StackRadar

CVE-2025-46394

Low

Advisory

Published 23 Apr 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
867
of 17,787 indexed, latest versions
Container images
912
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 867 of 17,787 indexed charts deploy, on 912 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.36.1-r10, 1.36.1-r11, 1.36.1-r15, 1.36.1-r17+15 more1.36.1-r21, 1.36.1-r31, 1.37.0-r14, 1.37.0-r20+1 more886
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2025-46394CGA-35qx-p5pw-chp7DEBIAN-CVE-2025-46394UBUNTU-CVE-2025-46394
Also known as
CGA-jgxh-j72w-f3hw

Charts affected

867 by stars
ChartLatestAffected imagesRadar Score
mosquittovicsuferVerified publisher0.1.11 of 1See more

mosquitto vicsufer 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.2021421af7b32b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

364
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

2,077
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
busybox@1.37.0-r18
1.37.0-r20

Open the chart page →

6,470
vote-appvote-appVerified publisher1.0.73 of 6See more

vote-app vote-app 1.0.7

3 of the 6 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
busybox@1.36.1-r28
1.36.1-r31
thecloudspark/app-vote:1.0c7da7417a86a
busybox@1.36.1-r28
1.36.1-r31
thecloudspark/app-worker:1.0dbfcfe02bf36
busybox@1.36.1-r15
1.36.1-r21

Open the chart page →

3,030
waldur-site-agentwaldur-site-agentVerified publisher1.0.71 of 1See more

waldur-site-agent waldur-site-agent 1.0.7

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

534
gateway-control-planewallarmVerified publisher0.2.01 of 2See more

gateway-control-plane wallarm 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/gateway-control-plane:0.2.0a321bc974a19
busybox@1.36.1-r20
1.36.1-r21

Open the chart page →

1,455
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/node-next:0.5.24314f3d2b918
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,408
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
busybox@1.37.0-r19
1.37.0-r20

Open the chart page →

4,985
hazelcastwenerme5.10.31 of 2See more

hazelcast wenerme 5.10.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,623
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
busybox@1.37.0-r18
1.37.0-r20
temporalio/server:1.29.1c1e3326b2ce1
busybox@1.37.0-r18
1.37.0-r20

Open the chart page →

14,618
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

6,323
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
busybox@1.37.0-r9
1.37.0-r14

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

789
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

13,197
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

9,381
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
busybox@1.36.1-r19
1.36.1-r21

Open the chart page →

569

Container images carrying it

912 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
iomesh/deck:v0.2.0282d6c419ed3
busybox@1.36.1-r29
1.36.1-r31
1
iomesh/deck:v0.1.0a31e26b6ae22
busybox@1.36.1-r15
1.36.1-r21
1
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
busybox@1.36.1-r15
1.36.1-r21
1
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
busybox@1.36.1-r29
1.36.1-r31
1
isebben/smart-proxy:latestab59a71ee9f4
busybox@1.36.1-r20
1.36.1-r21
1
ivanjosipovic/ingress-nginx-validate-jwt:1.13.995089339a68ae
busybox@1.37.0-r12
1.37.0-r14
1
jaegertracing/jaeger:2.9.0e128b9adbb29
busybox@1.37.0-r18
1.37.0-r20
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
busybox@1.36.1-r29
1.36.1-r31
1
jeboehm/mailserver-filter:5.0.92e756949e537d
busybox@1.37.0-r12
1.37.0-r14
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
busybox@1.37.0-r12
1.37.0-r14
1
jeboehm/mailserver-mta:5.0.925fb2f31c940d
busybox@1.37.0-r12
1.37.0-r14
1
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
busybox@1.37.0-r12
1.37.0-r14
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
busybox@1.37.0-r18
1.37.0-r20
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
busybox@1.36.1-r29
1.36.1-r31
1
jlesage/firefox:v25.03.1055c28defe31
busybox@1.37.0-r9
1.37.0-r14
1
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
busybox@1.36.1-r29
1.36.1-r31
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
busybox@1.36.1-r29
1.36.1-r31
1
kfirfer/elasticsearch-cacher:0.0.1cf81d0959256
busybox@1.37.0-r8
1.37.0-r14
1
kfirfer/mysql-client:0.0.4d23d173f333f
busybox@1.36.1-r15
1.36.1-r21
1
khaliq/drl-exporter:latestf63cf53166f8
busybox@1.36.1-r29
1.36.1-r31
1
khaliq/pingme:v0.2.749f96888d2ab
busybox@1.37.0-r19
1.37.0-r20
1
kiwigrid/k8s-sidecar:1.27.6db85bd553253
busybox@1.36.1-r29
1.36.1-r31
1
kiwigrid/k8s-sidecar:1.26.2e271016441af
busybox@1.36.1-r15
1.36.1-r21
1
kubesec/kubesec:latest025a365d9f18
busybox@1.36.1-r29
1.36.1-r31
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
busybox@1.36.1-r29
1.36.1-r31
1
kubeshop/testkube-logs-server:latest094186b19698
busybox@1.37.0-r12
1.37.0-r14
1
kubeshop/tracetest:v1.7.173d7e3a2db43
busybox@1.36.1-r29
1.36.1-r31
1
kubesphere/ks-extensions-museum:latest29681958f220
busybox@1.36.1-r15
1.36.1-r21
1
kubevious/backend:1.2.22d9ba6eb46b6
busybox@1.36.1-r15
1.36.1-r21
1
kubevious/parser:1.2.299ae7a5168c2
busybox@1.36.1-r15
1.36.1-r21
1
langgenius/dify-web:0.6.11a2a294743634
busybox@1.36.1-r15
1.36.1-r21
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
busybox@1.37.0-r13
1.37.0-r14
1
langgenius/dify-web:1.0.0d64914ff0d6d
busybox@1.36.1-r29
1.36.1-r31
1
layer5/meshery:stable-latest78a8be21bef3
busybox@1.37.0-r12
1.37.0-r14
1
leantime/leantime:3.3.3ad4bfb0699d3
busybox@1.36.1-r29
1.36.1-r31
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
busybox@1.36.1-r29
1.36.1-r31
1
library/bash:5.2.21a422913be6a4
busybox@1.36.1-r15
1.36.1-r21
1
library/caddy:2.9-alpineb4e3952384eb
busybox@1.36.1-r29
1.36.1-r31
1
library/docker:28.5.2-dind2a232a42256f
busybox@1.37.0-r19
1.37.0-r20
1
library/docker:27-cli851f91d24121
busybox@1.37.0-r12
1.37.0-r14
1
library/docker:27-dindaa3df78ecf32
busybox@1.37.0-r12
1.37.0-r14
1
library/docker:26.1-dinddd43b430341a
busybox@1.36.1-r29
1.36.1-r31
1
library/eclipse-mosquitto:2.0.2021421af7b32b
busybox@1.36.1-r29
1.36.1-r31
1
library/memcached:1.6.32-alpine0a27d9d5084f
busybox@1.36.1-r29
1.36.1-r31
1
library/memcached:1.6.29-alpine462ae4a35c26
busybox@1.36.1-r29
1.36.1-r31
1
library/memcached:1.6.39-alpine3.227b45203a99eb
busybox@1.37.0-r19
1.37.0-r20
1
library/memcached:1.6.26-alpine8906e7654a20
busybox@1.36.1-r15
1.36.1-r21
1
library/memcached:1.6.38-alpinee93269864a7d
busybox@1.37.0-r18
1.37.0-r20
1
library/memcached:1.6.24-alpineeff78098089f
busybox@1.36.1-r15
1.36.1-r21
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
busybox@1.36.1-r19
1.36.1-r21
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.