StackRadar

CVE-2025-4673

Medium

Advisory

Published 11 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,857
of 17,821 indexed, latest versions
Container images
3,453
deployed by those charts
Fix available
1 of 2
affected packages

Sensitive headers not cleared on cross-origin redirect in net/http

Carried by container images the latest versions of 2,857 of 17,821 indexed charts deploy, on 3,453 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+156 more1.23.103,453
OSV records
DEBIAN-CVE-2025-4673GO-2025-3751
Also known as
BIT-golang-2025-4673

Charts affected

2,857 by stars
ChartLatestAffected imagesRadar Score
nydus-snapshotterdragonflyVerified publisher0.0.101 of 2See more

nydus-snapshotter dragonfly 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
stdlib@go1.18.10
1.23.10

Open the chart page →

3,669
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
stdlib@go1.20.12
1.23.10

Open the chart page →

69,465
gethdysnixVerified publisher1.1.21 of 1See more

geth dysnix 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ethereum/client-go:v1.14.8886ec69b35b0
stdlib@go1.22.6
1.23.10

Open the chart page →

1,627
glideeinstackOfficialVerified publisher0.0.21 of 1See more

glide einstack 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
stdlib@go1.21.6
1.23.10

Open the chart page →

1,335
elchi-discoveryelchi1.0.01 of 1See more

elchi-discovery elchi 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
jhonbrownn/elchi-discovery:latest8f6551ecc98c
stdlib@go1.23.1
1.23.10

Open the chart page →

638
elchi-stackelchi1.13.03 of 10See more

elchi-stack elchi 1.13.0

3 of the 10 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.23.10
otel/opentelemetry-collector-contrib:0.89.0995f17004231
stdlib@go1.21.4
1.23.10
victoriametrics/victoria-metrics:v1.93.577a9815d0640
stdlib@go1.21.1
1.23.10

Open the chart page →

15,785
navidromeemmas-chartsVerified publisher0.0.61 of 1See more

navidrome emmas-charts 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
deluan/navidrome:0.50.02cf4442b0099
stdlib@go1.21.0
1.23.10

Open the chart page →

2,130
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.23.10

Open the chart page →

31,614
nexus-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

nexus-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
stdlib@go1.17.2
1.23.10

Open the chart page →

2,267
httpbingoestahnVerified publisher0.1.11 of 1See more

httpbingo estahn 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
mccutchen/go-httpbin:v2.2.25994403ef75b
stdlib@go1.16.2
1.23.10

Open the chart page →

1,360
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
stdlib@go1.23.5
1.23.10

Open the chart page →

3,121
genesis-generatorethereum-helm-chartsVerified publisher0.2.31 of 2See more

genesis-generator ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
skylenet/ethereum-genesis-generator:latest210353ce7c89
stdlib@go1.17.13
1.23.10

Open the chart page →

3,138
ipfs-clusterethereum-helm-chartsVerified publisher0.1.142 of 3See more

ipfs-cluster ethereum-helm-charts 0.1.14

2 of the 3 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ipfs/kubo:latestb293923d66e4
stdlib@go1.19.8
1.23.10
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
stdlib@go1.19.3
1.23.10

Open the chart page →

4,717
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.19.8
1.23.10

Open the chart page →

11,495
event-exporterevent-exporterVerified publisher0.1.171 of 1See more

event-exporter event-exporter 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
kubestar/event-exporter:latest656606941255
stdlib@go1.20.14
1.23.10

Open the chart page →

1,211
events-exporterevents-exporter0.0.41 of 1See more

events-exporter events-exporter 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
stdlib@go1.19.5
1.23.10

Open the chart page →

2,135
github-actions-runner-operatorevryfs-ossVerified publisher2.8.11 of 1See more

github-actions-runner-operator evryfs-oss 2.8.1

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
stdlib@go1.21.1
1.23.10

Open the chart page →

1,237
vidcheckfactlyVerified publisher0.5.21 of 2See more

vidcheck factly 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
factly/vidcheck-server:0.12.087064eb0463c
stdlib@go1.14.2
1.23.10

Open the chart page →

3,621
ecr-cleanupfairwinds-stableVerified publisher1.2.81 of 1See more

ecr-cleanup fairwinds-stable 1.2.8

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
stdlib@go1.19.6
1.23.10

Open the chart page →

1,005
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.23.10
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.23.10
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.23.10

Open the chart page →

8,691
federidfederidOfficialVerified publisher0.1.21 of 1See more

federid federid 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
federid/webhook:0.1.0fbfb7c6510a7
stdlib@go1.23.3
1.23.10

