StackRadar

CVE-2025-4207

Medium

Advisory

Published 8 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
252
of 17,781 indexed, latest versions
Container images
254
deployed by those charts
Fix available
10 of 13
affected packages

PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation

Carried by container images the latest versions of 252 of 17,781 indexed charts deploy, on 254 images.

Affected packageAffected versionsFixed inImages
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+1, 15.5-0+deb12u1+6 more15.13-0+deb12u176
postgresqlbitnami11.8.0-10, 11.12.0-7, 14.4.0-0, 14.4.0-11+23 more13.21.028
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 more12.22-0ubuntu0.20.04.417
postgresql16apk16.1-r0, 16.2-r0, 16.2-r1, 16.3-r0+2 more16.9-r013
PostgreSQLbitnami15.3.0, 15.4.0, 15.5.0-42, 16.0.0+6 more13.21.011
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+4 more14.18-0ubuntu0.22.04.111
postgresql15apk15.3-r0, 15.4-r0, 15.5-r0, 15.6-r0+1 more15.13-r08
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql17apk17.2-r0, 17.4-r017.5-r03
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.116.9-0ubuntu0.24.04.12
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
postgresql-13deb13.3-1, 13.4-0+deb11u1, 13.5-0+deb11u1, 13.6-1.pgdg110+1+13 more13.21-0+deb11u185
OSV records
ALPINE-CVE-2025-4207BIT-postgresql-2025-4207DEBIAN-CVE-2025-4207UBUNTU-CVE-2025-4207DLA-4159-1
Also known as
USN-7520-1

Charts affected

252 by stars
ChartLatestAffected imagesRadar Score
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1

Open the chart page →

22,589
shinsei-managerjtektVerified publisher0.2.02 of 8See more

shinsei-manager jtekt 0.2.0

2 of the 8 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1

Open the chart page →

63,461
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

16,600
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
postgresql@17.5.0-14
13.21.0

Open the chart page →

14,801
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
postgresql@17.2.0-4
13.21.0

Open the chart page →

12,062
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
postgresql@16.3.0-12
13.21.0

Open the chart page →

9,098
kubeflowkromanow94-kubeflow0.5.12 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

2 of the 30 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
library/python:3.7eedf63967cdb
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1

Open the chart page →

70,530
jupyterhubkubeblocksVerified publisher0.1.01 of 7See more

jupyterhub kubeblocks 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
postgresql-13@13.11-0+deb11u1
13.21-0+deb11u1

Open the chart page →

7,356
freescoutl4gVerified publisher0.1.02 of 3See more

freescout l4g 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
postgresql16@16.3-r0
16.9-r0
zzorica/k8s-mgmt-pod:0.5.2640ca4de2922
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1

Open the chart page →

5,332
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1

Open the chart page →

3,891
motionlinuxoid690.1.01 of 1See more

motion linuxoid69 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/linuxoid69/motion:4.7.0-0.1.0f0f000c3fc47
postgresql-13@13.18-0+deb11u1
13.21-0+deb11u1

Open the chart page →

494
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1

Open the chart page →

5,905
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
postgresql-12@12.9-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4

Open the chart page →

17,779
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
postgresql-13@13.11-0+deb11u1
13.21-0+deb11u1

Open the chart page →

7,315
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
postgresql15@15.4-r0
15.13-r0

Open the chart page →

5,940
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
postgresql-15@15.10-0+deb12u1
15.13-0+deb12u1

Open the chart page →

5,823
memgptmemgptVerified publisher0.3.191 of 2See more

memgpt memgpt 0.3.19

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ankane/pgvector:v0.5.1d3a9d8ac27bb
postgresql-15@15.4-2.pgdg120+1
15.13-0+deb12u1

Open the chart page →

5,866
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
postgresql-15@15.12-0+deb12u2
15.13-0+deb12u1

Open the chart page →

43,341
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1

Open the chart page →

8,556
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

25,704
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

30,363
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

13,686
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1

Open the chart page →

12,791
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1

Open the chart page →

12,791
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

12,813
betydbncsaVerified publisher0.6.12 of 4See more

betydb ncsa 0.6.1

2 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:11.8.0c3f10b41989f
postgresql@11.8.0-10
13.21.0
pecan/bety:5.4.1f825d480cd62
postgresql-13@13.4-0+deb11u1
13.21-0+deb11u1

Open the chart page →

9,542
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.03ba6e6f11388
postgresql@16.4.0-20
13.21.0

Open the chart page →

15,369
pecanncsaVerified publisher0.6.22 of 15See more

pecan ncsa 0.6.2

2 of the 15 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
postgresql-13@13.4-0+deb11u1
13.21-0+deb11u1
pecan/web:1.7.2814d678c5550
postgresql-13@13.4-0+deb11u1
13.21-0+deb11u1

Open the chart page →

14,154
smilencsaVerified publisher1.1.013 of 23See more

smile ncsa 1.1.0

13 of the 23 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/classification_train:0.1.207477060bba8
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_list:0.1.051cb17626519
postgresql-13@13.10-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
postgresql-13@13.11-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

109,294
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
postgresql16@16.6-r0
16.9-r0

Open the chart page →

2,293
servernodejs0.0.21 of 1See more

server nodejs 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
maissacrement/pock8snodejs:0.0.16da0db1159da
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1

