StackRadar

CVE-2025-45768

High

Advisory

Published 31 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
238
of 17,781 indexed, latest versions
Container images
231
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 238 of 17,781 indexed charts deploy, on 231 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+13 moreno fix listed231
pyjwtdeb2.6.0-1, 2.6.0-1+deb12u1no fix listed9
OSV records
DEBIAN-CVE-2025-45768PYSEC-2025-183

Charts affected

238 by stars
ChartLatestAffected imagesRadar Score
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pyjwt@2.10.1
no fix listed

Open the chart page →

15,371
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pyjwt@2.9.0
no fix listed

Open the chart page →

4,803
syncserverchristianhuthVerified publisher1.3.01 of 1See more

syncserver christianhuth 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
mozilla/syncserver:latest016162bf39d8
pyjwt@1.7.1
no fix listed

Open the chart page →

1,382
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pyjwt@2.3.0
no fix listed

Open the chart page →

20,900
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
pyjwt@1.6.4
no fix listed

Open the chart page →

2,408
prometheus-operatorcloudnativeapp6.4.01 of 7See more

prometheus-operator cloudnativeapp 6.4.0

1 of the 7 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pyjwt@1.7.1
no fix listed

Open the chart page →

2,954
sentry-kubernetescloudnativeapp0.2.01 of 1See more

sentry-kubernetes cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
getsentry/sentry-kubernetes:latest6ac37974fd2a
pyjwt@1.7.1
no fix listed

Open the chart page →

1,415
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
pyjwt@1.7.1
no fix listed

Open the chart page →

5,060
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pyjwt@2.3.0
no fix listed

Open the chart page →

6,695
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
pyjwt@2.4.0
no fix listed

Open the chart page →

6,921
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pyjwt@2.3.0
no fix listed

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pyjwt@2.3.0
no fix listed

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pyjwt@2.3.0
no fix listed

Open the chart page →

11,592
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
pyjwt@2.4.0
no fix listed

Open the chart page →

16,069
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pyjwt@2.10.1
no fix listed

Open the chart page →

6,162
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
pyjwt@2.9.0
no fix listed

Open the chart page →

8,009
opencloudcommunity-opencloud3.0.01 of 11See more

opencloud community-opencloud 3.0.0

1 of the 11 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
apache/tika:latest-full80072bb73dd3
pyjwt@2.10.1
no fix listed

Open the chart page →

3,773
wopiservercs3orgOfficialVerified publisher0.9.21 of 1See more

wopiserver cs3org 0.9.2

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
pyjwt@2.6.0
no fix listed

Open the chart page →

2,348
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pyjwt@2.10.1
no fix listed
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pyjwt@2.10.1
no fix listed
opencsghq/label-studio:v2.4.0b4e849fcf94a
pyjwt@2.10.1
no fix listed

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pyjwt@2.8.0
no fix listed

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pyjwt@2.10.1
no fix listed

Open the chart page →

6,632
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
aristidetm/k8s-hub:3.3.7ccb516cb8474
pyjwt@2.8.0
no fix listed

Open the chart page →

16,604
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pyjwt@2.8.0
no fix listed

Open the chart page →

6,179
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
pyjwt@2.4.0
no fix listed

Open the chart page →

5,062
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
pyjwt@1.7.1
no fix listed

Open the chart page →

4,422
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pyjwt@2.10.1
no fix listed

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pyjwt@2.10.1
no fix listed

Open the chart page →

11,160
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
pyjwt@2.6.0
no fix listed

Open the chart page →

14,856
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pyjwt@2.8.0
no fix listed

Open the chart page →

19,224
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
pyjwt@1.7.0
no fix listed

Open the chart page →

4,217
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
pyjwt@2.8.0
no fix listed

Open the chart page →

14,627
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-rest:latest3009350bfc11
pyjwt@2.10.1
no fix listed

Open the chart page →

10,270
codecovdoubanVerified publisher0.2.43 of 8See more

codecov douban 0.2.4

3 of the 8 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
pyjwt@2.8.0
no fix listed
codecov/self-hosted-worker:24.4.1837f546b479b
pyjwt@2.4.0
no fix listed
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pyjwt@2.3.0
no fix listed

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
pyjwt@2.3.0
no fix listed

Open the chart page →

30,699
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
pyjwt@1.7.1
no fix listed

Open the chart page →

11,174
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
no fix listed

Open the chart page →

30,159
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
pyjwt@2.1.0
no fix listed

Open the chart page →

25,122
datadog-apmfairwinds-incubator2.0.01 of 1See more

datadog-apm fairwinds-incubator 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pyjwt@2.10.1
no fix listed

