StackRadar

CVE-2025-3576

Medium

Advisory

Published 15 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,559
of 17,787 indexed, latest versions
Container images
1,691
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 1,559 of 17,787 indexed charts deploy, on 1,691 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+40 more1.12+dfsg-2ubuntu5.4+esm7, 1.13.2+dfsg-5ubuntu2.2+esm7, 1.16-2ubuntu0.4+esm5, 1.17-6ubuntu4.11+4 more1,447
krb5rpm1.16.1-22.el8, 1.17-9.el8, 1.17-18.el8, 1.17-19.el8_2+25 more0:1.17-19.el8_2.3, 0:1.18.2-9.el8_4.3, 0:1.18.2-16.el8_6.4, 0:1.18.2-26.el8_8.5+5 more244
OSV records
DEBIAN-CVE-2025-3576RHSA-2025:13664RHSA-2025:13777RHSA-2025:15001RHSA-2025:15002RHSA-2025:15003RHSA-2025:15004RHSA-2025:8411RHSA-2025:9430RLSA-2025:8411RLSA-2025:9430UBUNTU-CVE-2025-3576DLA-4195-1SUSE-SU-2025:3699-1
Also known as
USN-7542-1

Charts affected

1,559 by stars
ChartLatestAffected imagesRadar Score
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.1.0-debian-11-r1529e3dd0e7e7a
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7

Open the chart page →

3,207
giteagiteaOfficialVerified publisher12.7.02 of 4See more

gitea gitea 12.7.0

2 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4

Open the chart page →

8,842
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7

Open the chart page →

6,597
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

11,372
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
krb5@1.18.2-14.el8
0:1.18.2-32.el8_10

Open the chart page →

7,713
dagsterdagsterVerified publisher1.13.221 of 5See more

dagster dagster 1.13.22

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/postgres:14.6f565573d74ae
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

3,459
graylogkong-zVerified publisher3.0.321 of 5See more

graylog kong-z 3.0.32

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
krb5@1.18.2-31.el8_10
0:1.18.2-32.el8_10

Open the chart page →

2,736
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
krb5@1.16-2ubuntu0.3
1.16-2ubuntu0.4+esm5

Open the chart page →

5,557
openldap-stack-hahelm-openldapVerified publisher4.3.31 of 5See more

openldap-stack-ha helm-openldap 4.3.3

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

5,948
rocketchatrocketchat-server7.0.23 of 12See more

rocketchat rocketchat-server 7.0.2

3 of the 12 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
bitnamilegacy/os-shell:11-debian-11-r722cb5982dcbf4
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

12,283
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
krb5@1.19.2-2
1.19.2-2ubuntu0.7

Open the chart page →

9,194
milvusmilvus4.0.314 of 5See more

milvus milvus 4.0.31

4 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
milvusdb/etcd:3.5.5-r2102aac62827b
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
milvusdb/milvus:v2.2.13a3a55e1c1497
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10

Open the chart page →

32,353
clearmlallegroaiOfficialVerified publisher7.15.02 of 4See more

clearml allegroai 7.15.0

2 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

10,648
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7

Open the chart page →

7,582
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

2,660
community-operatormongodb-helm-charts0.13.01 of 1See more

community-operator mongodb-helm-charts 0.13.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
krb5@1.18.2-31.el8_10
0:1.18.2-32.el8_10

Open the chart page →

1,126
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

4,808
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

6,949
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

22,115
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
krb5@1.18.2-30.el8_10
0:1.18.2-32.el8_10

Open the chart page →

924
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
krb5@1.13.2+dfsg-5ubuntu2.1
1.13.2+dfsg-5ubuntu2.2+esm7
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
krb5@1.13.2+dfsg-5ubuntu2.1
1.13.2+dfsg-5ubuntu2.2+esm7

Open the chart page →

23,992
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.03 of 5See more

openproject openproject-helm-charts 13.11.0

3 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
openproject/hocuspocus:release-338001b288dc1359dfb5
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4

Open the chart page →

19,998
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
krb5@1.19.2-2
1.19.2-2ubuntu0.7
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
krb5@1.19.2-2
1.19.2-2ubuntu0.7
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
krb5@1.19.2-2
1.19.2-2ubuntu0.7
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
krb5@1.19.2-2
1.19.2-2ubuntu0.7

Open the chart page →

33,907
chatwootchatwootVerified publisher2.0.242 of 3See more

chatwoot chatwoot 2.0.24

2 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

9,204
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
krb5@1.20.1-2
1.20.1-2+deb12u4