Open the chart page →

1,902
nominatimnominatim-chart1.3.02 of 3See more

nominatim nominatim-chart 1.3.0

2 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
postgresql-12@12.12-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
robjuz/postgresql-nominatim:latest805c7bab76df
postgresql@11.12.0-7
13.21.0

Open the chart page →

22,658
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

15,187
apicurioone-acre-fundVerified publisher2.3.01 of 5See more

apicurio one-acre-fund 2.3.0

1 of the 5 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
13.21.0

Open the chart page →

18,667
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed

Open the chart page →

26,211
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed

Open the chart page →

15,702
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
postgresql-9.5@9.5.10-0ubuntu0.16.04
no fix listed

Open the chart page →

93,855
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed

Open the chart page →

41,044
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
postgresql-15@15.10-0+deb12u1
15.13-0+deb12u1

Open the chart page →

10,978
hiveopstty0.1.81 of 4See more

hive opstty 0.1.8

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
postgresql@16.6.0-1
13.21.0

Open the chart page →

4,523
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

12,350
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1

Open the chart page →

27,373
pgcatpgcatVerified publisher0.2.51 of 1See more

pgcat pgcat 0.2.5

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

3,775
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
postgresql-15@15.12-0+deb12u2
15.13-0+deb12u1

Open the chart page →

8,189
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1

Open the chart page →

2,565
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
postgresql-13@13.8-0+deb11u1
13.21-0+deb11u1

Open the chart page →

4,642
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1

Open the chart page →

16,196

Container images carrying it

254 by charts deploying them

A fixed version is listed for 10 of the 13 affected packages.

Container imageDigestPackageFixed inUsed by
library/postgres:13.11-bullseye5c265bf1fd30
postgresql-13@13.11-1.pgdg110+1
13.21-0+deb11u1
1
library/postgres:15.38775adb39f0d
postgresql-15@15.3-1.pgdg120+1
15.13-0+deb12u1
1
library/python:3.8d41127070014
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1
1
library/python:3.12.9-bullseyeed4450bab88f
postgresql-13@13.20-0+deb11u1
13.21-0+deb11u1
1
librenms/librenms:24.11.00920bc9117a8
postgresql16@16.6-r0
16.9-r0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
postgresql-12@12.9-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
1
maissacrement/pock8snodejs:0.0.16da0db1159da
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
postgresql-15@15.12-0+deb12u2
15.13-0+deb12u1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1
1
matrixdotorg/synapse:v1.78.0def97fd537d8
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
1
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1
1
matterlabs/external-node:v24.0.06cbfea4c694a
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1
1
mautic/mautic:v4-apache94ea4acf4049
postgresql-13@13.20-0+deb11u1
13.21-0+deb11u1
1
mediagis/nominatim:3.7c15e941485ef
postgresql-12@12.12-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
1
mediagis/nominatim:4.2d0eae7b51374
postgresql-14@14.10-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
postgresql-15@15.12-0+deb12u2
15.13-0+deb12u1
1
mnaggar3396/python-app:latest371d8ed84b15
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1
1
muhammedgamal/fp23:latest74b4cd69b6fa
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
postgresql-13@13.8-0+deb11u1
13.21-0+deb11u1
1
netboxcommunity/netbox:v3.2.83d652dca5351
postgresql-14@14.4-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1
1
opea/codetrans-ui:1.03ef121f34610
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1
1
opea/docsum-ui:1.07f854e9bffaf
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1
1
opendatacube/pipelines:wofs-1.225d810e8504b8
postgresql-10@10.6-0ubuntu0.18.04.1
no fix listed
1
opendatacube/restcube:latest91870111837c
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed
1
opendatacube/wms:latest1b90cdf68831
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed
1
openelevation/open-elevation:latest82fb21612e86
postgresql-12@12.7-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
1
openkm/openkm-ce:6.3.113bc465a7461b
postgresql-12@12.12-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
1
openzaak/open-notificaties:1.3.02e65313b9b10
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1
1
owncloud/server:10.15.051d9b74fc2a8
postgresql-12@12.19-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
1
oxfordsemantic/rdfox:5.6db17910eb855
postgresql-12@12.9-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
postgresql-12@12.9-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
1
pecan/web:1.7.2814d678c5550
postgresql-13@13.4-0+deb11u1
13.21-0+deb11u1
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
postgresql-15@15.12-0+deb12u2
15.13-0+deb12u1
1
phntom/email-manager:0.1.22d8e2a9f2f085
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
1
phntom/external-dns-host-network:0.0.123adadbac8443
postgresql-13@13.8-0+deb11u1
13.21-0+deb11u1
1
psono/psono-server:5.0.03b974b43ea03
postgresql16@16.3-r0
16.9-r0
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1
1
resurfaceio/resurface:3.7.84d5cda2f64109
postgresql-14@14.17-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1
1
robjuz/postgresql-nominatim:latest805c7bab76df
postgresql@11.12.0-7
13.21.0
1
robmarkcole/deepstack-ui:latest410275726459
postgresql-13@13.3-1
13.21-0+deb11u1
1
robotshop/rs-payment:latest774b52c6180d
postgresql-13@13.3-1
13.21-0+deb11u1
1
roundcube/roundcubemail:1.5.3-apachea8ea6fd751dc
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1
1
sissbruecker/linkding:1.35.00c5dddf0b37c
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.