StackRadar

CVE-2025-46394

Low

Advisory

Published 23 Apr 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
861
of 17,790 indexed, latest versions
Container images
907
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 861 of 17,790 indexed charts deploy, on 907 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.36.1-r10, 1.36.1-r11, 1.36.1-r15, 1.36.1-r17+15 more1.36.1-r21, 1.36.1-r31, 1.37.0-r14, 1.37.0-r20+1 more882
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed25
OSV records
ALPINE-CVE-2025-46394CGA-35qx-p5pw-chp7DEBIAN-CVE-2025-46394UBUNTU-CVE-2025-46394
Also known as
CGA-jgxh-j72w-f3hw

Charts affected

861 by stars
ChartLatestAffected imagesRadar Score
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
wallarm/node-next:0.5.24314f3d2b918
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,408
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
busybox@1.37.0-r19
1.37.0-r20

Open the chart page →

4,985
hazelcastwenerme5.10.31 of 2See more

hazelcast wenerme 5.10.3

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

2,623
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
busybox@1.37.0-r18
1.37.0-r20
temporalio/server:1.29.1c1e3326b2ce1
busybox@1.37.0-r18
1.37.0-r20

Open the chart page →

14,618
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

6,323
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
busybox@1.37.0-r9
1.37.0-r14

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

789
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

13,197
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

9,381
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
busybox@1.36.1-r19
1.36.1-r21

Open the chart page →

569

Container images carrying it

907 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/nats:2.10.12-alpinebca70839d953
busybox@1.36.1-r15
1.36.1-r21
1
library/nextcloud:31.0.6-apache588609d76b21
busybox@1:1.35.0-4+b4
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
busybox@1:1.37.0-6+b3
no fix listed
1
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
busybox@1:1.37.0-6+b8
no fix listed
1
library/nextcloud:34.0.4-apachede4ad9389386
busybox@1:1.37.0-6+b8
no fix listed
1
library/nginx:1.25.5-alpine-slim22414422d1ba
busybox@1.36.1-r15
1.36.1-r21
1
library/nginx:1.27-alpine65645c7bb6a0
busybox@1.37.0-r12
1.37.0-r14
1
library/nginx:1.29.3-alpineb3c656d55d7a
busybox@1.37.0-r19
1.37.0-r20
1
library/node:18-alpine8d6421d663b4
busybox@1.37.0-r12
1.37.0-r14
1
library/postgres:18.1-alpine3.2144d837eb4c2e
busybox@1.37.0-r13
1.37.0-r14
1
library/postgres:16.4-alpine5660c2cbfea5
busybox@1.36.1-r29
1.36.1-r31
1
library/postgres:17.5-alpine6567bca8d7bc
busybox@1.37.0-r18
1.37.0-r20
1
library/postgres:17.4-alpine7062a2109c4b
busybox@1.37.0-r12
1.37.0-r14
1
library/postgres:12-alpine7c8f48705831
busybox@1.37.0-r9
1.37.0-r14
1
library/postgres:17.2-alpine7e5df973a748
busybox@1.37.0-r9
1.37.0-r14
1
library/postgres:16.2-alpine951bfda46030
busybox@1.36.1-r15
1.36.1-r21
1
library/postgres:17.6-alpineef257d85f76e
busybox@1.37.0-r19
1.37.0-r20
1
library/python:3.8-alpine3d93b1f77efc
busybox@1.36.1-r29
1.36.1-r31
1
library/rabbitmq:3.12-management-alpine0b44fbcc3a4b
busybox@1.36.1-r29
1.36.1-r31
1
library/rabbitmq:3.13.1-alpine4bcec9fde55c
busybox@1.36.1-r15
1.36.1-r21
1
library/rabbitmq:3.12-alpine97907aceae0a
busybox@1.36.1-r29
1.36.1-r31
1
library/rabbitmq:3.13.0-alpineb4abd8d41c68
busybox@1.36.1-r15
1.36.1-r21
1
library/redis:7.2.5-alpine6aaf3f5e6bc8
busybox@1.36.1-r29
1.36.1-r31
1
library/redis:6.2.20-alpine77697a75da9f
busybox@1.37.0-r13
1.37.0-r14
1
library/redis:7.4.1-alpinec1e88455c852
busybox@1.36.1-r29
1.36.1-r31
1
library/redis:7.0-alpinec9d92d840fd0
busybox@1.36.1-r29
1.36.1-r31
1
library/traefik:v2.11.00a5157f742d2
busybox@1.36.1-r15
1.36.1-r21
1
library/traefik:3.3.5104204dadedf
busybox@1.37.0-r12
1.37.0-r14
1
library/varnish:7.3-alpine6db2c9e4c2dd
busybox@1.36.1-r19
1.36.1-r21
1
librenms/librenms:24.11.00920bc9117a8
busybox@1.36.1-r19
1.36.1-r21
1
lifailon/openrouter-bot:latestea37e4b6b952
busybox@1.37.0-r18
1.37.0-r20
1
linkstackorg/linkstack:latest1c8b05399ee4
busybox@1.37.0-r19
1.37.0-r20
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
busybox@1.37.0-r12
1.37.0-r14
1
linuxserver/heimdall:2.6.371597f4461e4
busybox@1.36.1-r29
1.36.1-r31
1
linuxserver/openssh-server:9.7_p1-r4-ls17153ea39d2485c
busybox@1.36.1-r29
1.36.1-r31
1
linuxserver/smokeping:2.8.2b7f906899cd3
busybox@1.36.1-r29
1.36.1-r31
1
litlyx/litlyx-consumer:latest02225e77d316
busybox@1.37.0-r19
1.37.0-r20
1
litlyx/litlyx-dashboard:lateste64ff2d52385
busybox@1.37.0-r19
1.37.0-r20
1
litlyx/litlyx-producer:latest10407f36613f
busybox@1.37.0-r19
1.37.0-r20
1
livekit/livekit-server:v1.9.03602a85840d5
busybox@1.37.0-r18
1.37.0-r20
1
loeken/radarr:5.27.0-nightlya24409d3846d
busybox@1.37.0-r13
1.37.0-r14
1
maildev/maildev:2.2.1180ef51f65ee
busybox@1.37.0-r8
1.37.0-r14
1
mathieuruellan/piwigo:latest04572c8a1b04
busybox@1.36.1-r29
1.36.1-r31
1
mathnao/certs:2.1.3b900e6b64684
busybox@1.37.0-r12
1.37.0-r14
1
mauricenino/dashdot:5.9.2236997816917
busybox@1.37.0-r12
1.37.0-r14
1
mavrick1/kubestellar-b:latest45ca0429a1d4
busybox@1.37.0-r12
1.37.0-r14
1
mavrick1/kubestellar-f:latest56bd8eaa53a4
busybox@1.37.0-r12
1.37.0-r14
1
metabase/metabase:v0.53.4.17807bc5cad17
busybox@1.37.0-r12
1.37.0-r14
1
mikefarah/yq:4.45.12c100efaca06
busybox@1.37.0-r9
1.37.0-r14
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
busybox@1.36.1-r28
1.36.1-r31
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.