StackRadar

CVE-2025-43965

High

Advisory

Published 23 Apr 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
120
of 17,781 indexed, latest versions
Container images
137
deployed by those charts
Fix available
1 of 1
affected package

imagemagick - security update

Carried by container images the latest versions of 120 of 17,781 indexed charts deploy, on 137 images.

Affected packageAffected versionsFixed inImages
imagemagickdeb8:6.8.9.9-7ubuntu5.9, 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.11.60+dfsg-1.3, 8:6.9.11.60+dfsg-1.3+deb11u1+8 more8:6.8.9.9-7ubuntu5.16+esm16, 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm6, 8:6.9.11.60+dfsg-1.3+deb11u5, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm6+3 more137
OSV records
DEBIAN-CVE-2025-43965UBUNTU-CVE-2025-43965DLA-4139-1
Also known as
USN-8007-1

Charts affected

120 by stars
ChartLatestAffected imagesRadar Score
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
imagemagick@8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u5

Open the chart page →

7,574
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

11,888
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

20,223
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

13,390
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
imagemagick@8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u5

Open the chart page →

2,038
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
imagemagick@8:6.9.12.98+dfsg1-5.2build2
8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm5

Open the chart page →

8,193
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

11,199
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

28,858
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

14,358
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3

Open the chart page →

10,795
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5

Open the chart page →

3,392
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
imagemagick@8:6.9.12.98+dfsg1-5.2build2
8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm5

Open the chart page →

7,628
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5

Open the chart page →

2,132
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5

Open the chart page →

2,021
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-43965.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
imagemagick@8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u5

Open the chart page →

1,838

Container images carrying it

137 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/facebook/threatexchange/hma:1.0.1784d09c6b75a7
imagemagick@8:6.9.11.60+dfsg-1.3+deb11u4
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/itzg/minecraft-server:latestc1a267d9ed6d
imagemagick@8:6.9.12.98+dfsg1-5.2build2
8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm5
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
imagemagick@8:6.9.10.23+dfsg-2.1ubuntu11.4
8:6.9.10.23+dfsg-2.1ubuntu11.11+esm6
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
imagemagick@8:6.9.10.23+dfsg-2.1ubuntu11.4
8:6.9.10.23+dfsg-2.1ubuntu11.11+esm6
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
imagemagick@8:6.9.10.23+dfsg-2.1ubuntu11.4
8:6.9.10.23+dfsg-2.1ubuntu11.11+esm6
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
imagemagick@8:6.9.10.23+dfsg-2.1ubuntu11.4
8:6.9.10.23+dfsg-2.1ubuntu11.11+esm6
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
imagemagick@8:6.9.10.23+dfsg-2.1ubuntu11.4
8:6.9.10.23+dfsg-2.1ubuntu11.11+esm6
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
imagemagick@8:6.9.12.98+dfsg1-5.2build2
8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm5
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
imagemagick@8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
imagemagick@8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
imagemagick@8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
imagemagick@8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
imagemagick@8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u5
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u3
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.