StackRadar

CVE-2025-30754

Medium

Advisory

Published 15 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
75
of 17,781 indexed, latest versions
Container images
66
deployed by those charts
Fix available
7 of 7
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 75 of 17,781 indexed charts deploy, on 66 images.

Affected packageAffected versionsFixed inImages
openjdk-8deb8u151-b12-0ubuntu0.16.04.2, 8u171-b11-0ubuntu0.16.04.1, 8u191-b12-2ubuntu0.16.04.1, 8u212-b03-0ubuntu1.18.04.1+11 more8u462-ga~us1-0ubuntu2~16.04.2, 8u462-ga~us1-0ubuntu2~18.04.2, 8u462-ga~us1-0ubuntu2~20.04.2, 8u462-ga~us1-0ubuntu2~22.04.2+1 more22
javabitnami11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+12 more1.8.016
openjdk-ltsdeb11.0.3+7-1ubuntu2~18.04.1, 11.0.8+10-0ubuntu1~18.04.1, 11.0.11+9-0ubuntu2~20.04, 11.0.13+8-0ubuntu1~20.04+6 more11.0.28+6-1ubuntu1~18.04.1, 11.0.28+6-1ubuntu1~20.04.1, 11.0.28+6-1ubuntu1~24.04.116
openjdk-17deb17.0.3+7-0ubuntu0.20.04.1, 17.0.8+7-1~22.04, 17.0.9+9-1~20.04, 17.0.10+7-1~22.04.1+5 more17.0.16+8-1~deb12u1, 17.0.16+8~us1-0ubuntu1~20.04.6, 17.0.16+8~us1-0ubuntu1~22.04.1, 17.0.16+8~us1-0ubuntu1~24.04.110
Javabitnami11.0.20-8, 11.0.21-10, 17.0.8-7, 17.0.10-13-1+2 more1.8.07
openjdk-21deb21.0.5+11-1ubuntu1~24.04, 21.0.7+6~us1-0ubuntu1~24.0421.0.8+9~us1-0ubuntu1~24.04.13
jrebitnami17.0.16-12-0, 21.0.8-12-01.8.02
OSV records
BIT-java-2025-30754BIT-jre-2025-30754DEBIAN-CVE-2025-30754UBUNTU-CVE-2025-30754
Also known as
BIT-java-min-2025-30754, USN-7667-1, USN-7668-1, USN-7674-1, USN-7690-1

Charts affected

75 by stars
ChartLatestAffected imagesRadar Score
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
openjdk-lts@11.0.8+10-0ubuntu1~18.04.1
11.0.28+6-1ubuntu1~18.04.1

Open the chart page →

26,944
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
openjdk-lts@11.0.18+10-0ubuntu1~20.04.1
11.0.28+6-1ubuntu1~20.04.1

Open the chart page →

15,722
daveit-at-mOfficialVerified publisher0.2.151 of 11See more

dave it-at-m 0.2.15

1 of the 11 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
java@21.0.8-12-0
1.8.0

Open the chart page →

15,089
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
openjdk-17@17.0.11+9-1
17.0.16+8~us1-0ubuntu1~24.04.1

Open the chart page →

45,239
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
openjdk-8@8u372-ga~us1-0ubuntu1~18.04
8u462-ga~us1-0ubuntu2~18.04.2

Open the chart page →

7,826
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
openjdk-21@21.0.5+11-1ubuntu1~24.04
21.0.8+9~us1-0ubuntu1~24.04.1

Open the chart page →

6,586
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
openjdk-21@21.0.5+11-1ubuntu1~24.04
21.0.8+9~us1-0ubuntu1~24.04.1

Open the chart page →

6,568
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
openjdk-21@21.0.7+6~us1-0ubuntu1~24.04
21.0.8+9~us1-0ubuntu1~24.04.1

Open the chart page →

8,811
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
openjdk-17@17.0.15+6~us1-0ubuntu1~20.04
17.0.16+8~us1-0ubuntu1~20.04.6

Open the chart page →

7,268
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
openjdk-lts@11.0.19+7~us1-0ubuntu1~20.04.1
11.0.28+6-1ubuntu1~20.04.1

Open the chart page →

11,188
backendmojaloop0.1.02 of 6See more

backend mojaloop 0.1.0

2 of the 6 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
java@11.0.15-150
1.8.0
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
java@11.0.21-10-6
Java@11.0.21-10
1.8.0
1.8.0

