StackRadar

CVE-2025-3576

Medium

Advisory

Published 15 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,546
of 17,781 indexed, latest versions
Container images
1,679
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 1,546 of 17,781 indexed charts deploy, on 1,679 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+40 more1.12+dfsg-2ubuntu5.4+esm7, 1.13.2+dfsg-5ubuntu2.2+esm7, 1.16-2ubuntu0.4+esm5, 1.17-6ubuntu4.11+4 more1,436
krb5rpm1.16.1-22.el8, 1.17-9.el8, 1.17-18.el8, 1.17-19.el8_2+25 more0:1.17-19.el8_2.3, 0:1.18.2-9.el8_4.3, 0:1.18.2-16.el8_6.4, 0:1.18.2-26.el8_8.5+5 more243
OSV records
DEBIAN-CVE-2025-3576RHSA-2025:13664RHSA-2025:13777RHSA-2025:15001RHSA-2025:15002RHSA-2025:15003RHSA-2025:15004RHSA-2025:8411RHSA-2025:9430RLSA-2025:8411RLSA-2025:9430UBUNTU-CVE-2025-3576DLA-4195-1SUSE-SU-2025:3699-1
Also known as
USN-7542-1

Charts affected

1,546 by stars
ChartLatestAffected imagesRadar Score
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.1.0-debian-11-r1529e3dd0e7e7a
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7

Open the chart page →

3,195
giteagiteaOfficialVerified publisher12.7.02 of 4See more

gitea gitea 12.7.0

2 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4

Open the chart page →

8,811
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7

Open the chart page →

6,556
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

11,367
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
krb5@1.18.2-14.el8
0:1.18.2-32.el8_10

Open the chart page →

7,713
dagsterdagsterVerified publisher1.13.221 of 5See more

dagster dagster 1.13.22

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/postgres:14.6f565573d74ae
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

3,455
graylogkong-zVerified publisher3.0.321 of 5See more

graylog kong-z 3.0.32

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
krb5@1.18.2-31.el8_10
0:1.18.2-32.el8_10

Open the chart page →

2,699
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
krb5@1.16-2ubuntu0.3
1.16-2ubuntu0.4+esm5

Open the chart page →

5,552
openldap-stack-hahelm-openldapVerified publisher4.3.31 of 5See more

openldap-stack-ha helm-openldap 4.3.3

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

5,919
rocketchatrocketchat-server7.0.23 of 12See more

rocketchat rocketchat-server 7.0.2

3 of the 12 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
bitnamilegacy/os-shell:11-debian-11-r722cb5982dcbf4
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

12,279
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
krb5@1.19.2-2
1.19.2-2ubuntu0.7

Open the chart page →

9,145
milvusmilvus4.0.314 of 5See more

milvus milvus 4.0.31

4 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
milvusdb/etcd:3.5.5-r2102aac62827b
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
milvusdb/milvus:v2.2.13a3a55e1c1497
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10

Open the chart page →

32,259
clearmlallegroaiOfficialVerified publisher7.15.02 of 4See more

clearml allegroai 7.15.0

2 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

10,622
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7

Open the chart page →

7,568
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

2,800
community-operatormongodb-helm-charts0.13.01 of 1See more

community-operator mongodb-helm-charts 0.13.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
krb5@1.18.2-31.el8_10
0:1.18.2-32.el8_10

Open the chart page →

1,127
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

4,802
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

6,927
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

22,002
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
krb5@1.18.2-30.el8_10
0:1.18.2-32.el8_10

Open the chart page →

925
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
krb5@1.13.2+dfsg-5ubuntu2.1
1.13.2+dfsg-5ubuntu2.2+esm7
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
krb5@1.13.2+dfsg-5ubuntu2.1
1.13.2+dfsg-5ubuntu2.2+esm7

Open the chart page →

23,964
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.03 of 5See more

openproject openproject-helm-charts 13.11.0

3 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
openproject/hocuspocus:release-338001b288dc1359dfb5
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4

Open the chart page →

19,926
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
krb5@1.19.2-2
1.19.2-2ubuntu0.7
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
krb5@1.19.2-2
1.19.2-2ubuntu0.7
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
krb5@1.19.2-2
1.19.2-2ubuntu0.7
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
krb5@1.19.2-2
1.19.2-2ubuntu0.7

Open the chart page →

33,725
chatwootchatwootVerified publisher2.0.242 of 3See more

chatwoot chatwoot 2.0.24

2 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

9,203
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
krb5@1.20.1-2
1.20.1-2+deb12u4

Open the chart page →

4,293
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

6,543
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

8,364
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4

Open the chart page →

5,987
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7

Open the chart page →

12,746
dependency-trackevryfs-ossVerified publisher1.5.51 of 3See more

dependency-track evryfs-oss 1.5.5

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7

Open the chart page →

2,503
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
krb5@1.20.1-6ubuntu2.1
1.20.1-6ubuntu2.6

Open the chart page →

3,382
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
krb5@1.16-2ubuntu0.2
1.16-2ubuntu0.4+esm5

Open the chart page →

15,592
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11

Open the chart page →

7,880
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3

Open the chart page →

6,854
docker-mailserverdocker-mailserver0.4.01 of 2See more

docker-mailserver docker-mailserver 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
mailserver/docker-mailserver:11.0.0e0809756dc96
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