Open the chart page →

2,041
fission-corefission-chartsVerified publisher1.14.13 of 3See more

fission-core fission-charts 1.14.1

3 of the 3 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
fission/fission-bundle:1.14.13fcfd8a0fa5d
stdlib@go1.15.14
1.23.10
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
stdlib@go1.15.14
1.23.10
fission/reporter:1.14.104c6e06af175
stdlib@go1.15.14
1.23.10

Open the chart page →

7,110
openldapfluktuid0.1.11 of 2See more

openldap fluktuid 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.23.10

Open the chart page →

3,315
free5gcfree5gcVerified publisher0.1.311 of 12See more

free5gc free5gc 0.1.3

11 of the 12 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
stdlib@go1.21.8
1.23.10
free5gc/ausf:v3.4.3687ff4daf5da
stdlib@go1.21.8
1.23.10
free5gc/chf:v3.4.3e2a4dd98a4ed
stdlib@go1.21.8
1.23.10
free5gc/nrf:v3.4.399e46b860efb
stdlib@go1.21.8
1.23.10
free5gc/nssf:v3.4.3dfe8c68c04b4
stdlib@go1.21.8
1.23.10
free5gc/pcf:v3.4.3f712e8ecd927
stdlib@go1.21.8
1.23.10
free5gc/smf:v3.4.360e38baa4b10
stdlib@go1.21.8
1.23.10
free5gc/udm:v3.4.32f68df062a50
stdlib@go1.21.8
1.23.10
free5gc/udr:v3.4.3c0783bcdcbdc
stdlib@go1.21.8
1.23.10
free5gc/upf:v3.4.3b6b362a39fdd
stdlib@go1.21.8
1.23.10
free5gc/webui:v3.4.39adeb18492cb
stdlib@go1.21.8
1.23.10

Open the chart page →

10,717
fsmfsmOfficialVerified publisher0.2.112 of 5See more

fsm fsm 0.2.11

2 of the 5 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
stdlib@go1.19.13
1.23.10
flomesh/fsm-manager:0.2.1122f849c70b25
stdlib@go1.19.13
1.23.10

Open the chart page →

4,228
adguard-homegabe565Verified publisher0.3.251 of 2See more

adguard-home gabe565 0.3.25

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.56c64a0b37f7b9
stdlib@go1.23.5
1.23.10

Open the chart page →

815
home-assistantgabe565Verified publisher0.17.01 of 1See more

home-assistant gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:latestd89226851697
stdlib@go1.23.3
1.23.10

Open the chart page →

2,162
memosgabe565Verified publisher0.17.01 of 1See more

memos gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/usememos/memos:0.24.04723d86e6797
stdlib@go1.23.6
1.23.10

Open the chart page →

1,477
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
stdlib@go1.16.2
1.23.10

Open the chart page →

3,399
gboxgboxVerified publisher1.0.51 of 2See more

gbox gbox 1.0.5

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
gboxproxy/gbox:v1.0.63a9f4a711d5c
stdlib@go1.17.9
1.23.10

Open the chart page →

2,539
adguard-homegeek-cookbookVerified publisher5.5.21 of 2See more

adguard-home geek-cookbook 5.5.2

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.7b9974aed13d0
stdlib@go1.17.9
1.23.10

Open the chart page →

1,743
alertmanager-botgeek-cookbookVerified publisher6.4.21 of 1See more

alertmanager-bot geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
stdlib@go1.13.15
1.23.10

Open the chart page →

3,588
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.23.10

Open the chart page →

17,598
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
stdlib@go1.16.9
1.23.10

Open the chart page →

3,476
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
stdlib@go1.16.5
1.23.10

Open the chart page →

3,634
influxdb-exportergeek-cookbookVerified publisher1.2.21 of 1See more

influxdb-exporter geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.23.10

Open the chart page →

1,051
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.23.10

Open the chart page →

14,040
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
stdlib@go1.17.7
1.23.10

Open the chart page →

2,569
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
stdlib@go1.15.2
1.23.10

Open the chart page →

3,168
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
stdlib@go1.15.12
1.23.10

Open the chart page →

8,061
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.23.10

Open the chart page →

11,800
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.23.10

Open the chart page →

10,314
sambageek-cookbookVerified publisher6.2.21 of 1See more

samba geek-cookbook 6.2.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.23.10

Open the chart page →

2,319
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.23.10

Open the chart page →

13,338
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
stdlib@go1.13.15
1.23.10

Open the chart page →

15,926
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
stdlib@go1.17.5
1.23.10

Open the chart page →

5,133
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latestc885aa902faf
stdlib@go1.24.1
1.23.10

Open the chart page →

2,671
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.23.10

Open the chart page →

7,724
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.23.10
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.23.10

Open the chart page →

14,566
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.23.10

Open the chart page →

6,489

Container images carrying it

3,453 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.23.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.23.10
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.23.10
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.