StackRadar

CVE-2025-3576

Medium

Advisory

Published 15 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,559
of 17,787 indexed, latest versions
Container images
1,691
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 1,559 of 17,787 indexed charts deploy, on 1,691 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+40 more1.12+dfsg-2ubuntu5.4+esm7, 1.13.2+dfsg-5ubuntu2.2+esm7, 1.16-2ubuntu0.4+esm5, 1.17-6ubuntu4.11+4 more1,447
krb5rpm1.16.1-22.el8, 1.17-9.el8, 1.17-18.el8, 1.17-19.el8_2+25 more0:1.17-19.el8_2.3, 0:1.18.2-9.el8_4.3, 0:1.18.2-16.el8_6.4, 0:1.18.2-26.el8_8.5+5 more244
OSV records
DEBIAN-CVE-2025-3576RHSA-2025:13664RHSA-2025:13777RHSA-2025:15001RHSA-2025:15002RHSA-2025:15003RHSA-2025:15004RHSA-2025:8411RHSA-2025:9430RLSA-2025:8411RLSA-2025:9430UBUNTU-CVE-2025-3576DLA-4195-1SUSE-SU-2025:3699-1
Also known as
USN-7542-1

Charts affected

1,559 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7

Open the chart page →

14,172
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
krb5@1.18.2-14.el8
0:1.18.2-32.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.6

Open the chart page →

2,136
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-3576.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-32.el8_10

Open the chart page →

3,697

Container images carrying it

1,691 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
krb5@1.18.3-6+deb11u6
1.18.3-6+deb11u7
1
aristidetm/basic-notebook:3.6.5469dbc951224
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
1
aroralalit/student-producer:1.0.02a094f597b36
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
artifacthub/tracker:v1.19.06596c8c4d955
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
arturisimo/planner:v1.0fff9de644941
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.11
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u7
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
assistiot/identity-manager_db:latest0d3e6d35f168
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
assistiot/identity-manager_kc:latest0df4b4fa899a
krb5@1.18.2-14.el8
0:1.18.2-16.el8_6.4
1
assistiot/location_processing:lateste9bae124095f
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
assistiot/open_api_backend:1.1.230812ba93555
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.11
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
krb5@1.20.1-2
1.20.1-2+deb12u4
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.11
1
atlassian/confluence-server:7.10.03b9222ab32ef
krb5@1.19.2-2
1.19.2-2ubuntu0.7
1
atlassian/jira-software:8.14.037bc46cbec1a
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.7
1
atlassian/jira-software:9.7.264a75aa4ec4e
krb5@1.20.1-6ubuntu2.5
1.20.1-6ubuntu2.6
1
atmoz/sftp:latest0960390462a4
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
1
atomix/atomix:3.1.127738ff4f5c63
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
avinash263/pyredis263:latestaa2b8727f1a6
krb5@1.20.1-2
1.20.1-2+deb12u4
1
avzini/web-app:latestf40b30210ed0
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
azhar008/flaskapplication:latesta1e827b0adea
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
baserow/backend:1.31.1e0b3c8130b91
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
baserow/baserow:1.30.1df0c42eb67e8
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.11
1
beastob/url-shortener:1.0.299a49885ab33
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
beopenit/door-helm:v3.0.1b4d9f9bee224
krb5@1.18.2-25.el8_8
0:1.18.2-26.el8_8.5
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
1
biospheere/promcord:latest16d4fd269e66
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u7
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
bitnamilegacy/git:latest4b08d0c5af8d
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u4
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u4
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u7
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u7
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.