1,382
flagsmithflagsmithOfficialVerified publisher0.83.01 of 4See more

flagsmith flagsmith 0.83.0

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

2,110
glasskube-operatorglasskubeOfficialVerified publisher0.12.23 of 3See more

glasskube-operator glasskube 0.12.2

3 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5

Open the chart page →

11,933
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.7

Open the chart page →

10,670
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11

Open the chart page →

18,509
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
krb5@1.18.2-26.el8_9
0:1.18.2-32.el8_10

Open the chart page →

6,675
codefreshcodefresh-onpremOfficialVerified publisher2.12.133 of 42See more

codefresh codefresh-onprem 2.12.13

3 of the 42 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
bitnamilegacy/rabbitmq:4.1.39e635efba431
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4

Open the chart page →

14,956
loki-simple-scalablegrafana1.8.111 of 3See more

loki-simple-scalable grafana 1.8.11

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

6,470
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.3.21f104ee51e512
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7

Open the chart page →

3,004
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2api:3.86f56d239d280
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2auth:3.833ecfda16608
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2notifier:3.8f190a6212195
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2rulesengine:3.8259503496ff9
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2scheduler:3.8b1de2055c362
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2sensorcontainer:3.8b1a338f64773
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2stream:3.81c8904a3bf67
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2timersengine:3.81bf35bfaf00c
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2web:3.809989a26c8b7
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11
stackstorm/st2workflowengine:3.819fdfffdbba8
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.11

Open the chart page →

96,419
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
supabase/logflare:1.8.12d429005429ce
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
supabase/realtime:v2.33.8d207e6e23ad3
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
supabase/studio:20241021-9f9b08326d8070c55e9
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

23,123
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

8,493
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
krb5@1.18.3-6+deb11u5
1.18.3-6+deb11u7

Open the chart page →

3,004
adminercetic0.2.11 of 1See more

adminer cetic 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/adminer:4.8.1-standalone34d37131366c
krb5@1.18.3-6+deb11u5
1.18.3-6+deb11u7

Open the chart page →

461
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
krb5@1.19.2-2
1.19.2-2ubuntu0.7

Open the chart page →

3,454
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.7

Open the chart page →

7,857

Container images carrying it

1,679 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
krb5@1.18.2-22.el8_7
0:1.18.2-26.el8_8.5
1
altinity/metrics-exporter:0.20.01a46d104406d
krb5@1.18.2-22.el8_7
0:1.18.2-26.el8_8.5
1
anchore/anchore-engine:v0.10.0bde9eedf639d
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
krb5@1.17-9.el8
0:1.18.2-32.el8_10
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
krb5@1.20.1-6ubuntu2.1
1.20.1-6ubuntu2.6
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7
1
andrianrf/backoffice:latest047a7837651e
krb5@1.18.2-29.el8_10
0:1.18.2-32.el8_10
1
andrianrf/backoffice-be:latest6036614803d4
krb5@1.20.1-8.el9
0:1.20.1-9.el9_2.3
1
andrianrf/bpjstk-service:latest46abe878d9d8
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
andrianrf/bpjstk-simulator:latestb63fdb51d39d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
andrianrf/iso-client:latestba560086ce15
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
andrianrf/iso-server:latest7da47f525c7d
krb5@1.20.1-8.el9
0:1.20.1-9.el9_2.3
1
anguda/ant-media:2.5c435285fc241
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.11
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
krb5@1.20.1-2
1.20.1-2+deb12u4
1
anujdatar/cups:25.07.01685df04a643b
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
1
apache/activemq-artemis:2.37.0bae523439ee3
krb5@1.20.1-6ubuntu2.1
1.20.1-6ubuntu2.6
1
apache/airflow:2.8.4-python3.964e58748b6b9
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
apache/airflow:2.8.1e5560ad0b86e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
apache/camel-k:1.10.43bb13d14f64a
krb5@1.18.2-14.el8
0:1.18.2-16.el8_6.4
1
apache/drill:1.21.11f96558fd292
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
apache/iotdb:0.13.3-nodeafa47bf1692a
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apache/nifi-registry:1.27.063b8e3e40742
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
apachepinot/pinot:latest-jdk110018bb04ced7
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apachepulsar/pulsar:3.0.79c9947de139d
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.7
1
apachepulsar/pulsar:2.9.0d056c89b7131
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apachepulsar/pulsar:2.8.2d538416d5afe
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apache/rocketmq:5.3.0434d8398f996
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.6
1
apache/rocketmq-exporter:0.0.2c8fb51195444
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
apache/skywalking-oap-server:9.2.0133d35d2c263
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apache/skywalking-ui:9.2.0295f1dc87d98
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
apache/skywalking-ui:8.9.180530f0308a5
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
apache/superset:4.0.1ab9467fd712c
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
apache/tika:2.9.0.092d055a84e9e
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.7
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
apimap/api:v1.8.11ae2b3ab00177
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
apimap/developer:v1.3.1406d3858e20c
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
apimap/portal:v2.4.0041a4790c65c
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
archish27/python-fastapi-postgres:latest6610071a2101
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
krb5@1.18.3-6+deb11u6
1.18.3-6+deb11u7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.