StackRadar

CVE-2025-40221

Medium

Advisory

Published 4 Dec 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,966 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 11 of 17,966 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
linuxdeb6.8.0-38.38, 6.8.0-39.39, 6.8.0-57.59, 6.8.0-60.63+6 more6.8.0-106.106, 6.17.0-14.1410
OSV records
UBUNTU-CVE-2025-40221
Also known as
USN-8029-1, USN-8095-1

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
6.8.0-106.106

Open the chart page →

81,052
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
6.8.0-106.106

Open the chart page →

74,893
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
linux@6.17.0-7.7
6.17.0-14.14

Open the chart page →

36,524
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
linux@6.8.0-94.96
6.8.0-106.106

Open the chart page →

63,413
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
6.8.0-106.106

Open the chart page →

79,021
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
6.8.0-106.106

Open the chart page →

63,058
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
6.8.0-106.106

Open the chart page →

98,578
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
6.8.0-106.106

Open the chart page →

88,899
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
6.8.0-106.106

Open the chart page →

73,154
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
6.8.0-106.106

Open the chart page →

68,410
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2025-40221.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
6.8.0-106.106

Open the chart page →

56,137

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
6.8.0-106.106
2
aktosecurity/data-ingestion-service213aded7adc5
linux@6.8.0-94.96
6.8.0-106.106
1
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
6.8.0-106.106
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
6.8.0-106.106
1
photoprism/photoprism:251130db16ee6b1ba3
linux@6.17.0-7.7
6.17.0-14.14
1
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
6.8.0-106.106
1
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
6.8.0-106.106
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
6.8.0-106.106
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
6.8.0-106.106
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
6.8.0-106.106
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.