StackRadar

CVE-2025-4207

Medium

Advisory

Published 8 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
254
of 17,787 indexed, latest versions
Container images
255
deployed by those charts
Fix available
10 of 13
affected packages

PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation

Carried by container images the latest versions of 254 of 17,787 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+1, 15.5-0+deb12u1+6 more15.13-0+deb12u176
postgresqlbitnami11.8.0-10, 11.12.0-7, 14.4.0-0, 14.4.0-11+23 more13.21.028
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 more12.22-0ubuntu0.20.04.417
postgresql16apk16.1-r0, 16.2-r0, 16.2-r1, 16.3-r0+2 more16.9-r013
PostgreSQLbitnami15.3.0, 15.4.0, 15.5.0-42, 16.0.0+6 more13.21.011
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+4 more14.18-0ubuntu0.22.04.111
postgresql15apk15.3-r0, 15.4-r0, 15.5-r0, 15.6-r0+1 more15.13-r08
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql17apk17.2-r0, 17.4-r017.5-r03
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.116.9-0ubuntu0.24.04.12
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
postgresql-13deb13.3-1, 13.4-0+deb11u1, 13.5-0+deb11u1, 13.6-1.pgdg110+1+13 more13.21-0+deb11u186
OSV records
ALPINE-CVE-2025-4207BIT-postgresql-2025-4207DEBIAN-CVE-2025-4207UBUNTU-CVE-2025-4207DLA-4159-1
Also known as
USN-7520-1

Charts affected

254 by stars
ChartLatestAffected imagesRadar Score
jasperjasperVerified publisher1.0.2031 of 2See more

jasper jasper 1.0.203

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
postgresql@17.5.0-14
13.21.0

Open the chart page →

9,148
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1

Open the chart page →

22,665
shinsei-managerjtektVerified publisher0.2.02 of 8See more

shinsei-manager jtekt 0.2.0

2 of the 8 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1

Open the chart page →

59,560
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

16,626
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
postgresql@17.5.0-14
13.21.0

Open the chart page →

14,833
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
postgresql@17.2.0-4
13.21.0

Open the chart page →

12,131
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
postgresql@16.3.0-12
13.21.0

Open the chart page →

8,680
kubeflowkromanow94-kubeflow0.5.12 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

2 of the 30 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
library/python:3.7eedf63967cdb
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1

Open the chart page →

68,994
jupyterhubkubeblocksVerified publisher0.1.01 of 7See more

jupyterhub kubeblocks 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
postgresql-13@13.11-0+deb11u1
13.21-0+deb11u1

Open the chart page →

7,356
gptchat-api-feishubotkubegemsapp0.1.11 of 3See more

gptchat-api-feishubot kubegemsapp 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
kubegems/chatgpt-api:latestf3c492a938ad
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1

Open the chart page →

8,486
freescoutl4gVerified publisher0.1.02 of 3See more

freescout l4g 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
postgresql16@16.3-r0
16.9-r0
zzorica/k8s-mgmt-pod:0.5.2640ca4de2922
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1

Open the chart page →

5,331
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1

Open the chart page →

3,891
motionlinuxoid690.1.01 of 1See more

motion linuxoid69 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/linuxoid69/motion:4.7.0-0.1.0f0f000c3fc47
postgresql-13@13.18-0+deb11u1
13.21-0+deb11u1

Open the chart page →

494
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1

Open the chart page →

5,905
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
postgresql-12@12.9-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4

Open the chart page →

17,836
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
postgresql-13@13.11-0+deb11u1
13.21-0+deb11u1

Open the chart page →

6,722
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
postgresql15@15.4-r0
15.13-r0

Open the chart page →

5,941
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
postgresql-15@15.10-0+deb12u1
15.13-0+deb12u1

Open the chart page →

5,849
memgptmemgptVerified publisher0.3.191 of 2See more

memgpt memgpt 0.3.19

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ankane/pgvector:v0.5.1d3a9d8ac27bb
postgresql-15@15.4-2.pgdg120+1
15.13-0+deb12u1

Open the chart page →

5,872
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
postgresql-15@15.12-0+deb12u2
15.13-0+deb12u1

Open the chart page →

42,983
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1

Open the chart page →

8,556
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

23,263
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

30,195
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

13,711
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1

Open the chart page →

12,861
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

12,839
betydbncsaVerified publisher0.6.12 of 4See more

betydb ncsa 0.6.1

2 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:11.8.0c3f10b41989f
postgresql@11.8.0-10
13.21.0
pecan/bety:5.4.1f825d480cd62
postgresql-13@13.4-0+deb11u1
13.21-0+deb11u1

Open the chart page →

9,542
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.03ba6e6f11388
postgresql@16.4.0-20
13.21.0

Open the chart page →

15,408
pecanncsaVerified publisher0.6.22 of 15See more

pecan ncsa 0.6.2

2 of the 15 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
postgresql-13@13.4-0+deb11u1
13.21-0+deb11u1
pecan/web:1.7.2814d678c5550
postgresql-13@13.4-0+deb11u1
13.21-0+deb11u1

Open the chart page →

14,154
smilencsaVerified publisher1.1.013 of 23See more

smile ncsa 1.1.0

13 of the 23 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/classification_train:0.1.207477060bba8
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_list:0.1.051cb17626519
postgresql-13@13.10-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
postgresql-13@13.11-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

109,485
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
postgresql16@16.6-r0
16.9-r0

Open the chart page →

2,292
servernodejs0.0.21 of 1See more

server nodejs 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
maissacrement/pock8snodejs:0.0.16da0db1159da
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1

