StackRadar

CVE-2025-47913

High

Advisory

Published 13 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,026
of 17,790 indexed, latest versions
Container images
2,316
deployed by those charts
Fix available
8 of 8
affected packages

Red Hat Security Advisory: container-tools:rhel8 security update

Carried by container images the latest versions of 2,026 of 17,790 indexed charts deploy, on 2,316 images.

Affected packageAffected versionsFixed inImages
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-82.module+el8.10.0+23863+d7fda2d71
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+23863+d7fda2d71
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+23863+d7fda2d71
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+23863+d7fda2d71
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc4:1.2.9-2.module+el8.10.0+23863+d7fda2d71
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.5-5.module+el8.10.0+23863+d7fda2d71
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+23863+d7fda2d71
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+144 more0.43.02,316
OSV records
RHSA-2026:0753GO-2025-4116
Also known as
GHSA-56w8-48fp-6mgv, RHSA-2026:16701

Charts affected

2,026 by stars
ChartLatestAffected imagesRadar Score
kubeviouskubevious1.2.21 of 7See more

kubevious kubevious 1.2.2

1 of the 7 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.43.0

Open the chart page →

14,212
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.03 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

3 of the 6 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/crypto@v0.13.0
0.43.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/crypto@v0.13.0
0.43.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/crypto@v0.13.0
0.43.0

Open the chart page →

11,675
prometheus-pingmesh-exporterkubservice-chartsVerified publisher1.1.11 of 1See more

prometheus-pingmesh-exporter kubservice-charts 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/crypto@v0.28.0
0.43.0

Open the chart page →

855
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/crypto@v0.16.0
0.43.0
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/crypto@v0.14.0
0.43.0

Open the chart page →

3,310
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/crypto@v0.12.0
0.43.0

Open the chart page →

3,686
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.43.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/crypto@v0.1.0
0.43.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/crypto@v0.1.0
0.43.0

Open the chart page →

5,595
kubecostmesosphere-stable0.37.56 of 9See more

kubecost mesosphere-stable 0.37.5

6 of the 9 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
grafana/grafana:9.4.71a359d92f40e
golang.org/x/crypto@v0.4.0
0.43.0
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/crypto@v0.15.0
0.43.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
golang.org/x/crypto@v0.14.0
0.43.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/crypto@v0.18.0
0.43.0
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/crypto@v0.26.0
0.43.0
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/crypto@v0.24.0
0.43.0

Open the chart page →

17,799
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.43.0

Open the chart page →

2,750
helm-ai-kernelmindburn-labsOfficialVerified publisher0.8.51 of 2See more

helm-ai-kernel mindburn-labs 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/crypto@v0.25.0
0.43.0

Open the chart page →

2,175
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.43.0

Open the chart page →

3,803
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/crypto@v0.42.0
0.43.0

Open the chart page →

4,077
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.43.0

Open the chart page →

5,066
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
alpine/git:2.47.2062a01ad7a0e
golang.org/x/crypto@v0.38.0
0.43.0

Open the chart page →

5,244
oesopsmxVerified publisher4.0.325 of 25See more

oes opsmx 4.0.32

5 of the 25 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/crypto@v0.0.0-20201012173705-84dcc777aaee
0.43.0
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.43.0
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.43.0
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.43.0
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.43.0

Open the chart page →

108,315
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/crypto@v0.0.0-20220518034528-6f7dac969898
0.43.0
ipfs/ipfs-cluster:1.0.21511f6d57994
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.43.0

Open the chart page →

3,769
permifypermifyVerified publisher0.5.01 of 1See more

permify permify 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
golang.org/x/crypto@v0.24.0
0.43.0

Open the chart page →

1,003
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/crypto@v0.39.0
0.43.0

Open the chart page →

2,877
plecopleco0.24.01 of 1See more

pleco pleco 0.24.0

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/crypto@v0.37.0
0.43.0

Open the chart page →

1,353
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/crypto@v0.8.0
0.43.0

Open the chart page →

1,948
prometheus-systemd-exporterprometheus-communityVerified publisher0.5.21 of 1See more

prometheus-systemd-exporter prometheus-community 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/systemd-exporter:v0.7.078c03f875dfb
golang.org/x/crypto@v0.31.0
0.43.0

Open the chart page →

725
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.43.0
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.43.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.43.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.43.0

Open the chart page →

12,132
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/crypto@v0.35.0
0.43.0

Open the chart page →

5,465
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.43.0

Open the chart page →

2,731
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
golang.org/x/crypto@v0.40.0
0.43.0

Open the chart page →

13,647
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/crypto@v0.29.0
0.43.0

Open the chart page →

1,218
bentoself-hosters-by-nightVerified publisher0.9.11 of 1See more

bento self-hosters-by-night 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
golang.org/x/crypto@v0.36.0
0.43.0

Open the chart page →

1,053
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/crypto@v0.0.0-20221010152910-d6f0a8c073c2
0.43.0

Open the chart page →

1,670
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/crypto@v0.0.0-20200323165209-0ec3e9974c59
0.43.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.43.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.43.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.43.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.43.0

Open the chart page →

12,537
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
golang.org/x/crypto@v0.40.0
0.43.0

Open the chart page →

1,070
sn-platformstreamnative1.11.445 of 9See more

sn-platform streamnative 1.11.44

5 of the 9 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/crypto@v0.4.0
0.43.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/crypto@v0.0.0-20220208050332-20e1d8d225ab
0.43.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/crypto@v0.1.0
0.43.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.43.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/crypto@v0.7.0
0.43.0