Open the chart page →

16,198
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.28+6-1ubuntu1~20.04.1

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
openjdk-lts@11.0.13+8-0ubuntu1~20.04
11.0.28+6-1ubuntu1~20.04.1

Open the chart page →

15,675
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
java@17.0.11-12-0
Java@17.0.11-12-0
1.8.0
1.8.0

Open the chart page →

15,369
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
openjdk-8@8u382-ga-1~20.04.1
8u462-ga~us1-0ubuntu2~20.04.2

Open the chart page →

109,294
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
openjdk-lts@11.0.26+4-1ubuntu1~24.04
11.0.28+6-1ubuntu1~24.04.1

Open the chart page →

6,037
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
openjdk-8@8u212-b03-0ubuntu1.18.04.1
openjdk-lts@11.0.3+7-1ubuntu2~18.04.1
8u462-ga~us1-0ubuntu2~18.04.2
11.0.28+6-1ubuntu1~18.04.1

Open the chart page →

63,223
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
openjdk-lts@11.0.14.1+1-0ubuntu1~20.04
11.0.28+6-1ubuntu1~20.04.1

Open the chart page →

15,520
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
java@11.0.20-8-5
Java@11.0.20-8
1.8.0
1.8.0

Open the chart page →

2,917
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
openjdk-8@8u312-b07-0ubuntu1~18.04
8u462-ga~us1-0ubuntu2~18.04.2

Open the chart page →

14,493
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
openjdk-lts@11.0.19+7~us1-0ubuntu1~20.04.1
11.0.28+6-1ubuntu1~20.04.1

Open the chart page →

18,756
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
openjdk-17@17.0.11+9-1
17.0.16+8~us1-0ubuntu1~24.04.1

Open the chart page →

45,239
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
java@11.0.20-8-3
Java@11.0.20-8
1.8.0
1.8.0

Open the chart page →

9,397
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.28+6-1ubuntu1~20.04.1

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-30754.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.28+6-1ubuntu1~20.04.1

