StackRadar

CVE-2025-46394

Low

Advisory

Published 23 Apr 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
867
of 17,787 indexed, latest versions
Container images
912
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 867 of 17,787 indexed charts deploy, on 912 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.36.1-r10, 1.36.1-r11, 1.36.1-r15, 1.36.1-r17+15 more1.36.1-r21, 1.36.1-r31, 1.37.0-r14, 1.37.0-r20+1 more886
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2025-46394CGA-35qx-p5pw-chp7DEBIAN-CVE-2025-46394UBUNTU-CVE-2025-46394
Also known as
CGA-jgxh-j72w-f3hw

Charts affected

867 by stars
ChartLatestAffected imagesRadar Score
mosquittovicsuferVerified publisher0.1.11 of 1See more

mosquitto vicsufer 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.2021421af7b32b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

364
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

2,077
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
busybox@1.37.0-r18
1.37.0-r20

Open the chart page →

6,470
vote-appvote-appVerified publisher1.0.73 of 6See more

vote-app vote-app 1.0.7

3 of the 6 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
busybox@1.36.1-r28
1.36.1-r31
thecloudspark/app-vote:1.0c7da7417a86a
busybox@1.36.1-r28
1.36.1-r31
thecloudspark/app-worker:1.0dbfcfe02bf36
busybox@1.36.1-r15
1.36.1-r21

Open the chart page →

3,030
waldur-site-agentwaldur-site-agentVerified publisher1.0.71 of 1See more

waldur-site-agent waldur-site-agent 1.0.7

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

534
gateway-control-planewallarmVerified publisher0.2.01 of 2See more

gateway-control-plane wallarm 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/gateway-control-plane:0.2.0a321bc974a19
busybox@1.36.1-r20
1.36.1-r21

Open the chart page →

1,455
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/node-next:0.5.24314f3d2b918
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,408
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
busybox@1.37.0-r19
1.37.0-r20

Open the chart page →

4,985
hazelcastwenerme5.10.31 of 2See more

hazelcast wenerme 5.10.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,623
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
busybox@1.37.0-r18
1.37.0-r20
temporalio/server:1.29.1c1e3326b2ce1
busybox@1.37.0-r18
1.37.0-r20

Open the chart page →

14,618
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

6,323
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
busybox@1.37.0-r9
1.37.0-r14

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

789
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

13,197
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

9,381
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
busybox@1.36.1-r19
1.36.1-r21

