StackRadar

CVE-2025-3576

Medium

Advisory

Published 15 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,559
of 17,790 indexed, latest versions
Container images
1,691
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 1,559 of 17,790 indexed charts deploy, on 1,691 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+40 more1.12+dfsg-2ubuntu5.4+esm7, 1.13.2+dfsg-5ubuntu2.2+esm7, 1.16-2ubuntu0.4+esm5, 1.17-6ubuntu4.11+4 more1,447
krb5rpm1.16.1-22.el8, 1.17-9.el8, 1.17-18.el8, 1.17-19.el8_2+25 more0:1.17-19.el8_2.3, 0:1.18.2-9.el8_4.3, 0:1.18.2-16.el8_6.4, 0:1.18.2-26.el8_8.5+5 more244
OSV records
DEBIAN-CVE-2025-3576RHSA-2025:13664RHSA-2025:13777RHSA-2025:15001RHSA-2025:15002RHSA-2025:15003RHSA-2025:15004RHSA-2025:8411RHSA-2025:9430RLSA-2025:8411RLSA-2025:9430UBUNTU-CVE-2025-3576DLA-4195-1SUSE-SU-2025:3699-1
Also known as
USN-7542-1

Charts affected

1,559 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7

Open the chart page →

14,173
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
krb5@1.18.2-14.el8
0:1.18.2-32.el8_10

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

7,697
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

13,783
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.6

Open the chart page →

2,142
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10

Open the chart page →

3,697

Container images carrying it

1,691 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
stratospire/activityrelay:0.2.3a4c34cb01117
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
subsquid/substrate-gateway:firesquid76a913993ed2
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
substratusai/verba:v0.4.0-baseURL261695be635eb
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
supabase/logflare:1.8.12d429005429ce
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
1
supabase/realtime:v2.33.8d207e6e23ad3
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
supabase/studio:20241021-9f9b08326d8070c55e9
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.11
1
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.11
1
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
sysnet4admin/colosseum-cms:loge74b43c7f492
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
1
t3nde/tideways:1.7.2777e008f764db
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
taigaio/taiga-back:6.4.29f97323cc150
krb5@1.18.3-6
1.18.3-6+deb11u7
1
tautulli/tautulli:v2.7.7c4da15f058ea
krb5@1.18.3-6
1.18.3-6+deb11u7
1
teknas09/bird-pod:latest12a1fa85c4aa
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
krb5@1.13.2+dfsg-5ubuntu2
1.13.2+dfsg-5ubuntu2.2+esm7
1
th0th/node-red:4.0.3-debiand06fa39f7406
krb5@1.18.3-6+deb11u5
1.18.3-6+deb11u7
1
thehiveproject/cortex:3.1.7f4bc64fb8844
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
theradius/loggia:0.463ba348546ec
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
thesisrobot/bitcoind:v23.016b368e4d52c
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
thingsboard/tb-js-executor:3.4.113e1eadf8ace
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
thingsboard/tb-node:3.4.1645f43b688f7
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
thingsboard/tb-node:3.6.0f40a542832c4
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
thingsboard/tb-web-ui:3.4.157f98ed53b3d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
thingsboard/tb-web-ui:3.6.0d388378062cc
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
thmmniii/fbs-core:v1.27.15438517d9fc2
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
thongngo3301/stakefish:latesta341af5976e3
krb5@1.20.1-2
1.20.1-2+deb12u4
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.7
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
krb5@1.19.2-2ubuntu0.5
1.19.2-2ubuntu0.7
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
krb5@1.13.2+dfsg-5ubuntu2
1.13.2+dfsg-5ubuntu2.2+esm7
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
torrespro/mca-worker:2.0.06d3bd305a1ba
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
tpdock/freeradius:2.2.93da600c95a49
krb5@1.13.2+dfsg-5ubuntu2
1.13.2+dfsg-5ubuntu2.2+esm7
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
trinodb/trino:45038c6f24ab1a4
krb5@1.21.1-1.el9
0:1.21.1-2.el9_4.2
1
trinodb/trino:405ee80ab5eeab2
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
typesense/typesense:0.25.1035ccfbc3fd8
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7
1
typesense/typesense:28.0.rc35dea1b62b7b6e
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.7
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.