StackRadar

CVE-2025-4947

Medium

Advisory

Published 28 May 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
164
of 17,781 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 164 of 17,781 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
curlapk8.8.0-r0, 8.9.0-r0, 8.9.1-r0, 8.9.1-r1+7 more8.14.0-r0160
OSV records
ALPINE-CVE-2025-4947

Charts affected

164 by stars
ChartLatestAffected imagesRadar Score
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
curl@8.12.1-r0
8.14.0-r0

Open the chart page →

7,901
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
carlosmz87/test_helm_frontend:latest79f4b528f42a
curl@8.11.0-r2
8.14.0-r0

Open the chart page →

11,648
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:1.002d5674ca863
curl@8.9.1-r1
8.14.0-r0

Open the chart page →

39,090
chatqna-uitest-opea0.9.01 of 1See more

chatqna-ui test-opea 0.9.0

1 of the 1 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:v0.9bdb9ec215872
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

921
uitest-opea1.0.01 of 1See more

ui test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:1.002d5674ca863
curl@8.9.1-r1
8.14.0-r0

Open the chart page →

755
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
curl@8.12.1-r0
8.14.0-r0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
curl@8.12.1-r1
8.14.0-r0

Open the chart page →

4,768
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

4,303
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
curl@8.12.1-r1
8.14.0-r0

Open the chart page →

2,076
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

2,634
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
curl@8.9.1-r1
8.14.0-r0

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
curl@8.11.1-r0
8.14.0-r0

Open the chart page →

1,286
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
curl@8.10.1-r0
8.14.0-r0

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
curl@8.11.1-r0
8.14.0-r0

Open the chart page →

9,381

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:11.1.3b23b588cf7cb
curl@8.9.0-r0
8.14.0-r0
1
grafana/grafana:12.0.2b5b59bfc7561
curl@8.12.1-r1
8.14.0-r0
1
grafana/grafana:11.3.1fa801ab6e1ae
curl@8.11.0-r2
8.14.0-r0
1
grafana/oncall:v1.16.5499851658393
curl@8.12.1-r1
8.14.0-r0
1
gridgain/community:8.9.11d32d182a0e6a
curl@8.9.1-r1
8.14.0-r0
1
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
curl@8.10.1-r0
8.14.0-r0
1
hashicorp/terraform:1.9.7b77efab1a448
curl@8.10.1-r0
8.14.0-r0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
curl@8.9.1-r1
8.14.0-r0
1
indevlab/ejabberd:24.12-k8s8bc689d093a7
curl@8.12.1-r0
8.14.0-r0
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
curl@8.12.1-r1
8.14.0-r0
1
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
curl@8.12.1-r1
8.14.0-r0
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
curl@8.12.1-r0
8.14.0-r0
1
layer5/meshery:stable-latest78a8be21bef3
curl@8.12.1-r1
8.14.0-r0
1
leantime/leantime:3.3.3ad4bfb0699d3
curl@8.11.0-r2
8.14.0-r0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
curl@8.10.1-r0
8.14.0-r0
1
library/docker:27-cli851f91d24121
curl@8.12.1-r0
8.14.0-r0
1
library/docker:27-dindaa3df78ecf32
curl@8.12.1-r0
8.14.0-r0
1
library/docker:26.1-dinddd43b430341a
curl@8.8.0-r0
8.14.0-r0
1
library/nginx:1.27-alpine65645c7bb6a0
curl@8.12.1-r1
8.14.0-r0
1
librenms/librenms:24.11.00920bc9117a8
curl@8.9.1-r1
8.14.0-r0
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
curl@8.12.1-r1
8.14.0-r0
1
linuxserver/heimdall:2.6.371597f4461e4
curl@8.12.1-r0
8.14.0-r0
1
linuxserver/openssh-server:9.7_p1-r4-ls17153ea39d2485c
curl@8.9.1-r2
8.14.0-r0
1
linuxserver/smokeping:2.8.2b7f906899cd3
curl@8.12.1-r0
8.14.0-r0
1
loeken/radarr:5.27.0-nightlya24409d3846d
curl@8.12.1-r1
8.14.0-r0
1
mathieuruellan/piwigo:latest04572c8a1b04
curl@8.11.0-r2
8.14.0-r0
1
mathnao/certs:2.1.3b900e6b64684
curl@8.12.1-r1
8.14.0-r0
1
mavrick1/kubestellar-b:latest45ca0429a1d4
curl@8.12.1-r1
8.14.0-r0
1
mavrick1/kubestellar-f:latest56bd8eaa53a4
curl@8.12.1-r1
8.14.0-r0
1
metabase/metabase:v0.53.4.17807bc5cad17
curl@8.12.1-r0
8.14.0-r0
1
nacos/nacos-server:v3.0.130a39cb0c54d
curl@8.12.1-r1
8.14.0-r0
1
nginxinc/nginx-unprivileged:1.27.4-alpine62a904036bfc
curl@8.12.1-r1
8.14.0-r0
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
curl@8.10.1-r0
8.14.0-r0
1
opea/chatqna-conversation-ui:v0.9bdb9ec215872
curl@8.9.0-r0
8.14.0-r0
1
opencsghq/csgship-portal:v1.2.1865814dc87a1
curl@8.12.1-r1
8.14.0-r0
1
openruntimes/executor:0.11.42228f186dcbb
curl@8.9.1-r0
8.14.0-r0
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
curl@8.12.1-r1
8.14.0-r0
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
curl@8.12.1-r1
8.14.0-r0
1
owncloud/ocis:7.1.388e7c854517d
curl@8.12.1-r0
8.14.0-r0
1
phpipam/phpipam-cron:v1.7.354468713454e
curl@8.11.0-r2
8.14.0-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
curl@8.11.0-r2
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.31.7-nginx-7e3e189d9d519
curl@8.12.1-r0
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.30.11-nginx-7f9297eea817d
curl@8.12.1-r0
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
curl@8.9.1-r1
8.14.0-r0
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
curl@8.10.1-r0
8.14.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.