StackRadar

CVE-2025-4565

High

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
172
of 17,781 indexed, latest versions
Container images
171
deployed by those charts
Fix available
2 of 2
affected packages

protobuf-python has a potential Denial of Service issue

Carried by container images the latest versions of 172 of 17,781 indexed charts deploy, on 171 images.

Affected packageAffected versionsFixed inImages
protobufpypi3.5.1, 3.5.2, 3.6.1, 3.7.0+47 more4.25.8, 5.29.5, 6.31.1160
protobufdeb2.6.1-1.3, 3.0.0-9.1ubuntu1, 3.0.0-9.1ubuntu1.1, 3.6.1.3-2ubuntu5+2 more2.6.1-1.3ubuntu0.1~esm4, 3.0.0-9.1ubuntu1.1+esm3, 3.6.1.3-2ubuntu5.2+esm2, 3.21.12-3+deb12u114
OSV records
GHSA-8qvm-5x2c-j2w7DEBIAN-CVE-2025-4565UBUNTU-CVE-2025-4565
Also known as
PYSEC-2026-1806, USN-7629-2

Charts affected

172 by stars
ChartLatestAffected imagesRadar Score
gar-exportersoftonic0.1.11 of 1See more

gar-exporter softonic 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
softonic/gar-exporter:0.2.1a64d6c0e0ae5
protobuf@3.13.0
4.25.8

Open the chart page →

2,296
verostakewise0.8.31 of 2See more

vero stakewise 0.8.3

1 of the 2 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
protobuf@4.25.5
4.25.8

Open the chart page →

3,458
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
protobuf@5.29.3
5.29.5

Open the chart page →

4,731
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
protobuf@3.11.3
4.25.8

Open the chart page →

1,287
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
protobuf@3.20.1
4.25.8

Open the chart page →

17,461
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
protobuf@4.25.5
4.25.8

Open the chart page →

4,393
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
protobuf@4.25.5
4.25.8
opea/embedding-tei:1.05c9639de61c1
protobuf@4.25.5
4.25.8
opea/llm-tgi:1.00c25aab3f106
protobuf@4.25.5
4.25.8
opea/reranking-tei:1.0e48613afb191
protobuf@4.25.5
4.25.8
opea/retriever-redis:1.0eb746b263705
protobuf@4.25.5
4.25.8

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
protobuf@4.25.5
4.25.8
opea/llm-tgi:1.00c25aab3f106
protobuf@4.25.5
4.25.8

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
protobuf@4.25.5
4.25.8
opea/llm-tgi:1.00c25aab3f106
protobuf@4.25.5
4.25.8

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
protobuf@4.25.5
4.25.8
opea/llm-docsum-tgi:1.002f9e8fa5d71
protobuf@4.25.5
4.25.8

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
protobuf@4.25.5
4.25.8

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
protobuf@4.25.5
4.25.8

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
protobuf@4.25.5
4.25.8

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
protobuf@4.25.5
4.25.8

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
protobuf@4.25.5
4.25.8

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
protobuf@4.25.5
4.25.8

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
protobuf@4.25.5
4.25.8

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
protobuf@4.25.5
4.25.8

Open the chart page →

5,350
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
protobuf@6.30.2
6.31.1

Open the chart page →

4,768
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
protobuf@4.25.3
4.25.8

Open the chart page →

13,459
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
protobuf@3.17.3
4.25.8

Open the chart page →

11,119
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-4565.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
protobuf@3.13.0
4.25.8

