StackRadar

CVE-2025-31115

High

Advisory

Published 3 Apr 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
657
of 17,787 indexed, latest versions
Container images
732
deployed by those charts
Fix available
3 of 3
affected packages

liblzma5-32bit-5.8.1-1.1 on GA media

Carried by container images the latest versions of 657 of 17,787 indexed charts deploy, on 732 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.4.1-0.2, 5.6.1+really5.4.5-1, 5.6.1+really5.4.5-1build0.15.4.1-1, 5.6.1+really5.4.5-1ubuntu0.2487
xzapk5.4.3-r0, 5.4.3-r1, 5.4.5-r0, 5.6.1-r3+2 more5.4.3-r1, 5.4.5-r1, 5.6.2-r1, 5.6.3-r1+1 more243
xzrpm5.2.3-lp151.4.3.15.8.1-1.12
OSV records
ALPINE-CVE-2025-31115DEBIAN-CVE-2025-31115UBUNTU-CVE-2025-31115openSUSE-SU-2025:14984-1
Also known as
DSA-5895-1, USN-7414-1

Charts affected

657 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
xz-utils@5.4.1-0.2
5.4.1-1

Open the chart page →

7,685
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
xz-utils@5.4.1-0.2
5.4.1-1
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
xz@5.6.2-r0
5.6.2-r1
hamzaarshad10/querypodpy:1.7154f38e8668e
xz-utils@5.4.1-0.2
5.4.1-1
murtazashah46/helmfile:latest4d11726cf803
xz-utils@5.4.1-0.2
5.4.1-1

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.2

Open the chart page →

2,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
xz-utils@5.4.1-0.2
5.4.1-1

Open the chart page →

2,674
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
xz@5.4.3-r0
5.4.3-r1

Open the chart page →

448
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
xz@5.4.3-r0
5.4.3-r1

Open the chart page →

1,588
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
xz@5.4.5-r0
5.4.5-r1

Open the chart page →

569

Container images carrying it

732 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
moreillon/user-manager-front:v5.1.06597e6b98d21
xz-utils@5.4.1-0.2
5.4.1-1
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
xz-utils@5.4.1-0.2
5.4.1-1
1
muhammedgamal/fp23:latest74b4cd69b6fa
xz-utils@5.4.1-0.2
5.4.1-1
1
murtazashah46/helmfile:latest4d11726cf803
xz-utils@5.4.1-0.2
5.4.1-1
1
mvance/unbound:1.20.04bf67b567f39
xz-utils@5.4.1-0.2
5.4.1-1
1
mvance/unbound:1.22.076906da36d18
xz-utils@5.4.1-0.2
5.4.1-1
1
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
xz@5.4.5-r0
5.4.5-r1
1
nginxinc/nginx-unprivileged8f14986c54fa
xz@5.4.5-r0
5.4.5-r1
1
nirmalnaveen/supermario:latest8541a39162f3
xz-utils@5.4.1-0.2
5.4.1-1
1
nodered/node-red:3.0.2-18e2632a7a35dd
xz@5.4.5-r0
5.4.5-r1
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
xz@5.6.2-r0
5.6.2-r1
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/asr:1.025dd26d9cd09
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/chatqna:1.038c51b791efa
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/chatqna-conversation-ui:v0.9bdb9ec215872
xz@5.6.2-r0
5.6.2-r1
1
opea/codegen:1.058f91683892d
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/codegen-ui:1.02bee4eb66f3e
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/codetrans:1.0e2436483b73d
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/codetrans-ui:1.03ef121f34610
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/docsum:1.03eaa91849512
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/docsum-ui:1.07f854e9bffaf
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/guardrails-tgi:1.0262c6048aab8
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/guardrails-tgi:latestf68bec6a1271
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/speecht5:1.0249afad3d268
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/tts:1.0257ae94709e9
xz-utils@5.4.1-0.2
5.4.1-1
1
opea/web-retriever-chroma:1.0fe08165d7770
xz-utils@5.4.1-0.2
5.4.1-1
1
openbas/caldera-server:5.1.0a277796d9724
xz-utils@5.4.1-0.2
5.4.1-1
1
opencsghq/csghub-portal:v2.4.0-ee93ad59164d87
xz-utils@5.4.1-0.2
5.4.1-1
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
xz-utils@5.4.1-0.2
5.4.1-1
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
xz-utils@5.4.1-0.2
5.4.1-1
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
xz@5.4.5-r0
5.4.5-r1
1
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
xz@5.6.2-r0
5.6.2-r1
1
openruntimes/executor:0.11.42228f186dcbb
xz@5.4.5-r0
5.4.5-r1
1
outlinewiki/outline:0.82.0494dfb9249a6
xz-utils@5.4.1-0.2
5.4.1-1
1
phan2410/dummy-service:0.0.89c6ed6de26ca
xz-utils@5.4.1-0.2
5.4.1-1
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
xz-utils@5.4.1-0.2
5.4.1-1
1
photoprism/photoprism:240711-cefc6fd632ca74
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.2
1
phpipam/phpipam-cron:v1.7.354468713454e
xz@5.6.2-r0
5.6.2-r1
1
phpipam/phpipam-www:v1.7.3ace0efd24830
xz@5.6.2-r0
5.6.2-r1
1
phsmith/rundeck-exporter:2.6.10265a7616ae8
xz@5.4.3-r0
5.4.3-r1
1
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
xz@5.4.5-r0
5.4.5-r1
1
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
xz@5.4.5-r0
5.4.5-r1
1
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
xz@5.4.5-r0
5.4.5-r1
1
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
xz@5.4.5-r0
5.4.5-r1
1
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
xz@5.6.2-r0
5.6.2-r1
1
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
xz@5.6.2-r0
5.6.2-r1
1
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
xz@5.6.2-r0
5.6.2-r1
1
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
xz@5.6.2-r0
5.6.2-r1
1
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
xz@5.6.2-r0
5.6.2-r1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.