StackRadar

CVE-2025-31672

Medium

Advisory

Published 9 Apr 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
35
of 17,781 indexed, latest versions
Container images
33
deployed by those charts
Fix available
1 of 1
affected package

Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing

Carried by container images the latest versions of 35 of 17,781 indexed charts deploy, on 33 images.

Affected packageAffected versionsFixed inImages
poi-ooxmlmaven3.9, 3.12, 3.14, 3.15+7 more5.4.033
OSV records
GHSA-gmg8-593g-7mv3

Charts affected

35 by stars
ChartLatestAffected imagesRadar Score
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
poi-ooxml@3.17
5.4.0

Open the chart page →

6,328
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
poi-ooxml@4.1.2
5.4.0

Open the chart page →

6,048
seafiledatamateVerified publisher0.6.02 of 6See more

seafile datamate 0.6.0

2 of the 6 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
poi-ooxml@5.2.3
5.4.0
datamate/seafile-professional:11.0.202dd66b722464
poi-ooxml@5.2.3
5.4.0

Open the chart page →

27,267
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
poi-ooxml@4.1.2
5.4.0
apache/hertzbeat-collector:1.8.0a2bab1be574c
poi-ooxml@4.1.2
5.4.0

Open the chart page →

14,000
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
library/elasticsearch:8.15.0310b9fc03b06
poi-ooxml@5.2.5
5.4.0

Open the chart page →

13,521
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
poi-ooxml@3.17
5.4.0

Open the chart page →

6,328
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
poi-ooxml@5.2.3
5.4.0

Open the chart page →

28,534
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
poi-ooxml@5.2.2
5.4.0

Open the chart page →

7,740
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
poi-ooxml@4.1.2
5.4.0

Open the chart page →

38,346
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
poi-ooxml@4.1.2
5.4.0

Open the chart page →

6,110
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
poi-ooxml@3.15
5.4.0

Open the chart page →

11,553
traccarjeffrescVerified publisher0.2.01 of 2See more

traccar jeffresc 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
traccar/traccar:6.7-alpine621c8d6d46fd
poi-ooxml@5.2.2
5.4.0

Open the chart page →

1,341
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
poi-ooxml@5.2.3
5.4.0

Open the chart page →

37,373
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
poi-ooxml@4.1.2
5.4.0

Open the chart page →

24,930
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
airbyte/server:2.2.070e125498a1c
poi-ooxml@5.3.0
5.4.0

Open the chart page →

12,473
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
poi-ooxml@3.15
5.4.0

Open the chart page →

11,553
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
poi-ooxml@5.2.2
5.4.0

Open the chart page →

4,145
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
poi-ooxml@3.9
5.4.0

Open the chart page →

9,722
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
poi-ooxml@3.14
5.4.0

Open the chart page →

9,808
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
poi-ooxml@4.1.2
5.4.0

Open the chart page →

8,245
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
poi-ooxml@3.12
5.4.0

Open the chart page →

27,949
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
poi-ooxml@4.0.1
5.4.0

Open the chart page →

26,944
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
poi-ooxml@5.2.2
5.4.0

Open the chart page →

9,920
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
poi-ooxml@4.1.2
5.4.0

Open the chart page →

37,671
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
poi-ooxml@5.2.3
5.4.0

Open the chart page →

1,754
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
poi-ooxml@4.1.2
5.4.0

Open the chart page →

4,664
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
poi-ooxml@4.1.2
5.4.0

Open the chart page →

6,490
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
poi-ooxml@5.2.5
5.4.0

Open the chart page →

4,257
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
poi-ooxml@5.2.3
5.4.0

Open the chart page →

3,683
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
poi-ooxml@3.12
5.4.0

Open the chart page →

55,726
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
poi-ooxml@3.17
5.4.0

Open the chart page →

3,633
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
poi-ooxml@4.1.2
5.4.0

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
poi-ooxml@4.1.2
5.4.0

Open the chart page →

8,806
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
poi-ooxml@5.2.3
5.4.0

Open the chart page →

9,397
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-31672.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
poi-ooxml@5.2.3
5.4.0

Open the chart page →

3,480

Container images carrying it

33 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
poi-ooxml@4.1.2
5.4.0
3
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
poi-ooxml@3.17
5.4.0
2
mbentley/omada-controller:4.3f4e682274bed
poi-ooxml@3.15
5.4.0
2
airbyte/server:2.2.070e125498a1c
poi-ooxml@5.3.0
5.4.0
1
apache/drill:1.21.11f96558fd292
poi-ooxml@5.2.3
5.4.0
1
apache/hertzbeat:1.8.075d48a62748f
poi-ooxml@4.1.2
5.4.0
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
poi-ooxml@4.1.2
5.4.0
1
apache/ranger:2.7.076c176e8a0e4
poi-ooxml@5.2.2
5.4.0
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
poi-ooxml@5.2.2
5.4.0
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
poi-ooxml@5.2.3
5.4.0
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
poi-ooxml@5.2.3
5.4.0
1
choerodon/event-store-service:0.8.03c94c97f6f69
poi-ooxml@3.14
5.4.0
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
poi-ooxml@5.2.2
5.4.0
1
datamate/seafile-professional:11.0.202dd66b722464
poi-ooxml@5.2.3
5.4.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
poi-ooxml@4.1.2
5.4.0
1
easypi/openrefine:3.7.0d2950a36a576
poi-ooxml@5.2.3
5.4.0
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
poi-ooxml@4.1.2
5.4.0
1
kubebb/gateway-api:v5.6.04d062f20309c
poi-ooxml@4.1.2
5.4.0
1
kubebb/mesh-api:v5.7.0a3879931dfa1
poi-ooxml@4.1.2
5.4.0
1
library/elasticsearch:8.17.32cc40b15dff8
poi-ooxml@5.2.5
5.4.0
1
library/elasticsearch:8.15.0310b9fc03b06
poi-ooxml@5.2.5
5.4.0
1
library/solr:8.7.0d124efd81fbb
poi-ooxml@4.1.2
5.4.0
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
poi-ooxml@5.2.3
5.4.0
1
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
poi-ooxml@3.12
5.4.0
1
openkm/openkm-ce:6.3.113bc465a7461b
poi-ooxml@3.12
5.4.0
1
owasp/dependency-track:3.8.0efc65e702ee1
poi-ooxml@3.17
5.4.0
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
poi-ooxml@3.9
5.4.0
1
sismics/docs:v1.10f4b0ef019cf1
poi-ooxml@4.0.1
5.4.0
1
thmmniii/fbs-core:v1.27.15438517d9fc2
poi-ooxml@5.2.3
5.4.0
1
traccar/traccar:6.7-alpine621c8d6d46fd
poi-ooxml@5.2.2
5.4.0
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
poi-ooxml@5.2.3
5.4.0
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
poi-ooxml@4.1.2
5.4.0
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
poi-ooxml@4.1.2
5.4.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.