StackRadar

CVE-2025-46394

Low

Advisory

Published 23 Apr 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
862
of 17,787 indexed, latest versions
Container images
907
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 862 of 17,787 indexed charts deploy, on 907 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.36.1-r10, 1.36.1-r11, 1.36.1-r15, 1.36.1-r17+15 more1.36.1-r21, 1.36.1-r31, 1.37.0-r14, 1.37.0-r20+1 more882
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed25
OSV records
ALPINE-CVE-2025-46394CGA-35qx-p5pw-chp7DEBIAN-CVE-2025-46394UBUNTU-CVE-2025-46394
Also known as
CGA-jgxh-j72w-f3hw

Charts affected

862 by stars
ChartLatestAffected imagesRadar Score
gateway-control-planewallarmVerified publisher0.2.01 of 2See more

gateway-control-plane wallarm 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/gateway-control-plane:0.2.0a321bc974a19
busybox@1.36.1-r20
1.36.1-r21

Open the chart page →

1,455
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/node-next:0.5.24314f3d2b918
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,408
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
busybox@1.37.0-r19
1.37.0-r20

Open the chart page →

4,984
hazelcastwenerme5.10.31See more

hazelcast wenerme 5.10.3

1 container image this version deploys carries CVE-2025-46394.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
busybox@1.37.0-r18
1.37.0-r20
temporalio/server:1.29.1c1e3326b2ce1
busybox@1.37.0-r18
1.37.0-r20

Open the chart page →

14,983
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
busybox@1.37.0-r9
1.37.0-r14

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

789
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

9,381
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
busybox@1.36.1-r19
1.36.1-r21

Open the chart page →

570

Container images carrying it

907 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
anguda/ant-media:2.5c435285fc241
busybox@1:1.30.1-4ubuntu6.4
no fix listed
1
apache/airflow:airflow-pgbouncer-2025.03.05-1.23.18fbd1a66c5f2
busybox@1.36.1-r19
1.36.1-r21
1
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
busybox@1.36.1-r19
1.36.1-r21
1
apache/kafka:4.1.0bff074a5d005
busybox@1.37.0-r19
1.37.0-r20
1
apache/kafka:3.9.0fbc7d7c428e3
busybox@1.36.1-r29
1.36.1-r31
1
apache/kafka-native:4.1.09a9d16e60894
busybox@1.37.0-r18
1.37.0-r20
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
busybox@1.36.1-r29
1.36.1-r31
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
busybox@1.36.1-r31
1.37.0-r14
1
appwrite/console:7.5.7aaa11ceab999
busybox@1.36.1-r29
1.36.1-r31
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
busybox@1.36.1-r15
1.36.1-r21
1
aquasec/tracee:0.24.1cfbbfee972e6
busybox@1.37.0-r13
1.37.0-r14
1
artifacthub/db-migrator:v1.19.02a746b289fcd
busybox@1.36.1-r29
1.36.1-r31
1
artifacthub/hub:v1.19.0111918d8c399
busybox@1.36.1-r29
1.36.1-r31
1
artifacthub/scanner:v1.19.0323d026e78c3
busybox@1.36.1-r29
1.36.1-r31
1
assistiot/resource-provisioning_im:1.0.0a942dc14030a
busybox@1.36.1-r15
1.36.1-r21
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
busybox@1.36.1-r15
1.36.1-r21
1
assistiot/traffic-classification_api:2.0.0e32b87786142
busybox@1.36.1-r15
1.36.1-r21
1
automatischio/automatisch:0.15.03bace7a12d5f
busybox@1.37.0-r12
1.37.0-r14
1
b3log/siyuan:v3.1.2595c0d129bc19
busybox@1.37.0-r12
1.37.0-r14
1
b4bz/homer:v24.12.14b44a4a9e329
busybox@1.36.1-r29
1.36.1-r31
1
b4bz/homer:v25.02.2c367265313f9
busybox@1.37.0-r12
1.37.0-r14
1
behnambm/docker-sample:v1bd3ad88afff9
busybox@1.36.1-r29
1.36.1-r31
1
beopenit/door-agent:v3.0.5d24c323fe7c3
busybox@1.36.1-r15
1.36.1-r21
1
beyzkaya/blog-frontend:v1.0.0bf412d75c510
busybox@1.37.0-r18
1.37.0-r20
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
busybox@1.36.1-r15
1.36.1-r21
1
blipai/deckard:0.0.28737d5d19a312
busybox@1.36.1-r15
1.36.1-r21
1
buddyspencer/gickup:0.10.386b656f19b0c1
busybox@1.36.1-r29
1.36.1-r31
1
burganbank/vault-initializer:v19259c34e4037
busybox@1.36.1-r28
1.36.1-r31
1
byrnedo/alpine-curl:latest7f0599d553e2
busybox@1.37.0-r19
1.37.0-r20
1
caarlos0/domain_exporter:v1.23.0d11dec138900
busybox@1.36.1-r15
1.36.1-r21
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
busybox@1.37.0-r18
1.37.0-r20
1
carlosmz87/test_helm_frontend:latest79f4b528f42a
busybox@1.36.1-r29
1.36.1-r31
1
casbin/casdoor:v1.753.0770ad9ec3190
busybox@1.36.1-r29
1.36.1-r31
1
censedata/floating-server:v1.6.3ebfffb9dd4c0
busybox@1.37.0-r12
1.37.0-r14
1
cesanta/docker_auth:1.14.098e0307e0d2d
busybox@1.37.0-r18
1.37.0-r20
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
busybox@1.37.0-r12
1.37.0-r14
1
chatwoot/chatwoot:v4.15.167ebc751c171
busybox@1.37.0-r12
1.37.0-r14
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
busybox@1:1.21.0-1ubuntu1.4
no fix listed
1
chibisafe/chibisafe:latest836467a50792
busybox@1.37.0-r18
1.37.0-r20
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
busybox@1.37.0-r18
1.37.0-r20
1
chrislusf/seaweedfs:3.64634b094b2183
busybox@1.36.1-r15
1.36.1-r21
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
busybox@1.37.0-r9
1.37.0-r14
1
ciuse99/suggestarr:v1.0.20d72768245ef5
busybox@1.37.0-r12
1.37.0-r14
1
clickhouse/clickhouse-server:26.701b81d1432c4
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.3810861a2e2d0
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.3.1092098d3b31dd
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:24.12.6.70-alpinecd450891db46
busybox@1.37.0-r12
1.37.0-r14
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
busybox@1.37.0-r19
1.37.0-r20
1
clsen2024/daejeon_2-3:latest1156cd87c8fb
busybox@1.36.1-r29
1.36.1-r31
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.