StackRadar

CVE-2025-4673

Medium

Advisory

Published 11 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,857
of 17,821 indexed, latest versions
Container images
3,453
deployed by those charts
Fix available
1 of 2
affected packages

Sensitive headers not cleared on cross-origin redirect in net/http

Carried by container images the latest versions of 2,857 of 17,821 indexed charts deploy, on 3,453 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+156 more1.23.103,453
OSV records
DEBIAN-CVE-2025-4673GO-2025-3751
Also known as
BIT-golang-2025-4673

Charts affected

2,857 by stars
ChartLatestAffected imagesRadar Score
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
stdlib@go1.20.5
1.23.10

Open the chart page →

1,096
scannerappscodeVerified publisher2026.1.152 of 3See more

scanner appscode 2026.1.15

2 of the 3 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
stdlib@go1.21.5
1.23.10
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
stdlib@go1.20.2
1.23.10

Open the chart page →

5,343
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
stdlib@go1.23.2
1.23.10

Open the chart page →

873
stash-enterpriseappscodeVerified publisher0.42.02 of 4See more

stash-enterprise appscode 0.42.0

2 of the 4 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.23.10
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
stdlib@go1.23.3
1.23.10

Open the chart page →

3,637
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
stdlib@go1.17.6
1.23.10

Open the chart page →

5,203
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
stdlib@go1.23.3
1.23.10
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
stdlib@go1.23.3
1.23.10

Open the chart page →

2,529
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
stdlib@go1.14.15
1.23.10

Open the chart page →

2,821
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.23.10

Open the chart page →

18,050
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
stdlib@go1.14.12
1.23.10

Open the chart page →

10,801
dltbrokerassist-iot-distributed-broker0.2.04 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

4 of the 9 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
stdlib@go1.17.13
1.23.10
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.23.10
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.23.10
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.23.10

Open the chart page →

194,576
dltloggingassist-iot-logging-auditing0.2.04 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

4 of the 9 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
stdlib@go1.17.13
1.23.10
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.23.10
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.23.10
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.23.10

Open the chart page →

194,556
deployautoml0.1.02 of 3See more

deploy automl 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.23.10
muonsoft/openapi-mock:latestc9afe1295484
stdlib@go1.20.2
1.23.10

Open the chart page →

2,950
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
stdlib@go1.17.5
1.23.10

Open the chart page →

4,326
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
stdlib@go1.16.2
1.23.10

Open the chart page →

3,399
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
stdlib@go1.18.1
1.23.10

Open the chart page →

3,750
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.23.10

Open the chart page →

1,277
kubebrowseravistoOfficialVerified publisher1.4.01 of 1See more

kubebrowser avisto 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
stdlib@go1.24.1
1.23.10

Open the chart page →

678
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.23.10

Open the chart page →

1,280
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
stdlib@go1.13.10
1.23.10

Open the chart page →

4,823
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
stdlib@go1.17.8
1.23.10
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
stdlib@go1.17.5
1.23.10
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
stdlib@go1.17.8
1.23.10

Open the chart page →

7,824
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
stdlib@go1.17.10
1.23.10

Open the chart page →

2,610
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
stdlib@go1.17.12
1.23.10

Open the chart page →

1,596
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
stdlib@go1.20.8
1.23.10

Open the chart page →

2,909
aramid-indexerbiatec-repoVerified publisher3.9.03 of 5See more

aramid-indexer biatec-repo 3.9.0

3 of the 5 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
stdlib@go1.23.9
1.23.10
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
stdlib@go1.23.9
1.23.10
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
stdlib@go1.23.3
1.23.10

Open the chart page →

13,723
self-hostbitwarden2.4.21 of 11See more

self-host bitwarden 2.4.2

1 of the 11 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
stdlib@go1.23.1
1.23.10

Open the chart page →

3,566
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.23.10

Open the chart page →

2,871
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
stdlib@go1.21.8
1.23.10

Open the chart page →

1,630
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
stdlib@go1.13.10
1.23.10

Open the chart page →

7,843
btrfs-nfs-csibtrfs-nfs-csi0.4.01 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

1 of the 7 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.23.10

Open the chart page →

3,249
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
stdlib@go1.21.4
1.23.10

Open the chart page →

2,050
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
stdlib@go1.14.7
1.23.10

Open the chart page →

2,672
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
stdlib@go1.24.2
1.23.10

Open the chart page →

1,660
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
stdlib@go1.24.2
1.23.10

Open the chart page →

1,660
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
stdlib@go1.22.2
1.23.10

Open the chart page →

913
capsulecapsuleOfficialVerified publisher0.14.61 of 2See more

capsule capsule 0.14.6

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.23.10

Open the chart page →

1,239
capsule-proxycapsule-proxyOfficialVerified publisher0.14.11 of 2See more

capsule-proxy capsule-proxy 0.14.1

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.23.10

Open the chart page →

1,254
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
stdlib@go1.16.2
1.23.10

Open the chart page →

3,513
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
stdlib@go1.23.0
1.23.10

Open the chart page →

1,818
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
stdlib@go1.22.4
1.23.10
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
stdlib@go1.21.12
1.23.10
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
stdlib@go1.21.12
1.23.10
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
stdlib@go1.21.12
1.23.10
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
stdlib@go1.21.12
1.23.10
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
stdlib@go1.21.12
1.23.10
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
stdlib@go1.21.12
1.23.10

Open the chart page →

12,813
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
stdlib@go1.22.0
1.23.10

Open the chart page →

1,039
cert-vaultcert-vaultOfficialVerified publisher2.12.03 of 7See more

cert-vault cert-vault 2.12.0

3 of the 7 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
stdlib@go1.23.7
1.23.10
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.23.10
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.23.10

Open the chart page →

15,547
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.23.10

Open the chart page →

10,844
challengerchronicleVerified publisher0.1.11 of 1See more

challenger chronicle 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.23.10

Open the chart page →

978
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
stdlib@go1.22.1
1.23.10

Open the chart page →

643
clairclair0.0.31 of 1See more

clair clair 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.7.28d38ffa8fad7
stdlib@go1.20.9
1.23.10

Open the chart page →

3,286
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
stdlib@go1.20.1
1.23.10
cloudbees/sidecar-injector:2.3.38f102ef0383a
stdlib@go1.20.1
1.23.10

Open the chart page →

3,270
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.23.10
prom/prometheus:v2.21.0d43417c260e5
stdlib@go1.15.2
1.23.10

Open the chart page →

4,267
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
stdlib@go1.17.6
1.23.10
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
stdlib@go1.18.6
1.23.10
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
stdlib@go1.17.6
1.23.10

Open the chart page →

7,601
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.23.10

Open the chart page →

2,715
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-4673.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.23.10

Open the chart page →

1,726

Container images carrying it

3,453 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.23.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.23.10
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.23.10
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.