Open the chart page →

2,785
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
pyjwt@1.7.1
no fix listed

Open the chart page →

14,673
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
pyjwt@2.8.0
no fix listed

Open the chart page →

12,454
kodiakfikaworks1.1.41 of 2See more

kodiak fikaworks 1.1.4

1 of the 2 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
cdignam/kodiak:v0.54.05a6a55b39cee
pyjwt@1.7.1
no fix listed

Open the chart page →

3,892
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pyjwt@2.9.0
no fix listed

Open the chart page →

64,489
ishare-satellitefiware1.3.21 of 1See more

ishare-satellite fiware 1.3.2

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
pyjwt@2.4.0
no fix listed

Open the chart page →

1,778
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
pyjwt@2.10.1
no fix listed

Open the chart page →

5,292
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
pyjwt@1.7.0
no fix listed

Open the chart page →

3,474
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
pyjwt@1.7.1
no fix listed

Open the chart page →

2,188
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pyjwt@2.10.1
no fix listed

Open the chart page →

2,183
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pyjwt@2.1.0
no fix listed

Open the chart page →

24,293
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pyjwt@2.10.1
no fix listed

Open the chart page →

8,923
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2025-45768.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
pyjwt@2.9.0
no fix listed

Open the chart page →

49,025

Container images carrying it

231 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
codecov/self-hosted-worker:24.4.1837f546b479b
pyjwt@2.4.0
no fix listed
1
datadog/agent:7.22.08f20e56b5311
pyjwt@1.7.1
no fix listed
1
datadog/agent:6aad9994de6a7
pyjwt@1.7.1
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
pyjwt@2.6.0
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
pyjwt@2.8.0
no fix listed
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyjwt@2.9.0
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
pyjwt@2.8.0
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
pyjwt@2.8.0
no fix listed
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
no fix listed
1
dpage/pgadmin4:8.418cd5711fc9a
pyjwt@2.8.0
no fix listed
1
dpage/pgadmin4:7.537946e4f3e7b
pyjwt@2.7.0
no fix listed
1
dpage/pgadmin4:9.11.050700ac17936
pyjwt@2.10.1
no fix listed
1
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
no fix listed
1
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
no fix listed
1
evk02/mlflow:2.2.1ef6ff257ef35
pyjwt@2.6.0
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pyjwt@2.9.0
no fix listed
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
pyjwt@2.4.0
no fix listed
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
pyjwt@1.7.1
no fix listed
1
flanksource/batch-runner:v1.0.44689687a7cf95
pyjwt@2.10.1
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
pyjwt@1.7.1
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
pyjwt@1.7.1
no fix listed
1
galaxy/cloudman-server:lateste5c265fe9fcd
pyjwt@2.4.0
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pyjwt@2.10.1
no fix listed
1
gethue/hue:4.11.011b649636e68
pyjwt@2.4.0
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
pyjwt@1.7.1
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
pyjwt@2.4.0
no fix listed
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
pyjwt@1.7.1
no fix listed
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
pyjwt@2.10.1
no fix listed
1
grafana/oncall:v1.16.5499851658393
pyjwt@2.10.1
no fix listed
1
hayk96/alerta-web:9.0.486377705e9e3
pyjwt@2.10.1
no fix listed
1
heartexlabs/label-studio:latestaa461572e8f9
pyjwt@2.10.1
no fix listed
1
hhyo/archery:v1.9.11aa41843419e
pyjwt@2.5.0
no fix listed
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
pyjwt@2.8.0
no fix listed
1
homeassistant/home-assistant:2023.12.48d000332b09b
pyjwt@2.8.0
no fix listed
1
i4trust/activation-service:2.2.09f3719176893
pyjwt@2.7.0
no fix listed
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pyjwt@1.7.1
no fix listed
1
jertel/elastalert2:2.2.34dcc0ef93efc
pyjwt@1.7.1
no fix listed
1
jmferrer/azure-devops-agent:latest030f68ec6998
pyjwt@1.7.1
no fix listed
1
john19968010/fastapi-template:latest31a90f6bd69c
pyjwt@2.6.0
no fix listed
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
no fix listed
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
pyjwt@2.8.0
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
pyjwt@1.7.1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
pyjwt@1.7.1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
pyjwt@1.7.1
no fix listed
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
pyjwt@2.4.0
no fix listed
1
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pyjwt@1.7.1
no fix listed
1
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pyjwt@1.7.1
no fix listed
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pyjwt@2.3.0
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
pyjwt@2.8.0
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
pyjwt@2.8.0
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.