StackRadar

CVE-2025-40777

High

Advisory

Published 16 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
bind9deb1:9.18.19-1~deb12u1, 1:9.18.24-1, 1:9.18.33-1~deb12u2, 1:9.18.41-1~deb12u1+3 moreno fix listed15
OSV records
DEBIAN-CVE-2025-40777

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
bind9@1:9.18.49-1~deb12u2
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
bind9@1:9.18.49-1~deb12u2
no fix listed

Open the chart page →

7,894
dragonflydragonflyVerified publisher1.8.41 of 3See more

dragonfly dragonfly 1.8.4

1 of the 3 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.4a1b52779c4dd
bind9@1:9.18.49-1~deb12u2
no fix listed

Open the chart page →

3,787
oneuptimeoneuptimeOfficialVerified publisher13.0.41 of 7See more

oneuptime oneuptime 13.0.4

1 of the 7 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
oneuptime/probe:release6b2d98713711
bind9@1:9.18.49-1~deb12u2
no fix listed

Open the chart page →

11,192
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
bind9@1:9.18.24-1
no fix listed

Open the chart page →

18,376
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
bind9@1:9.18.41-1~deb12u1
no fix listed

Open the chart page →

7,740
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
bind9@1:9.18.33-1~deb12u2
no fix listed

Open the chart page →

6,998
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
bind9@1:9.18.33-1~deb12u2
no fix listed

Open the chart page →

14,559
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
bind9@1:9.18.24-1
no fix listed

Open the chart page →

9,244
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
bind9@1:9.18.19-1~deb12u1
no fix listed

Open the chart page →

6,026
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
bind9@1:9.18.49-1~deb12u1
no fix listed

Open the chart page →

9,077
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
bind9@1:9.18.47-1~deb12u1
no fix listed

Open the chart page →

5,568
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
bind9@1:9.18.47-1~deb12u1
no fix listed

Open the chart page →

5,341
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
bind9@1:9.18.49-1~deb12u1
no fix listed

Open the chart page →

6,854
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-40777.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
bind9@1:9.18.33-1~deb12u2
no fix listed

Open the chart page →

6,779

Container images carrying it

15 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
bind9@1:9.18.33-1~deb12u2
no fix listed
1
dragonflyoss/client:v1.5.4a1b52779c4dd
bind9@1:9.18.49-1~deb12u2
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
bind9@1:9.18.24-1
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
bind9@1:9.18.41-1~deb12u1
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
bind9@1:9.18.49-1~deb12u1
no fix listed
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
bind9@1:9.18.33-1~deb12u2
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
bind9@1:9.18.24-1
no fix listed
1
oneuptime/probe:release6b2d98713711
bind9@1:9.18.49-1~deb12u2
no fix listed
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
bind9@1:9.18.33-1~deb12u2
no fix listed
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
bind9@1:9.18.19-1~deb12u1
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
bind9@1:9.18.49-1~deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
bind9@1:9.18.49-1~deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
bind9@1:9.18.47-1~deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
bind9@1:9.18.47-1~deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
bind9@1:9.18.49-1~deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.