StackRadar

CVE-2025-4563

Low

Advisory

Published 23 Jun 2025In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
2.7
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

kubernetes allows nodes to bypass dynamic resource allocation authorization checks

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
k8s.io/kubernetesgolangv1.32.2, v1.33.0, v1.33.11.32.6, 1.33.210
OSV records
GHSA-hj2p-8wj8-pfq4
Also known as
GO-2025-3774

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
k8s.io/kubernetes@v1.33.1
1.33.2

Open the chart page →

5,240
vsphere-csivsphere-tmm3.8.12 of 7See more

vsphere-csi vsphere-tmm 3.8.1

2 of the 7 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
k8s.io/kubernetes@v1.33.0
1.33.2
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
k8s.io/kubernetes@v1.33.0
1.33.2

Open the chart page →

3,911
gateway-operatorkongOfficialVerified publisher0.6.11 of 1See more

gateway-operator kong 0.6.1

1 of the 1 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
kong/gateway-operator:1.603510967482b
k8s.io/kubernetes@v1.33.0
1.33.2

Open the chart page →

842
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
k8s.io/kubernetes@v1.32.2
1.32.6

Open the chart page →

10,037
capsule-argo-addoncapsule-argo-addonVerified publisher0.7.51 of 2See more

capsule-argo-addon capsule-argo-addon 0.7.5

1 of the 2 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/capsule-argo-addon:0.7.5087a80163971
k8s.io/kubernetes@v1.33.1
1.33.2

Open the chart page →

2,038
capi-kamaji-vsphere-fullclastixVerified publisher1.0.11 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

1 of the 9 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
k8s.io/kubernetes@v1.33.1
1.33.2

Open the chart page →

5,933
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
opencsghq/kubectl:latestb6d87e1048c2
k8s.io/kubernetes@v1.33.1
1.33.2

Open the chart page →

58,897
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
k8s.io/kubernetes@v1.33.1
1.33.2

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
k8s.io/kubernetes@v1.33.1
1.33.2

Open the chart page →

68,240
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
k8s.io/kubernetes@v1.33.0
1.33.2

Open the chart page →

6,037
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-4563.

Container imageDigestPackageFixed in
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
k8s.io/kubernetes@v1.33.1
1.33.2

Open the chart page →

68,240

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
k8s.io/kubernetes@v1.33.1
1.33.2
3
1dev/server:11.9.0cd5b12fe5471
k8s.io/kubernetes@v1.33.0
1.33.2
1
kong/gateway-operator:1.603510967482b
k8s.io/kubernetes@v1.33.0
1.33.2
1
opencsghq/kubectl:latestb6d87e1048c2
k8s.io/kubernetes@v1.33.1
1.33.2
1
ghcr.io/peak-scale/capsule-argo-addon:0.7.5087a80163971
k8s.io/kubernetes@v1.33.1
1.33.2
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
k8s.io/kubernetes@v1.32.2
1.32.6
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
k8s.io/kubernetes@v1.33.1
1.33.2
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
k8s.io/kubernetes@v1.33.1
1.33.2
1
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
k8s.io/kubernetes@v1.33.0
1.33.2
1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
k8s.io/kubernetes@v1.33.0
1.33.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.