StackRadar

CVE-2025-46394

Low

Advisory

Published 23 Apr 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
857
of 17,787 indexed, latest versions
Container images
902
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 857 of 17,787 indexed charts deploy, on 902 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.36.1-r10, 1.36.1-r11, 1.36.1-r15, 1.36.1-r17+15 more1.36.1-r21, 1.36.1-r31, 1.37.0-r14, 1.37.0-r20+1 more877
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed25
OSV records
ALPINE-CVE-2025-46394CGA-35qx-p5pw-chp7DEBIAN-CVE-2025-46394UBUNTU-CVE-2025-46394
Also known as
CGA-jgxh-j72w-f3hw

Charts affected

857 by stars
ChartLatestAffected imagesRadar Score
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
busybox@1.37.0-r9
1.37.0-r14

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
busybox@1.37.0-r12
1.37.0-r14

Open the chart page →

789
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
busybox@1.36.1-r29
1.36.1-r31

Open the chart page →

9,381
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-46394.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
busybox@1.36.1-r19
1.36.1-r21

Open the chart page →

570

Container images carrying it

902 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
busybox@1.37.0-r19
1.37.0-r20
13
curlimages/curl:8.5.008e466006f08
busybox@1.36.1-r15
1.36.1-r21
7
curlimages/curl:8.17.0935d9100e9ba
busybox@1.37.0-r19
1.37.0-r20
6
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
busybox@1.36.1-r29
1.36.1-r31
6
alpine/kubectl:1.34.18413f8890d19
busybox@1.37.0-r19
1.37.0-r20
5
keelhq/keel:latest73714afb4443
busybox@1.36.1-r29
1.36.1-r31
5
library/alpine:3.196baf43584bcb
busybox@1.36.1-r20
1.36.1-r21
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
busybox@1.37.0-r12
1.37.0-r14
5
curlimages/curl:8.8.073e4d532ea62
busybox@1.36.1-r18
1.36.1-r21
4
library/rabbitmq:3.13-management-alpine:3-management-alpine606d8c0d6b3c
busybox@1.37.0-r19
1.37.0-r20
4
openquantumsafe/openssl3:latest543fb00ce31d
busybox@1.37.0-r9
1.37.0-r14
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
busybox@1.36.1-r15
1.36.1-r21
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
busybox@1.36.1-r29
1.36.1-r31
4
alfhou/hammond:v0.0.24c85dc0293aa1
busybox@1.36.1-r15
1.36.1-r21
3
derailed/popeye:v0.22.18e68e22c7663
busybox@1.37.0-r9
1.37.0-r14
3
grafana/grafana:11.0.00dc5a246ab16
busybox@1.36.1-r15
1.36.1-r21
3
grafana/grafana:11.3.0a0f881232a6f
busybox@1.36.1-r29
1.36.1-r31
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
busybox@1.37.0-r19
1.37.0-r20
3
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
busybox@1.36.1-r29
1.36.1-r31
3
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
busybox@1.37.0-r12
1.37.0-r14
3
library/nginx:1.25.5-alpine:1.25-alpine516475cc129d
busybox@1.36.1-r15
1.36.1-r21
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
busybox@1.36.1-r29
1.36.1-r31
3
library/redis:7.2.4-alpinec8bb255c3559
busybox@1.36.1-r15
1.36.1-r21
3
migrate/migrate:latestcc4ad8e19d66
busybox@1.36.1-r20
1.36.1-r21
3
natsio/nats-box:0.19.28031d190c7ee
busybox@1.37.0-r19
1.37.0-r20
3
opencsghq/psql:latest57def8e77d0f
busybox@1.37.0-r9
1.37.0-r14
3
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
busybox@1:1.37.0-6+dhi1
no fix listed
3
wallabag/wallabag:2.6.144a527e027e0d
busybox@1.36.1-r19
1.36.1-r21
3
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
busybox@1.37.0-r12
1.37.0-r14
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed
3
quay.io/devtron/devtron-utils:geni-v1.1.4f6269309455a
busybox@1.36.1-r15
1.36.1-r21
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
busybox@1.37.0-r9
1.37.0-r14
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
busybox@1.37.0-r9
1.37.0-r14
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
busybox@1.36.1-r15
1.36.1-r21
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
busybox@1.37.0-r9
1.37.0-r14
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
busybox@1.37.0-r9
1.37.0-r14
3
alpine/curl:8.7.1f0c1b7ca12f6
busybox@1.36.1-r29
1.36.1-r31
2
alpine/git:2.47.2062a01ad7a0e
busybox@1.37.0-r12
1.37.0-r14
2
apache/fineract:1.12.1a83cf1980609
busybox@1.36.1-r30
1.36.1-r31
2
apache/superset:dockerizeafe59523a6c8
busybox@1.36.1-r15
1.36.1-r21
2
apecloud/apecloud-mcp:0.1.094041b080510
busybox@1.37.0-r18
1.37.0-r20
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
busybox@1.36.1-r29
1.36.1-r31
2
clickhouse/clickhouse-server:25.7-alpine258d43821508
busybox@1.37.0-r19
1.37.0-r20
2
clickhouse/clickhouse-server:24.3.3.102-alpinef226fe41f057
busybox@1.36.1-r15
1.36.1-r21
2
clickhouse/clickhouse-server:26.8.2:latestfa394da808cc
busybox@1:1.30.1-7ubuntu3.1
no fix listed
2
curlimages/curl:8.15.04026b29997dc
busybox@1.37.0-r18
1.37.0-r20
2
curlimages/curl:8.6.0c3b8bee303c6
busybox@1.36.1-r15
1.36.1-r21
2
devopsfaith/krakend:latestf8bdaa8a1a43
busybox@1.37.0-r12
1.37.0-r14
2
dtzar/helm-kubectl:3.14.455429449408e
busybox@1.36.1-r15
1.36.1-r21
2
epamedp/krci-portal:0.8.0687acf641097
busybox@1.36.1-r15
1.36.1-r21
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.