Open the chart page →

4,086

Container images carrying it

171 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
protobuf@4.25.5
4.25.8
4
cloudve/cloudlaunch-server:latest4a3d7fae90bb
protobuf@3.19.1
4.25.8
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm4
3
amancevice/superset:0.35.212a0a9e66550
protobuf@3.11.2
4.25.8
2
cs3org/wopiserver:v9.4.202a9e78757b4
protobuf@4.22.0
4.25.8
2
datawire/aes:1.14.48588eafe6862
protobuf@3.13.0
4.25.8
2
larribas/mlflow:1.9.105ccb0b46bfb
protobuf@3.12.2
4.25.8
2
lncm/specter-desktop:v1.10.536eaa06f99f4
protobuf@3.17.3
4.25.8
2
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
protobuf@3.7.0
4.25.8
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
protobuf@3.5.2
4.25.8
2
opea/embedding-tei:1.05c9639de61c1
protobuf@4.25.5
4.25.8
2
opea/reranking-tei:1.0e48613afb191
protobuf@4.25.5
4.25.8
2
opea/retriever-redis:1.0eb746b263705
protobuf@4.25.5
4.25.8
2
weblate/weblate:4.2.2-169c160d37a3c
protobuf@3.13.0
4.25.8
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
protobuf@3.14.0
4.25.8
2
airbyte/manifest-server:7.23.73b3a670af168
protobuf@5.29.4
5.29.5
1
alerta/alerta-web:8.5.04786b9eaa606
protobuf@3.19.1
4.25.8
1
allegroai/clearml:2.0.0-613713ae38f7daf
protobuf@5.29.2
5.29.5
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
protobuf@3.20.3
4.25.8
1
amancevice/superset:0.28.1c8c04bfe3d66
protobuf@3.7.1
4.25.8
1
apache/airflow:2.8.4-python3.964e58748b6b9
protobuf@4.25.3
4.25.8
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
protobuf@4.25.4
4.25.8
1
apache/airflow:2.8.1e5560ad0b86e
protobuf@4.25.2
4.25.8
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
protobuf@3.20.3
4.25.8
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
protobuf@3.19.4
4.25.8
1
apachepulsar/pulsar:2.6.14db6ff0b4045
protobuf@3.13.0
4.25.8
1
apachepulsar/pulsar:3.0.79c9947de139d
protobuf@3.20.3
4.25.8
1
apachepulsar/pulsar:2.9.0d056c89b7131
protobuf@3.19.1
4.25.8
1
apachepulsar/pulsar:2.8.2d538416d5afe
protobuf@3.19.1
4.25.8
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
protobuf@3.17.3
4.25.8
1
assistiot/fl_local_operations_inference:latest0518b63a2e69
protobuf@4.22.3
4.25.8
1
assistiot/fl_training_collector:latest792715dd3084
protobuf@3.19.0
4.25.8
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
protobuf@4.22.1
protobuf@3.6.1.3-2ubuntu5.2
4.25.8
3.6.1.3-2ubuntu5.2+esm2
1
baserow/backend:1.31.1e0b3c8130b91
protobuf@4.25.3
4.25.8
1
baserow/baserow:1.30.1df0c42eb67e8
protobuf@4.25.3
4.25.8
1
behnambm/docker-sample:v1bd3ad88afff9
protobuf@4.21.12
4.25.8
1
buntha/mlflow:2.1.1154542cc3083
protobuf@4.21.12
4.25.8
1
cheyang/distributed-tf:1.6.046cc34755493
protobuf@3.5.1
4.25.8
1
codecov/self-hosted-api:24.4.10475cb1c3136
protobuf@4.24.3
4.25.8
1
codecov/self-hosted-worker:24.4.1837f546b479b
protobuf@4.24.3
4.25.8
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
protobuf@5.29.3
5.29.5
1
datadog/agent:7.22.08f20e56b5311
protobuf@3.7.0
4.25.8
1
datadog/agent:6aad9994de6a7
protobuf@3.17.3
4.25.8
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
protobuf@3.13.0
4.25.8
1
datawire/aes:1.13.62beb65062c8b
protobuf@3.13.0
4.25.8
1
datawire/emissary:2.0.2-ea9716efbdd24b
protobuf@3.13.0
4.25.8
1
ddosify/selfhosted_backend:3.2.93c11e3182652
protobuf@4.25.3
4.25.8
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
protobuf@4.25.3
4.25.8
1
dpage/pgadmin4:8.418cd5711fc9a
protobuf@4.25.3
4.25.8
1
dpage/pgadmin4:7.537946e4f3e7b
protobuf@4.23.4
4.25.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.