StackRadar

CVE-2025-46394

Low

Advisory

Published 23 Apr 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
867
of 17,787 indexed, latest versions
Container images
912
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 867 of 17,787 indexed charts deploy, on 912 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.36.1-r10, 1.36.1-r11, 1.36.1-r15, 1.36.1-r17+15 more1.36.1-r21, 1.36.1-r31, 1.37.0-r14, 1.37.0-r20+1 more886
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2025-46394CGA-35qx-p5pw-chp7DEBIAN-CVE-2025-46394UBUNTU-CVE-2025-46394
Also known as
CGA-jgxh-j72w-f3hw

Charts affected

867 by stars
ChartLatestAffected imagesRadar Score
mosquittovicsuferVerified publisher0.1.11 of 1See more

mosquitto vicsufer 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.2021421af7b32b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

364
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

2,077
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
busybox@1.37.0-r18
1.37.0-r20

Open the chart page →

6,470
vote-appvote-appVerified publisher1.0.73 of 6See more

vote-app vote-app 1.0.7

3 of the 6 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
busybox@1.36.1-r28
1.36.1-r31
thecloudspark/app-vote:1.0c7da7417a86a
busybox@1.36.1-r28
1.36.1-r31
thecloudspark/app-worker:1.0dbfcfe02bf36
busybox@1.36.1-r15
1.36.1-r21

Open the chart page →

3,030
waldur-site-agentwaldur-site-agentVerified publisher1.0.71 of 1See more

waldur-site-agent waldur-site-agent 1.0.7

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

534
gateway-control-planewallarmVerified publisher0.2.01 of 2See more

gateway-control-plane wallarm 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/gateway-control-plane:0.2.0a321bc974a19
busybox@1.36.1-r20
1.36.1-r21

Open the chart page →

1,455
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/node-next:0.5.24314f3d2b918
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,408
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
busybox@1.37.0-r19
1.37.0-r20

Open the chart page →

4,985
hazelcastwenerme5.10.31 of 2See more

hazelcast wenerme 5.10.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,623
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
busybox@1.37.0-r18
1.37.0-r20
temporalio/server:1.29.1c1e3326b2ce1
busybox@1.37.0-r18
1.37.0-r20

Open the chart page →

14,618
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

6,323
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
busybox@1.37.0-r9
1.37.0-r14

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

789
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

13,197
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

9,381
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
busybox@1.36.1-r19
1.36.1-r21

Open the chart page →

569

Container images carrying it

912 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
clsen2024/daejeon_2-3:latest1156cd87c8fb
busybox@1.36.1-r29
1.36.1-r31
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
busybox@1.36.1-r29
1.36.1-r31
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
busybox@1.36.1-r29
1.36.1-r31
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
busybox@1.36.1-r29
1.36.1-r31
1
cometbft/cometbft:v0.38.1722c2ac018f40
busybox@1.37.0-r12
1.37.0-r14
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
busybox@1.36.1-r29
1.36.1-r31
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
busybox@1.36.1-r15
1.36.1-r21
1
contane/foreman:0.5.2efb98bdcc4e9
busybox@1.37.0-r12
1.37.0-r14
1
copyparty/ac:1.19.200a0a8605062c
busybox@1.37.0-r19
1.37.0-r20
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
busybox@1.37.0-r18
1.37.0-r20
1
cryptexlabs/authf:0.12.11189c07411d7c
busybox@1.36.1-r15
1.36.1-r21
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
busybox@1.36.1-r15
1.36.1-r21
1
curlimages/curl:8.7.125d29daeb9b1
busybox@1.36.1-r15
1.36.1-r21
1
curlimages/curl:8.9.18addc281f0ea
busybox@1.36.1-r29
1.36.1-r31
1
curlimages/curl:8.12.194e9e444bcba
busybox@1.37.0-r12
1.37.0-r14
1
czerwonk/ping_exporter:v1.1.394f51e1ef1e2
busybox@1.36.1-r15
1.36.1-r21
1
daledavies/jump:v1.4.10a0c8ad93902
busybox@1.36.1-r15
1.36.1-r21
1
dannyben/madness:latestebdf50556c02
busybox@1.36.1-r29
1.36.1-r31
1
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
busybox@1.37.0-r18
1.37.0-r20
1
davdiv/musicociel:deva85f99be882c
busybox@1.36.1-r15
1.36.1-r21
1
davidy/giphy-app:1.0.2-arm41b2355cc23a
busybox@1.36.1-r29
1.36.1-r31
1
ddefrancesco/scoperunner-server:0.2.1daaac6657600
busybox@1.36.1-r15
1.36.1-r21
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
busybox@1:1.30.1-7ubuntu3
no fix listed
1
defactops/defactops-ui:1.0.16825cdf9ba706
busybox@1.36.1-r15
1.36.1-r21
1
devopsfaith/krakend:2.7.09219cda867e2
busybox@1.36.1-r19
1.36.1-r21
1
devopstales/kubedash:3.1.08bb837da5aec
busybox@1.36.1-r29
1.36.1-r31
1
devravinder/node-express-app:1.0.05325a96967b5
busybox@1.37.0-r9
1.37.0-r14
1
devture/exim-relay:4.98-r0-47ba30080c7a6
busybox@1.37.0-r9
1.37.0-r14
1
dgraph/ratel:v25.0.34cae1ff95027
busybox@1.37.0-r19
1.37.0-r20
1
dinutac/jinja2docker:2.1.89340dde8a8a4
busybox@1.36.1-r15
1.36.1-r21
1
directus/directus:11.1.0e3c8bb975350
busybox@1.36.1-r29
1.36.1-r31
1
djjudas21/bearhugmugs:0.1.14fa898a52d97
busybox@1.36.1-r29
1.36.1-r31
1
djjudas21/dbdump:0.0.917fc245e29bd
busybox@1.36.1-r15
1.36.1-r21
1
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
busybox@1.37.0-r18
1.37.0-r20
1
djjudas21/liturgical-colour-app:0.7.2954935971d42
busybox@1.37.0-r18
1.37.0-r20
1
djjudas21/nova-exporter:0.0.10e9094580885c
busybox@1.37.0-r18
1.37.0-r20
1
documenso/documenso:v1.8.17f16a9449f18
busybox@1.36.1-r29
1.36.1-r31
1
donetick/donetick:v0.1.60849a43d9e363
busybox@1.37.0-r18
1.37.0-r20
1
dpage/pgadmin4:8.418cd5711fc9a
busybox@1.36.1-r15
1.36.1-r21
1
dpage/pgadmin4:9.252cb72a9e3da
busybox@1.37.0-r12
1.37.0-r14
1
dpage/pgadmin4:8.13561c1f8f99f2
busybox@1.36.1-r29
1.36.1-r31
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
busybox@1.36.1-r15
1.36.1-r21
1
duck1123/dinsro:latest9568c5961d5d
busybox@1.37.0-r9
1.37.0-r14
1
durellirsd/security-smells-api:v17398aca4fc2e
busybox@1.36.1-r28
1.36.1-r31
1
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
busybox@1.37.0-r18
1.37.0-r20
1
dwdraju/alpine-curl-jq:latest83bd9be2b14b
busybox@1.36.1-r29
1.36.1-r31
1
eftechcombr/glpi:nginx-12.0.0-rc1372f0bd43e15
busybox@1.37.0-r12
1.37.0-r14
1
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
busybox@1.37.0-r19
1.37.0-r20
1
elautoestopista/raponchi:0.3.0b6f74db9fc81
busybox@1.36.1-r28
1.36.1-r31
1
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
busybox@1.36.1-r29
1.36.1-r31
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.