StackRadar

CVE-2025-48432

Medium

Advisory

Published 5 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.0
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
64
deployed by those charts
Fix available
1 of 1
affected package

Django Improper Output Neutralization for Logs vulnerability

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 64 images.

Affected packageAffected versionsFixed inImages
djangopypi1.11.11, 1.11.24, 1.11.29, 2.2.13+44 more4.2.22, 5.1.1064
OSV records
GHSA-7xr5-9hcq-chf9
Also known as
BIT-django-2025-48432, PYSEC-2025-47

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
django@1.11.29
4.2.22

Open the chart page →

6,501
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
django@4.1.7
4.2.22

Open the chart page →

2,628
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
django@4.1.10
4.2.22

Open the chart page →

2,581
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
django@3.2.16
4.2.22

Open the chart page →

16,417
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
django@5.0.14
5.1.10

Open the chart page →

8,405
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
django@2.2.26
4.2.22

Open the chart page →

3,891
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
4.2.22
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
django@1.11.11
4.2.22

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
4.2.22

Open the chart page →

26,211
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
django@3.2.14
4.2.22

Open the chart page →

22,084
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
4.2.22

Open the chart page →

8,694
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
4.2.22

Open the chart page →

4,731
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48432.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
django@4.0.5
4.2.22

Open the chart page →

3,392

Container images carrying it

64 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
sissbruecker/linkding:1.35.00c5dddf0b37c
django@5.1.1
5.1.10
1
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
django@3.2.16
4.2.22
1
taigaio/taiga-back:6.4.29f97323cc150
django@2.2.24
4.2.22
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
django@3.2.11
4.2.22
1
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
4.2.22
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
django@4.0.10
4.2.22
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
django@5.1.4
5.1.10
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
django@5.0.4
5.1.10
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
django@5.1.1
5.1.10
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
django@4.0.6
4.2.22
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
django@4.2.7
4.2.22
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
4.2.22
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
django@4.2.18
4.2.22
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
django@4.2.21
4.2.22
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.