StackRadar

CVE-2025-31115

High

Advisory

Published 3 Apr 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
654
of 17,781 indexed, latest versions
Container images
729
deployed by those charts
Fix available
3 of 3
affected packages

liblzma5-32bit-5.8.1-1.1 on GA media

Carried by container images the latest versions of 654 of 17,781 indexed charts deploy, on 729 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.4.1-0.2, 5.6.1+really5.4.5-1, 5.6.1+really5.4.5-1build0.15.4.1-1, 5.6.1+really5.4.5-1ubuntu0.2485
xzapk5.4.3-r0, 5.4.3-r1, 5.4.5-r0, 5.6.1-r3+2 more5.4.3-r1, 5.4.5-r1, 5.6.2-r1, 5.6.3-r1+1 more242
xzrpm5.2.3-lp151.4.3.15.8.1-1.12
OSV records
ALPINE-CVE-2025-31115DEBIAN-CVE-2025-31115UBUNTU-CVE-2025-31115openSUSE-SU-2025:14984-1
Also known as
DSA-5895-1, USN-7414-1

Charts affected

654 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
xz-utils@5.4.1-0.2
5.4.1-1

Open the chart page →

2,661
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
xz@5.4.3-r0
5.4.3-r1

Open the chart page →

448
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
xz@5.4.3-r0
5.4.3-r1

Open the chart page →

1,589
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-31115.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
xz@5.4.5-r0
5.4.5-r1

Open the chart page →

570

Container images carrying it

729 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
xz@5.6.2-r0
5.6.2-r1
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
xz-utils@5.4.1-0.2
5.4.1-1
6
quay.io/devtron/postgres:14.91b594392f7cb
xz-utils@5.4.1-0.2
5.4.1-1
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
xz-utils@5.4.1-0.2
5.4.1-1
5
library/postgres:122f2a8c2a7d10
xz-utils@5.4.1-0.2
5.4.1-1
5
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
xz@5.4.3-r0
5.4.3-r1
5
bitnamilegacy/postgresql:16233f361c5819
xz-utils@5.4.1-0.2
5.4.1-1
4
library/nginx:1.27.1287ff321f9e3
xz-utils@5.4.1-0.2
5.4.1-1
4
opea/llm-tgi:1.00c25aab3f106
xz-utils@5.4.1-0.2
5.4.1-1
4
shashkist/flask-contacts-app:latest581de1fd6084
xz-utils@5.4.1-0.2
5.4.1-1
4
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
xz-utils@5.4.1-0.2
5.4.1-1
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
xz-utils@5.4.1-0.2
5.4.1-1
3
gchq/hdfs:3.3.35ec58edbb2db
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.2
3
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
xz@5.6.2-r0
5.6.2-r1
3
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
xz@5.6.3-r0
5.6.3-r1
3
library/docker:20.10-dind:20-dindaf96c680a7e1
xz@5.4.3-r0
5.4.3-r1
3
library/nginx:1.25.5-alpine:1.25-alpine516475cc129d
xz@5.4.5-r0
5.4.5-r1
3
library/nginx:1.25:1.25.5a484819eb602
xz-utils@5.4.1-0.2
5.4.1-1
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
xz@5.6.1-r3
5.6.2-r1
3
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
xz@5.4.3-r0
5.4.3-r1
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
xz@5.4.3-r0
5.4.3-r1
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
xz-utils@5.4.1-0.2
5.4.1-1
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
xz-utils@5.4.1-0.2
5.4.1-1
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
xz-utils@5.4.1-0.2
5.4.1-1
3
quay.io/devtron/ai-agent:0.0.16545dac92173
xz-utils@5.4.1-0.2
5.4.1-1
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.2
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.2
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.2
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.2
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.2
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.2
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.2
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
xz@5.4.3-r0
5.4.3-r1
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.2
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
xz-utils@5.4.1-0.2
5.4.1-1
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
xz-utils@5.4.1-0.2
5.4.1-1
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
xz-utils@5.4.1-0.2
5.4.1-1
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
xz@5.4.3-r0
5.4.3-r1
2
dtzar/helm-kubectl:3.14.455429449408e
xz@5.4.5-r0
5.4.5-r1
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
xz-utils@5.4.1-0.2
5.4.1-1
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
xz-utils@5.4.1-0.2
5.4.1-1
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
xz-utils@5.4.1-0.2
5.4.1-1
2
langgenius/dify-sandbox:0.2.009b7e8705673
xz-utils@5.4.1-0.2
5.4.1-1
2
library/nginx:1.27.098f8ec75657d
xz-utils@5.4.1-0.2
5.4.1-1
2
library/phpmyadmin:5.2.16e75aa8f767c
xz-utils@5.4.1-0.2
5.4.1-1
2
library/postgres:16.109f23e02d766
xz-utils@5.4.1-0.2
5.4.1-1
2
library/postgres:16.24aea012537ed
xz-utils@5.4.1-0.2
5.4.1-1
2
library/postgres:16.4e62fbf9d3e2b
xz-utils@5.4.1-0.2
5.4.1-1
2
library/postgres:11-alpineea50b9fd617b
xz@5.4.5-r0
5.4.5-r1
2
library/python:3.7eedf63967cdb
xz-utils@5.4.1-0.2
5.4.1-1
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.