StackRadar

CVE-2025-32989

Medium

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
875
of 17,787 indexed, latest versions
Container images
946
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 875 of 17,787 indexed charts deploy, on 946 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.7.3-4ubuntu1, 3.7.3-4ubuntu1.1, 3.7.3-4ubuntu1.2, 3.7.3-4ubuntu1.3+15 more3.7.3-4ubuntu1.7, 3.7.9-2+deb12u5, 3.8.3-1.1ubuntu3.4, 3.8.3-1.1ubuntu3.4+Fips1920
gnutlsapk3.8.5-r0, 3.8.8-r03.8.12-r026
OSV records
ALPINE-CVE-2025-32989DEBIAN-CVE-2025-32989UBUNTU-CVE-2025-32989
Also known as
USN-7635-1

Charts affected

875 by stars
ChartLatestAffected imagesRadar Score
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.4+Fips1

Open the chart page →

4,305
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
library/mariadb:12.0-noble607835cd628b
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.4+Fips1

Open the chart page →

4,054
twenty-crmvictorlane0.0.12 of 3See more

twenty-crm victorlane 0.0.1

2 of the 3 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
redis/redis-stack-server:latest798ab84d9f26
gnutls28@3.7.3-4ubuntu1.7
no fix listed
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.7

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.4+Fips1

Open the chart page →

7,628
eth-validatorwateim1.4.52 of 3See more

eth-validator wateim 1.4.5

2 of the 3 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
sigp/lighthouse:latest9a62bb870545
gnutls28@3.7.3-4ubuntu1.9
no fix listed
wateim/lighthouse-launch:latest2520149ee574
gnutls28@3.7.3-4ubuntu1.5
3.7.3-4ubuntu1.7

Open the chart page →

4,998
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u5

Open the chart page →

5,984
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.7

Open the chart page →

6,232
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u5

Open the chart page →

7,085
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.4+Fips1

Open the chart page →

9,130
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.4+Fips1

Open the chart page →

9,130
web-dvwaweb-dvwa1.16.02 of 2See more

web-dvwa web-dvwa 1.16.0

2 of the 2 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
gnutls28@3.7.9-2
3.7.9-2+deb12u5
library/mariadb:10ce66c7be32a0
gnutls28@3.7.3-4ubuntu1.9
no fix listed

Open the chart page →

10,001
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5

Open the chart page →

2,678
apisixwenerme2.17.01 of 3See more

apisix wenerme 2.17.0

1 of the 3 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u5

Open the chart page →

3,045
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u5

Open the chart page →

9,117
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.7
openebs/node-disk-operator:2.1.06afe2123c457
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.7

Open the chart page →

10,489
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.7.45f2a56b95266
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u5

Open the chart page →

14,983
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
gnutls28@3.7.3-4ubuntu1.3
3.7.3-4ubuntu1.7

Open the chart page →

9,248
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u5

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
gnutls28@3.7.3-4ubuntu1.5
3.7.3-4ubuntu1.7

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u5

Open the chart page →

7,673
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
hamzaarshad10/querypodpy:1.7154f38e8668e
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
murtazashah46/helmfile:latest4d11726cf803
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5

Open the chart page →

13,677
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.4

Open the chart page →

2,097
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u5

Open the chart page →

2,661
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-32989.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
gnutls28@3.7.3-4ubuntu1.9
no fix listed

Open the chart page →

7,849

Container images carrying it

946 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
freeradius/freeradius-server:3.2.8af6fd34a5b78
gnutls28@3.7.3-4ubuntu1.7
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u5
1
gchq/accumulo:2.0.1c460bb587d6d
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.4
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
gnutls@3.8.8-r0
3.8.12-r0
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
gnutls28@3.7.3-4ubuntu1.8
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
gnutls28@3.7.3-4ubuntu1.6
3.7.3-4ubuntu1.7
1
getsentry/relay:24.10.0ba7bf9163219
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
gitea/gitea:1.22.376f516a1a8c2
gnutls@3.8.5-r0
3.8.12-r0
1
glasskube/operator:0.12.2be5133100d63
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.7
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
gnutls28@3.7.3-4ubuntu1.6
3.7.3-4ubuntu1.7
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
gnutls28@3.7.9-2
3.7.9-2+deb12u5
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
gnutls28@3.7.9-2
3.7.9-2+deb12u5
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
gnutls28@3.7.9-2
3.7.9-2+deb12u5
1
gradiant/open5gs-dbctl:0.10.3332031245fce
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.4
1
grafana/agent:v0.44.23364714a2f64
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.4
1
grafana/alloy:v1.5.101a63f4e032c
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.4
1
grafana/alloy:v1.4.306bdcbb51fc2
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.4
1
grafana/alloy:v1.11.38c7256f412fe
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.4+Fips1
1
grafana/beyla:1.3.336d07f8d276e
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u5
1
grafana/promtail:3.5.165bfae480b57
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.4
1
grafana/promtail:3.6.18dcfdf466da0
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.4+Fips1
1
graphprotocol/graph-node:latestb0436347fb24
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
graphprotocol/graph-node:v0.37.0f4452cdedd68
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
graylog/graylog:6.1.1019de1aff48c2
gnutls28@3.7.3-4ubuntu1.6
3.7.3-4ubuntu1.7
1
guacamole/guacamole:1.5.50f62f6d17ab3
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.7
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
gulacedia/web-dvwa-new:v367b467d961ca
gnutls28@3.7.9-2
3.7.9-2+deb12u5
1
hamidyousefi93/saam-test:latestc34f071f6ed0
gnutls28@3.7.9-2
3.7.9-2+deb12u5
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
hamzaarshad10/querypodpy:1.7154f38e8668e
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
hansehe/locust:1.1.0bc8e45262bc4
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u5
1
hashicorp/boundary:0.21.037bf86488b74
gnutls@3.8.8-r0
3.8.12-r0
1
hassroutyyoussef/accountservice:latest1f01edf1ee0c
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
hassroutyyoussef/orderservice:latest2fc3d1617928
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
hassroutyyoussef/userservice:lateste0392e2b4a90
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.7
1
hasura/graphql-engine:v2.48.10f6c1c4b957d2
gnutls28@3.7.3-4ubuntu1.7
no fix listed
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u5
1
hazegoodlife/haaze:milksite8d4c63169e14
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u5
1
headwindmdm/hmdm:0.1.93550b4840840
gnutls28@3.7.3-4ubuntu1.9
no fix listed
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u5
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
gnutls28@3.7.9-2
3.7.9-2+deb12u5
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u5
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.7
1
hiversh/gateway:0.1.45839226cc6e41
gnutls28@3.7.3-4ubuntu1.7
no fix listed
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
gnutls28@3.7.9-2
3.7.9-2+deb12u5
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
gnutls28@3.7.9-2
3.7.9-2+deb12u5
1
hmediade/printserver:latest481a552c8e1c
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.7
1
hmediade/printserver-init:latest7f005eb6c718
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.7
1
hyperglance/init:wildfly467ad8491bc3
gnutls28@3.7.3-4ubuntu1.8
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.