StackRadar

CVE-2025-46394

Low

Advisory

Published 23 Apr 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
857
of 17,787 indexed, latest versions
Container images
902
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 857 of 17,787 indexed charts deploy, on 902 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.36.1-r10, 1.36.1-r11, 1.36.1-r15, 1.36.1-r17+15 more1.36.1-r21, 1.36.1-r31, 1.37.0-r14, 1.37.0-r20+1 more877
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed25
OSV records
ALPINE-CVE-2025-46394CGA-35qx-p5pw-chp7DEBIAN-CVE-2025-46394UBUNTU-CVE-2025-46394
Also known as
CGA-jgxh-j72w-f3hw

Charts affected

857 by stars
ChartLatestAffected imagesRadar Score
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
busybox@1.37.0-r9
1.37.0-r14

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

789
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

9,381
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
busybox@1.36.1-r19
1.36.1-r21

Open the chart page →

570

Container images carrying it

902 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/eosc-lot-1/s3cmd:2-alpine49bce0dd876d
busybox@1.36.1-r15
1.36.1-r21
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
busybox@1.37.0-r18
1.37.0-r20
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
busybox@1.37.0-r18
1.37.0-r20
2
ghcr.io/kiwigrid/k8s-sidecar:1.29.142002d66ddb3
busybox@1.37.0-r9
1.37.0-r14
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
busybox@1.37.0-r18
1.37.0-r20
2
ghcr.io/smarter-project/home-orchestrator:maind44135b02d77
busybox@1.36.1-r19
1.36.1-r21
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
busybox@1.36.1-r15
1.36.1-r21
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
busybox@1.37.0-r18
1.37.0-r20
2
quay.io/curl/curl:8.16.0b17b13321678
busybox@1.37.0-r19
1.37.0-r20
2
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
busybox@1.37.0-r19
1.37.0-r20
2
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
busybox@1.36.1-r15
1.36.1-r21
2
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
busybox@1.36.1-r28
1.36.1-r31
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
busybox@1.37.0-r18
1.37.0-r20
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
busybox@1.36.1-r15
1.36.1-r21
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
busybox@1.37.0-r12
1.37.0-r14
2
2martens/configserver:latestbf1cdb80239d
busybox@1.36.1-r29
1.36.1-r31
1
2martens/timetable:latestbd1ba6ab84c9
busybox@1.37.0-r18
1.37.0-r20
1
2martens/wahlrecht:latestba2c3040dab0
busybox@1.37.0-r18
1.37.0-r20
1
abdullahkhawer/simple-elasticsearch-cleaner:2.1.028a6c3f7e0a9
busybox@1.37.0-r8
1.37.0-r14
1
abhinavsingh/proxy.py:latest51adc989fd03
busybox@1.37.0-r12
1.37.0-r14
1
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
busybox@1.37.0-r12
1.37.0-r14
1
adguard/adguardhome:v0.107.65d765078d2140
busybox@1.37.0-r12
1.37.0-r14
1
ahmetgrbzz/result_server:1.008e10f9c0f53
busybox@1.36.1-r15
1.36.1-r21
1
ahmetgrbzz/result_server:2.035c37ae2bafd
busybox@1.36.1-r15
1.36.1-r21
1
ahmetgrbzz/web_server:1.02e7fef69c29f
busybox@1.36.1-r15
1.36.1-r21
1
ahmetgrbzz/web_server:2.0f018bafd2b0c
busybox@1.36.1-r15
1.36.1-r21
1
airbyte/db:2.2.03b6985a0ce75
busybox@1.37.0-r19
1.37.0-r20
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
busybox@1.37.0-r18
1.37.0-r20
1
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
busybox@1.36.1-r20
1.36.1-r21
1
aktosecurity/mirror-api-logging:api-gateway-logging-multi-logging1a1bc76d50fe
busybox@1.36.1-r20
1.36.1-r21
1
alakaganaguathoork/local-business:latest7eb27b0f4a5a
busybox@1.37.0-r19
1.37.0-r20
1
alfio/alf.io:2.0-M5-26060c836a081446
busybox@1.36.1-r20
1.36.1-r21
1
alpine/curl:8.5.0513c4f0d7123
busybox@1.36.1-r15
1.36.1-r21
1
alpine/curl:8.12.08943e8c7e8e4
busybox@1.37.0-r9
1.37.0-r14
1
alpine/git:v2.49.1c0280cf95723
busybox@1.37.0-r19
1.37.0-r20
1
alpine/helm105741fa6621
busybox@1.36.1-r29
1.36.1-r31
1
alpine/k8s:1.31.106dbe6f391eda
busybox@1.37.0-r18
1.37.0-r20
1
alpine/k8s:1.31.137a319b15cfc9
busybox@1.37.0-r18
1.37.0-r20
1
alpine/k8s:1.32.47e1e7d5b7a96
busybox@1.37.0-r12
1.37.0-r14
1
alpine/k8s:1.31.49c4976d47656
busybox@1.37.0-r8
1.37.0-r14
1
alpine/k8s:1.30.0bd01dae02676
busybox@1.36.1-r15
1.36.1-r21
1
alpine/k8s:1.30.2cd560fce90f7
busybox@1.36.1-r29
1.36.1-r31
1
alpine/k8s:1.28.13e5c0b053fed7
busybox@1.36.1-r29
1.36.1-r31
1
alpine/k8s:1.32.3eec354133193
busybox@1.37.0-r12
1.37.0-r14
1
alpine/kubectl:1.33.32c59a3f0726c
busybox@1.37.0-r18
1.37.0-r20
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
busybox@1.37.0-r12
1.37.0-r14
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
busybox@1.37.0-r12
1.37.0-r14
1
andreymileshin/kube-info:v0.1.0f7b300bc9e66
busybox@1.36.1-r19
1.36.1-r21
1
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
busybox@1.36.1-r19
1.36.1-r21
1
anguda/ant-media:2.5c435285fc241
busybox@1:1.30.1-4ubuntu6.4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.