Open the chart page →

1,902
nominatimnominatim-chart1.3.02 of 3See more

nominatim nominatim-chart 1.3.0

2 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
postgresql-12@12.12-0ubuntu0.20.04.1
12.22-0ubuntu0.20.04.4
robjuz/postgresql-nominatim:latest805c7bab76df
postgresql@11.12.0-7
13.21.0

Open the chart page →

22,713
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

13,331
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

13,405
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1

Open the chart page →

13,387
apicurioone-acre-fundVerified publisher2.3.01 of 5See more

apicurio one-acre-fund 2.3.0

1 of the 5 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
13.21.0

Open the chart page →

18,666
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed

Open the chart page →

88,616
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed

Open the chart page →

26,234
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed

Open the chart page →

15,722
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
postgresql-9.5@9.5.10-0ubuntu0.16.04
no fix listed

Open the chart page →

93,965
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed

Open the chart page →

41,088
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
postgresql-15@15.10-0+deb12u1
15.13-0+deb12u1

Open the chart page →

11,003
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
postgresql@16.6.0-1
13.21.0

Open the chart page →

4,539
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

11,095
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1

Open the chart page →

25,681
pgcatpgcatVerified publisher0.2.51 of 1See more

pgcat pgcat 0.2.5

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1

Open the chart page →

3,316
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
postgresql-15@15.12-0+deb12u2
15.13-0+deb12u1

Open the chart page →

8,215
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2025-4207.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1

Open the chart page →

2,565

Container images carrying it

255 by charts deploying them

A fixed version is listed for 10 of the 13 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
postgresql@17.5.0-14
13.21.0
6
bitnamilegacy/postgresql:16233f361c5819
postgresql@16.6.0-1
13.21.0
4
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
postgresql@15.4.0-6
PostgreSQL@15.4.0
13.21.0
13.21.0
4
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
postgresql@15.3.0-3
PostgreSQL@15.3.0
13.21.0
13.21.0
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
postgresql@14.13.0-20
13.21.0
3
opencsghq/psql:latest57def8e77d0f
postgresql17@17.2-r0
17.5-r0
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
postgresql@16.6.0-1
13.21.0
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.9-0ubuntu0.24.04.1
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
13.21.0
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
postgresql@16.4.0-12
13.21.0
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
postgresql15@15.4-r0
15.13-r0
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
2
library/adminer:4.8.1-standalone34d37131366c
postgresql-13@13.15-0+deb11u1
13.21-0+deb11u1
2
library/python:3.7eedf63967cdb
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed
2
opendatacube/ows:latest668cbb41473c
postgresql-16@16.6-0ubuntu0.24.04.1
16.9-0ubuntu0.24.04.1
2
pecan/bety:5.4.1f825d480cd62
postgresql-13@13.4-0+deb11u1
13.21-0+deb11u1
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1
2
vaultwarden/server:1.25.239f34c5159a2
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1
2
yzhou442/equiz:latesta3f7ca69e28d
postgresql-13@13.8-0+deb11u1
13.21-0+deb11u1
2
ghcr.io/airflow-helm/pgbouncer:1.22.1-patch.0c181abe1093d
postgresql16@16.2-r1
16.9-r0
2
ghcr.io/airflow-helm/postgresql-bitnami:11.22-patch.0df576862b7c0
postgresql16@16.2-r1
16.9-r0
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
postgresql-14@14.5-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.18-0ubuntu0.22.04.1
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
postgresql-15@15.5-0+deb12u1
15.13-0+deb12u1
2
akaunting/akaunting:3.0.1552811b36ec3a
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
postgresql-13@13.9-0+deb11u1
13.21-0+deb11u1
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
postgresql-15@15.4-2.pgdg120+1
15.13-0+deb12u1
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1
1
apache/superset:4.0.1ab9467fd712c
postgresql-15@15.6-0+deb12u1
15.13-0+deb12u1
1
archish27/python-fastapi-postgres:latest6610071a2101
postgresql-13@13.7-0+deb11u1
13.21-0+deb11u1
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
postgresql-13@13.14-0+deb11u1
13.21-0+deb11u1
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
postgresql-15@15.8-0+deb12u1
15.13-0+deb12u1
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
postgresql-13@13.11-0+deb11u1
13.21-0+deb11u1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
1
avinash263/pyredis263:latestaa2b8727f1a6
postgresql-15@15.3-0+deb12u1
15.13-0+deb12u1
1
azhar008/flaskapplication:latesta1e827b0adea
postgresql-13@13.5-0+deb11u1
13.21-0+deb11u1
1
baserow/backend:1.31.1e0b3c8130b91
postgresql-15@15.10-0+deb12u1
15.13-0+deb12u1
1
baserow/baserow:1.30.1df0c42eb67e8
postgresql-15@15.10-1.pgdg120+1
15.13-0+deb12u1
1
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
postgresql@16.4.0-10
13.21.0
1
bitnamilegacy/postgresql:16.1.0-debian-11-r2504f3b0dfdb15
postgresql@16.1.0-34
PostgreSQL@16.1.0-34
13.21.0
13.21.0
1
bitnamilegacy/postgresql:16.1.0-debian-11-r1529e3dd0e7e7a
postgresql@16.1.0-14
PostgreSQL@16.1.0
13.21.0
13.21.0
1
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
postgresql@16.3.0-3
PostgreSQL@16.3.0-3
13.21.0
13.21.0
1
bitnamilegacy/postgresql:16.4.03ba6e6f11388
postgresql@16.4.0-20
13.21.0
1
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
postgresql@15.2.0-4
13.21.0
1
bitnamilegacy/postgresql:15.3.0-debian-11-r775f4cf61668e5
postgresql@15.3.0-9
PostgreSQL@15.3.0
13.21.0
13.21.0
1
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
postgresql@17.5.0-11
13.21.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.