StackRadar

CVE-2025-31115

High

Advisory

Published 3 Apr 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
657
of 17,787 indexed, latest versions
Container images
732
deployed by those charts
Fix available
3 of 3
affected packages

liblzma5-32bit-5.8.1-1.1 on GA media

Carried by container images the latest versions of 657 of 17,787 indexed charts deploy, on 732 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.4.1-0.2, 5.6.1+really5.4.5-1, 5.6.1+really5.4.5-1build0.15.4.1-1, 5.6.1+really5.4.5-1ubuntu0.2487
xzapk5.4.3-r0, 5.4.3-r1, 5.4.5-r0, 5.6.1-r3+2 more5.4.3-r1, 5.4.5-r1, 5.6.2-r1, 5.6.3-r1+1 more243
xzrpm5.2.3-lp151.4.3.15.8.1-1.12
OSV records
ALPINE-CVE-2025-31115DEBIAN-CVE-2025-31115UBUNTU-CVE-2025-31115openSUSE-SU-2025:14984-1
Also known as
DSA-5895-1, USN-7414-1

Charts affected

657 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
xz-utils@5.4.1-0.2
5.4.1-1

Open the chart page →

7,685
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
xz-utils@5.4.1-0.2
5.4.1-1
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
xz@5.6.2-r0
5.6.2-r1
hamzaarshad10/querypodpy:1.7154f38e8668e
xz-utils@5.4.1-0.2
5.4.1-1
murtazashah46/helmfile:latest4d11726cf803
xz-utils@5.4.1-0.2
5.4.1-1

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.2

Open the chart page →

2,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
xz-utils@5.4.1-0.2
5.4.1-1

Open the chart page →

2,674
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
xz@5.4.3-r0
5.4.3-r1

Open the chart page →

448
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
xz@5.4.3-r0
5.4.3-r1

Open the chart page →

1,588
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
xz@5.4.5-r0
5.4.5-r1

Open the chart page →

569

Container images carrying it

732 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
xz-utils@5.4.1-0.2
5.4.1-1
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
xz-utils@5.4.1-0.2
5.4.1-1
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
xz-utils@5.4.1-0.2
5.4.1-1
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
xz-utils@5.4.1-0.2
5.4.1-1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
xz-utils@5.4.1-0.2
5.4.1-1
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
xz-utils@5.4.1-0.2
5.4.1-1
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
xz@5.4.5-r0
5.4.5-r1
1
quay.io/frrouting/frr:9.0.2086acb1278fe
xz@5.4.3-r0
5.4.3-r1
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
xz@5.6.3-r0
5.6.3-r1
1
quay.io/kiwigrid/k8s-sidecar:1.25.2cb4c638ffb1f
xz@5.4.3-r0
5.4.3-r1
1
quay.io/maxiv/storageclass-router:0.4.160725dab588c
xz@5.4.5-r0
5.4.5-r1
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
xz@5.6.1-r3
5.6.2-r1
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
xz-utils@5.4.1-0.2
5.4.1-1
1
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
xz@5.4.3-r0
5.4.3-r1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
xz-utils@5.4.1-0.2
5.4.1-1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
xz-utils@5.4.1-0.2
5.4.1-1
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
xz@5.4.5-r0
5.4.5-r1
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
xz@5.4.3-r0
5.4.3-r1
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
xz@5.6.2-r0
5.6.2-r1
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
xz@5.4.5-r0
5.4.5-r1
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
xz@5.6.3-r0
5.6.3-r1
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
xz-utils@5.4.1-0.2
5.4.1-1
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
xz-utils@5.4.1-0.2
5.4.1-1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.