Open the chart page →

569

Container images carrying it

912 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
emqxecp/otelcol:2.5.04c31d9bec846
busybox@1.36.1-r29
1.36.1-r31
1
emqx/emqx-ee:4.4.38d48360ed86f4
busybox@1.37.0-r12
1.37.0-r14
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
busybox@1.37.0-r12
1.37.0-r14
1
erenozcan17/go_backend:v4.250b4f23422b6
busybox@1.37.0-r18
1.37.0-r20
1
erenozcan17/react_frontend:v4.56e1b14973f9b
busybox@1.37.0-r18
1.37.0-r20
1
erudikaltd/scoold:1.66.0949c56b57e8f
busybox@1.37.0-r19
1.37.0-r20
1
esteban1930/frontend-1:1.8.0f9078279632c
busybox@1.37.0-r18
1.37.0-r20
1
ethereum/client-go:v1.15.101f36ca5922a5
busybox@1.37.0-r12
1.37.0-r14
1
ethereum/client-go:v1.16.532b878e4144a
busybox@1.37.0-r19
1.37.0-r20
1
ethereum/client-go:v1.14.8886ec69b35b0
busybox@1.36.1-r29
1.36.1-r31
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
busybox@1.37.0-r12
1.37.0-r14
1
ethpandaops/ethereumjs:masterfb84b718500f
busybox@1.37.0-r12
1.37.0-r14
1
ethpandaops/xatu-cbt-api:latestf7dec2e07091
busybox@1.37.0-r19
1.37.0-r20
1
evoapicloud/evolution-manager:latestcbfeb314afb9
busybox@1.37.0-r19
1.37.0-r20
1
extrim/perlite:1.5.99cb7eb5598b6
busybox@1.37.0-r12
1.37.0-r14
1
fabioformosa/hello-world-api:latest063873af085c
busybox@1.36.1-r15
1.36.1-r21
1
falcosecurity/falcosidekick:2.32.01976da721518
busybox@1.37.0-r18
1.37.0-r20
1
fallenbagel/jellyseerr:latest4538137bc5af
busybox@1.37.0-r18
1.37.0-r20
1
featureformcom/quickstart-loader:latest82396f8fb5e8
busybox@1.36.1-r28
1.36.1-r31
1
featurehub/dacha2:1.9.1c8d5551b5e40
busybox@1.37.0-r12
1.37.0-r14
1
featurehub/edge:1.9.198ad426737f6
busybox@1.37.0-r12
1.37.0-r14
1
featurehub/mr:1.9.1477d8bf771a9
busybox@1.37.0-r12
1.37.0-r14
1
felipecs8/conversor-temperatura:v1f945423be36d
busybox@1.37.0-r12
1.37.0-r14
1
felipecs8/landing-page:v1db6d44e325a1
busybox@1.37.0-r18
1.37.0-r20
1
filiparag/hetzner_ddns:1.0.15a9cbae7997c
busybox@1.37.0-r19
1.37.0-r20
1
flashbots/mev-boost:1.8.07c486b5789da
busybox@1.36.1-r29
1.36.1-r31
1
fleetdm/fleet:v4.66.012e644b7f40e
busybox@1.37.0-r12
1.37.0-r14
1
flowable/flowable-rest:7.1.0b7ae287502cd
busybox@1.36.1-r29
1.36.1-r31
1
folioci/mod-agreements:latest29c3f233a498
busybox@1.36.1-r29
1.36.1-r31
1
folioci/mod-ldp:latestb55696fd9065
busybox@1.36.1-r29
1.36.1-r31
1
folioci/mod-licenses:latestcfd6109bf477
busybox@1.36.1-r29
1.36.1-r31
1
folioci/mod-oa:latestae3b069d4ba5
busybox@1.36.1-r29
1.36.1-r31
1
folioci/mod-search:latest44d7ee9acdf6
busybox@1.37.0-r18
1.37.0-r20
1
folioci/mod-serials-management:latest571fa1ffe8c9
busybox@1.36.1-r29
1.36.1-r31
1
folioci/mod-service-interaction:latestf53c327a48e8
busybox@1.36.1-r29
1.36.1-r31
1
fonoster/routr-connect:2.13.6e8c84b5eaa67
busybox@1.36.1-r19
1.36.1-r21
1
fonoster/routr-dispatcher:2.13.65f8f380dc174
busybox@1.36.1-r19
1.36.1-r21
1
fonoster/routr-edgeport:2.13.6d08a8a574a50
busybox@1.36.1-r19
1.36.1-r21
1
fonoster/routr-location:2.13.6051ba9c34ef5
busybox@1.36.1-r19
1.36.1-r21
1
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
busybox@1.36.1-r19
1.36.1-r21
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
busybox@1.36.1-r19
1.36.1-r21
1
fonoster/routr-registry:2.13.6e27001f2813c
busybox@1.36.1-r19
1.36.1-r21
1
fonoster/routr-requester:2.13.6e0c823506eb2
busybox@1.36.1-r19
1.36.1-r21
1
galaxy/galaxy-init:v18.010267bad550e6
busybox@1:1.21.0-1ubuntu1
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
busybox@1:1.21.0-1ubuntu1
no fix listed
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
busybox@1.37.0-r19
1.37.0-r20
1
gdrocha/togglr-frontend:1.0.0ffbc1571c234
busybox@1.37.0-r19
1.37.0-r20
1
getmeili/meilisearch:v1.11.0b9be3d2d4251
busybox@1.36.1-r29
1.36.1-r31
1
getmeili/meilisearch:v1.13.3bed3fb650e62
busybox@1.36.1-r29
1.36.1-r31
1
getmeili/meilisearch:v1.30.0f3ecbc8c5bfb
busybox@1.37.0-r19
1.37.0-r20
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.