Open the chart page →

3,700
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

6,550
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

8,387
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4

Open the chart page →

6,012
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7

Open the chart page →

12,830
dependency-trackevryfs-ossVerified publisher1.5.51 of 3See more

dependency-track evryfs-oss 1.5.5

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7

Open the chart page →

2,503
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
krb5@1.20.1-6ubuntu2.1
1.20.1-6ubuntu2.6

Open the chart page →

3,422
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
krb5@1.16-2ubuntu0.2
1.16-2ubuntu0.4+esm5

Open the chart page →

15,607
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11

Open the chart page →

7,917
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3

Open the chart page →

6,853
docker-mailserverdocker-mailserver0.4.01 of 2See more

docker-mailserver docker-mailserver 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
mailserver/docker-mailserver:11.0.0e0809756dc96
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

1,382
flagsmithflagsmithOfficialVerified publisher0.83.01 of 4See more

flagsmith flagsmith 0.83.0

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

2,110
glasskube-operatorglasskubeOfficialVerified publisher0.12.23 of 3See more

glasskube-operator glasskube 0.12.2

3 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5

Open the chart page →

11,971
milvusmilvus-helm5.0.281 of 4See more

milvus milvus-helm 5.0.28

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.7

Open the chart page →

10,764
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11

Open the chart page →

18,570
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
krb5@1.18.2-26.el8_9
0:1.18.2-32.el8_10

Open the chart page →

6,675
codefreshcodefresh-onpremOfficialVerified publisher2.12.133 of 42See more

codefresh codefresh-onprem 2.12.13

3 of the 42 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
bitnamilegacy/rabbitmq:4.1.39e635efba431
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4

Open the chart page →

14,615
loki-simple-scalablegrafana1.8.111 of 3See more

loki-simple-scalable grafana 1.8.11

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

6,470
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.3.21f104ee51e512
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7

Open the chart page →

3,004
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2api:3.86f56d239d280
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2auth:3.833ecfda16608
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2notifier:3.8f190a6212195
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2rulesengine:3.8259503496ff9
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2scheduler:3.8b1de2055c362
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2sensorcontainer:3.8b1a338f64773
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2stream:3.81c8904a3bf67
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2timersengine:3.81bf35bfaf00c
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2web:3.809989a26c8b7
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2workflowengine:3.819fdfffdbba8
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
supabase/logflare:1.8.12d429005429ce
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
supabase/realtime:v2.33.8d207e6e23ad3
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
supabase/studio:20241021-9f9b08326d8070c55e9
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

23,263
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

8,530
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
krb5@1.18.3-6+deb11u5
1.18.3-6+deb11u7

Open the chart page →

3,004
adminercetic0.2.11 of 1See more

adminer cetic 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/adminer:4.8.1-standalone34d37131366c
krb5@1.18.3-6+deb11u5
1.18.3-6+deb11u7

Open the chart page →

461
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
krb5@1.19.2-2
1.19.2-2ubuntu0.7

Open the chart page →

3,493
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.7

Open the chart page →

7,896

Container images carrying it

1,691 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/contactcatalogus-nginx:latest480c84fa9e63
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/digispoof-interface-nginx:latest8fa4597217a4
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/eav-component-nginx:latestd785c893096c
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/education-component-nginx:latest38900bc76ee0
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/medewerkercatalogus-nginx:latest06c3b27462e6
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/skeleton-pip:devce1ebe9387a2
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/user-component-nginx:latestb721579df8c3
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/waardepapieren-nginx:latestaf31cf6cd59f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
krb5@1.18.2-14.el8
0:1.18.2-32.el8_10
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
krb5@1.18.2-26.el8_9
0:1.18.2-32.el8_10
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
ghcr.io/cunningpike/fediblockhole:0.4.22abc5f0350dc
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
ghcr.io/dask/dask:2024.1.0080150de7d86
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
1
ghcr.io/dask/dask-gateway-server:2024.1.0881e7acfc5a0
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
krb5@1.20.1-6ubuntu2.2
1.20.1-6ubuntu2.6
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
krb5@1.18.2-14.el8
0:1.18.2-32.el8_10
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
krb5@1.18.2-14.el8
0:1.18.2-32.el8_10
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
krb5@1.18.2-21.el8
0:1.18.2-32.el8_10
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
krb5@1.19.1-23.el9_1
0:1.21.1-8.el9_6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.