Open the chart page →

28,605

Container images carrying it

66 by charts deploying them

A fixed version is listed for 7 of the 7 affected packages.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openjdk-8@8u171-b11-0ubuntu0.16.04.1
8u462-ga~us1-0ubuntu2~16.04.2
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openjdk-8@8u191-b12-2ubuntu0.16.04.1
8u462-ga~us1-0ubuntu2~16.04.2
4
gchq/hdfs:3.3.35ec58edbb2db
openjdk-8@8u442-b06~us1-0ubuntu1~24.04
8u462-ga~us1-0ubuntu2~24.04.2
3
jacobalberty/unifi:v10.0.162896c0ab82d33
openjdk-17@17.0.15+6~us1-0ubuntu1~20.04
17.0.16+8~us1-0ubuntu1~20.04.6
3
selenium/hub:3.141.5902f251d48d5f
openjdk-8@8u292-b10-0ubuntu1~20.04
8u462-ga~us1-0ubuntu2~20.04.2
3
signoz/zookeeper:3.7.1fcc4a3288154
java@11.0.20-8-5
Java@11.0.20-8
1.8.0
1.8.0
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
openjdk-17@17.0.11+9-1
17.0.16+8~us1-0ubuntu1~24.04.1
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
java@21.0.8-12-0
1.8.0
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
java@11.0.20-8-3
Java@11.0.20-8
1.8.0
1.8.0
2
hookiesolutions/webhookie:latest0629694246ba
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.28+6-1ubuntu1~20.04.1
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
openjdk-17@17.0.3+7-0ubuntu0.20.04.1
17.0.16+8~us1-0ubuntu1~20.04.6
2
mbentley/omada-controller:4.3f4e682274bed
openjdk-8@8u372-ga~us1-0ubuntu1~18.04
8u462-ga~us1-0ubuntu2~18.04.2
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
openjdk-21@21.0.7+6~us1-0ubuntu1~24.04
21.0.8+9~us1-0ubuntu1~24.04.1
2
1dev/server:11.9.0cd5b12fe5471
openjdk-lts@11.0.26+4-1ubuntu1~24.04
11.0.28+6-1ubuntu1~24.04.1
1
5200710/hadoop:3.2.3-java8092d3088a5fb
openjdk-8@8u392-ga-1~20.04
8u462-ga~us1-0ubuntu2~20.04.2
1
anguda/ant-media:2.5c435285fc241
openjdk-lts@11.0.18+10-0ubuntu1~20.04.1
11.0.28+6-1ubuntu1~20.04.1
1
apache/druid:29.0.10cef139b6bf1
openjdk-17@17.0.10+7-1~deb12u1
17.0.16+8-1~deb12u1
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
openjdk-lts@11.0.13+8-0ubuntu1~20.04
11.0.28+6-1ubuntu1~20.04.1
1
apachepulsar/pulsar:2.9.0d056c89b7131
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.28+6-1ubuntu1~20.04.1
1
apachepulsar/pulsar:2.8.2d538416d5afe
openjdk-lts@11.0.13+8-0ubuntu1~20.04
11.0.28+6-1ubuntu1~20.04.1
1
apache/tika:2.9.0.092d055a84e9e
openjdk-17@17.0.8+7-1~22.04
17.0.16+8~us1-0ubuntu1~22.04.1
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
java@11.0.25-11-1
1.8.0
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
java@17.0.10-13-2
Java@17.0.10-13-2
1.8.0
1.8.0
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
java@17.0.10-13-1
Java@17.0.10-13-1
1.8.0
1.8.0
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
java@21.0.7-9-0
1.8.0
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
java@17.0.7-7-2
1.8.0
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
java@11.0.18-10-2
1.8.0
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
java@11.0.15-150
1.8.0
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
java@17.0.6-10-4
1.8.0
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
java@17.0.11-12-0
Java@17.0.11-12-0
1.8.0
1.8.0
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jre@21.0.8-12-0
1.8.0
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
java@17.0.13-12-1
1.8.0
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
java@11.0.21-10-6
Java@11.0.21-10
1.8.0
1.8.0
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
java@11.0.18-10-1
1.8.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.28+6-1ubuntu1~20.04.1
1
cheyang/distributed-tf:1.6.046cc34755493
openjdk-8@8u151-b12-0ubuntu0.16.04.2
8u462-ga~us1-0ubuntu2~16.04.2
1
gchq/accumulo:2.0.1c460bb587d6d
openjdk-8@8u442-b06~us1-0ubuntu1~24.04
8u462-ga~us1-0ubuntu2~24.04.2
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
openjdk-8@8u171-b11-0ubuntu0.16.04.1
8u462-ga~us1-0ubuntu2~16.04.2
1
jacobalberty/unifi:v7.1.664a3616625dda
openjdk-8@8u312-b07-0ubuntu1~18.04
8u462-ga~us1-0ubuntu2~18.04.2
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
openjdk-lts@11.0.19+7~us1-0ubuntu1~18.04.1
11.0.28+6-1ubuntu1~18.04.1
1
jacobalberty/unifi:5.10.19c409924e2463
openjdk-8@8u191-b12-2ubuntu0.16.04.1
8u462-ga~us1-0ubuntu2~16.04.2
1
linuxserver/unifi-controller:8.0.240ae315a3a456
openjdk-17@17.0.9+9-1~20.04
17.0.16+8~us1-0ubuntu1~20.04.6
1
linuxserver/unifi-controller:7.3.83ab105cc50322
openjdk-lts@11.0.19+7~us1-0ubuntu1~20.04.1
11.0.28+6-1ubuntu1~20.04.1
1
merlos/zookeeper:3.9.3a38fc7e09ed7
openjdk-17@17.0.13+11-2~deb12u1
17.0.16+8-1~deb12u1
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
openjdk-8@8u212-b03-0ubuntu1.18.04.1
openjdk-lts@11.0.3+7-1ubuntu2~18.04.1
8u462-ga~us1-0ubuntu2~18.04.2
11.0.28+6-1ubuntu1~18.04.1
1
openkm/openkm-ce:6.3.113bc465a7461b
openjdk-8@8u342-b07-0ubuntu1~20.04
8u462-ga~us1-0ubuntu2~20.04.2
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
java@17.0.8-7-5
Java@17.0.8-7
1.8.0
1.8.0
1
project2team4/react:latest3ff031a08887
openjdk-lts@11.0.14.1+1-0ubuntu1~20.04
11.0.28+6-1ubuntu1~20.04.1
1
rundeck/rundeck:3.2.74d64fe56f767
openjdk-8@8u252-b09-1~16.04
8u462-ga~us1-0ubuntu2~16.04.2
1
rundeck/rundeck:3.0.16b13e8059ad72
openjdk-8@8u191-b12-2ubuntu0.16.04.1
8u462-ga~us1-0ubuntu2~16.04.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.