+deb13u2
no fix listed
1
openproject/hocuspocus:release-338001b288dc1359dfb5
lcms2@2.14-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.