CVE-2025-31115
HighAdvisory
Published 3 Apr 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.7
- base score, highest
- EPSS
- 0.007
- 49th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 651
- of 17,787 indexed, latest versions
- Container images
- 726
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
liblzma5-32bit-5.8.1-1.1 on GA media
Carried by container images the latest versions of 651 of 17,787 indexed charts deploy, on 726 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| xz-utilsdeb | 5.4.1-0.2, 5.6.1+really5.4.5-1, 5.6.1+really5.4.5-1build0.1 | 5.4.1-1, 5.6.1+really5.4.5-1ubuntu0.2 | 482 |
| xzapk | 5.4.3-r0, 5.4.3-r1, 5.4.5-r0, 5.6.1-r3+2 more | 5.4.3-r1, 5.4.5-r1, 5.6.2-r1, 5.6.3-r1+1 more | 242 |
| xzrpm | 5.2.3-lp151.4.3.1 | 5.8.1-1.1 | 2 |
- OSV records
- ALPINE-CVE-2025-31115DEBIAN-CVE-2025-31115UBUNTU-CVE-2025-31115openSUSE-SU-2025:14984-1
- Also known as
- DSA-5895-1, USN-7414-1
Charts affected
651 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| zerossl-cert-managerzerossl-cert-manager | 0.1.0 | 1 of 2See more | 570 |
Container images carrying it
726 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.