CVE-2025-48072
CriticalAdvisory
Published 31 Jul 2025In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.005
- 41st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 5
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- None
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openexrdeb | 3.1.13-2, 3.1.13-2build1 | no fix listed | 5 |
- OSV records
- UBUNTU-CVE-2025-48072
Charts affected
5 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| penpotpenpotOfficialVerified publisher | 1.9.0 | 1 of 4See more | 4,314 |
| minecraft-proxyminecraft-server-chartsVerified publisher | 3.10.0 | 1 of 1See more | 3,074 |
| photoprismandrenarchyVerified publisher | 8.15.0 | 1 of 1See more | 8,825 |
| photoprismmmontesVerified publisher | 0.14.0 | 1 of 1See more | 11,103 |
| photoprismschoolguys-helmcharts | 0.3.8 | 1 of 1See more | 10,348 |
Container images carrying it
5 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| itzg/ | 1c59f9631f3b | openexr | no fix listed | 1 |
| penpotapp/ | 72a8061e8806 | openexr | no fix listed | 1 |
| photoprism/ | 650c6ad5a651 | openexr | no fix listed | 1 |
| photoprism/ | 958642220223 | openexr | no fix listed | 1 |
| photoprism/ | db16ee6b1ba3 | openexr | no fix listed | 1 |