StackRadar

CVE-2025-3576

Medium

Advisory

Published 15 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,559
of 17,787 indexed, latest versions
Container images
1,691
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 1,559 of 17,787 indexed charts deploy, on 1,691 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+40 more1.12+dfsg-2ubuntu5.4+esm7, 1.13.2+dfsg-5ubuntu2.2+esm7, 1.16-2ubuntu0.4+esm5, 1.17-6ubuntu4.11+4 more1,447
krb5rpm1.16.1-22.el8, 1.17-9.el8, 1.17-18.el8, 1.17-19.el8_2+25 more0:1.17-19.el8_2.3, 0:1.18.2-9.el8_4.3, 0:1.18.2-16.el8_6.4, 0:1.18.2-26.el8_8.5+5 more244
OSV records
DEBIAN-CVE-2025-3576RHSA-2025:13664RHSA-2025:13777RHSA-2025:15001RHSA-2025:15002RHSA-2025:15003RHSA-2025:15004RHSA-2025:8411RHSA-2025:9430RLSA-2025:8411RLSA-2025:9430UBUNTU-CVE-2025-3576DLA-4195-1SUSE-SU-2025:3699-1
Also known as
USN-7542-1

Charts affected

1,559 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7

Open the chart page →

14,172
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
krb5@1.18.2-14.el8
0:1.18.2-32.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.6

Open the chart page →

2,136
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10

Open the chart page →

3,697

Container images carrying it

1,691 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
krb5@1.18.2-22.el8_7
0:1.18.2-26.el8_8.5
1
altinity/metrics-exporter:0.20.01a46d104406d
krb5@1.18.2-22.el8_7
0:1.18.2-26.el8_8.5
1
anchore/anchore-engine:v0.10.0bde9eedf639d
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
krb5@1.17-9.el8
0:1.18.2-32.el8_10
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
krb5@1.20.1-6ubuntu2.1
1.20.1-6ubuntu2.6
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7
1
andrianrf/backoffice:latest047a7837651e
krb5@1.18.2-29.el8_10
0:1.18.2-32.el8_10
1
andrianrf/backoffice-be:latest6036614803d4
krb5@1.20.1-8.el9
0:1.20.1-9.el9_2.3
1
andrianrf/bpjstk-service:latest46abe878d9d8
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
andrianrf/bpjstk-simulator:latestb63fdb51d39d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
andrianrf/iso-client:latestba560086ce15
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
andrianrf/iso-server:latest7da47f525c7d
krb5@1.20.1-8.el9
0:1.20.1-9.el9_2.3
1
anguda/ant-media:2.5c435285fc241
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.11
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
krb5@1.20.1-2
1.20.1-2+deb12u4
1
anujdatar/cups:25.07.01685df04a643b
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
1
apache/activemq-artemis:2.37.0bae523439ee3
krb5@1.20.1-6ubuntu2.1
1.20.1-6ubuntu2.6
1
apache/airflow:2.8.4-python3.964e58748b6b9
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
apache/airflow:2.8.1e5560ad0b86e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
apache/camel-k:1.10.43bb13d14f64a
krb5@1.18.2-14.el8
0:1.18.2-16.el8_6.4
1
apache/drill:1.21.11f96558fd292
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
apache/iotdb:0.13.3-nodeafa47bf1692a
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apache/nifi-registry:1.27.063b8e3e40742
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
apachepinot/pinot:latest-jdk110018bb04ced7
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.7
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apachepulsar/pulsar:3.0.79c9947de139d
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.7
1
apachepulsar/pulsar:2.9.0d056c89b7131
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apachepulsar/pulsar:2.8.2d538416d5afe
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apache/rocketmq:5.3.0434d8398f996
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.6
1
apache/rocketmq-exporter:0.0.2c8fb51195444
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
apache/skywalking-oap-server:9.2.0133d35d2c263
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apache/skywalking-ui:9.2.0295f1dc87d98
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
apache/skywalking-ui:8.9.180530f0308a5
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
apache/superset:4.0.1ab9467fd712c
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
apache/tika:2.9.0.092d055a84e9e
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.7
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
krb5@1.18.2-8.el8
0:1.18.2-9.el8_4.3
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
apimap/api:v1.8.11ae2b3ab00177
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
apimap/developer:v1.3.1406d3858e20c
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
apimap/portal:v2.4.0041a4790c65c
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
archish27/python-fastapi-postgres:latest6610071a2101
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.