Open the chart page →

15,564
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/crypto@v0.41.0
0.43.0

Open the chart page →

1,448
feedbacksystemthm-mni-iiVerified publisher0.47.14 of 10See more

feedbacksystem thm-mni-ii 0.47.1

4 of the 10 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/crypto@v0.17.0
0.43.0
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/crypto@v0.12.0
0.43.0
library/docker:20.10.21-dind3153fa63f546
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.43.0
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/crypto@v0.1.0
0.43.0

Open the chart page →

28,634
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/crypto@v0.37.0
0.43.0

Open the chart page →

1,503
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/crypto@v0.0.0-20200317142112-1b76d66859c6
0.43.0

Open the chart page →

4,145
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/crypto@v0.0.0-20200214034016-1d94cc7ab1c6
0.43.0
library/traefik:v2.57d5a6ae66572
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.43.0
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.43.0

Open the chart page →

9,271
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.43.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/crypto@v0.14.0
0.43.0

Open the chart page →

10,373
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/crypto@v0.40.0
0.43.0

Open the chart page →

1,627
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/crypto@v0.11.0
0.43.0

Open the chart page →

1,350
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.43.0

Open the chart page →

2,245
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
golang.org/x/crypto@v0.16.0
0.43.0

Open the chart page →

3,478
argo-cdwenerme10.9.11 of 3See more

argo-cd wenerme 10.9.1

1 of the 3 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/crypto@v0.36.0
0.43.0

Open the chart page →

3,003
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/crypto@v0.0.0-20210421170649-83a5a9bb288b
0.43.0

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.43.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.43.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.43.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.43.0

Open the chart page →

10,047
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.43.0

Open the chart page →

4,713
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/crypto@v0.0.0-20220507011949-2cf3adece122
0.43.0

Open the chart page →

4,049
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/crypto@v0.24.0
0.43.0

Open the chart page →

829
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
golang.org/x/crypto@v0.37.0
0.43.0

Open the chart page →

1,851
agentareaagentareaVerified publisher0.0.183 of 16See more

agentarea agentarea 0.0.18

3 of the 16 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/crypto@v0.26.0
0.43.0
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/crypto@v0.37.0
0.43.0
temporalio/ui:2.39.0b768f87f18b5
golang.org/x/crypto@v0.32.0
0.43.0

Open the chart page →

15,049
clearml-servingallegroaiVerified publisher1.6.23 of 9See more

clearml-serving allegroai 1.6.2

3 of the 9 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/crypto@v0.4.0
0.43.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/crypto@v0.1.0
0.43.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/crypto@v0.1.0
0.43.0

Open the chart page →

17,897
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-47913.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/crypto@v0.0.0-20220307211146-efcb8507fb70
0.43.0

Open the chart page →

3,119

Container images carrying it

2,316 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.43.0
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.43.0
1
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
golang.org/x/crypto@v0.40.0
0.43.0
1
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/crypto@v0.9.0
0.43.0
1
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/crypto@v0.9.0
0.43.0
1
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
golang.org/x/crypto@v0.38.0
0.43.0
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/crypto@v0.14.0
0.43.0
1
ghcr.io/daocloud/crproxy/crproxy:v0.8.0ee1eb3c9c9a1
golang.org/x/crypto@v0.24.0
0.43.0
1
ghcr.io/davidkarlsen/flyway-operator:0.2.1366f60b461c0d
golang.org/x/crypto@v0.36.0
0.43.0
1
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.43.0
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
golang.org/x/crypto@v0.23.0
0.43.0
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.43.0
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/crypto@v0.37.0
0.43.0
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.43.0
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
golang.org/x/crypto@v0.40.0
0.43.0
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/crypto@v0.31.0
0.43.0
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.43.0
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
golang.org/x/crypto@v0.36.0
0.43.0
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.43.0
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/crypto@v0.6.0
0.43.0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/crypto@v0.0.0-20220314234724-5d542ad81a58
0.43.0
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.43.0
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.43.0
1
ghcr.io/doodlescheduling/saml-exporter:v0.5.03d5a99841bc2
golang.org/x/crypto@v0.33.0
0.43.0
1
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/crypto@v0.23.0
0.43.0
1
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
golang.org/x/crypto@v0.33.0
0.43.0
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.43.0
1
ghcr.io/edgelesssys/continuum/continuum-proxy24c76f294a80
golang.org/x/crypto@v0.31.0
0.43.0
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.43.0
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/crypto@v0.16.0
0.43.0
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
0.43.0
1
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
golang.org/x/crypto@v0.35.0
0.43.0
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/crypto@v0.17.0
0.43.0
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.43.0
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/crypto@v0.6.0
0.43.0
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
golang.org/x/crypto@v0.18.0
0.43.0
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/crypto@v0.0.0-20220208050332-20e1d8d225ab
0.43.0
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.43.0
1
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
golang.org/x/crypto@v0.7.0
0.43.0
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/crypto@v0.41.0
0.43.0
1
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/crypto@v0.42.0
0.43.0
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/crypto@v0.26.0
0.43.0
1
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/crypto@v0.33.0
0.43.0
1
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/crypto@v0.32.0
0.43.0
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/crypto@v0.32.0
0.43.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.43.0
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/crypto@v0.4.0
0.43.0
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/crypto@v0.40.0
0.43.0
1
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/crypto@v0.32.0
0.43.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/crypto@v0.14.0
0.43.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.