StackRadar

CVE-2025-4947

Medium

Advisory

Published 28 May 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
164
of 17,781 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 164 of 17,781 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
curlapk8.8.0-r0, 8.9.0-r0, 8.9.1-r0, 8.9.1-r1+7 more8.14.0-r0160
OSV records
ALPINE-CVE-2025-4947

Charts affected

164 by stars
ChartLatestAffected imagesRadar Score
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
curl@8.12.1-r0
8.14.0-r0

Open the chart page →

7,901
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
carlosmz87/test_helm_frontend:latest79f4b528f42a
curl@8.11.0-r2
8.14.0-r0

Open the chart page →

11,648
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:1.002d5674ca863
curl@8.9.1-r1
8.14.0-r0

Open the chart page →

39,090
chatqna-uitest-opea0.9.01 of 1See more

chatqna-ui test-opea 0.9.0

1 of the 1 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:v0.9bdb9ec215872
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

921
uitest-opea1.0.01 of 1See more

ui test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:1.002d5674ca863
curl@8.9.1-r1
8.14.0-r0

Open the chart page →

755
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
curl@8.12.1-r0
8.14.0-r0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
curl@8.12.1-r1
8.14.0-r0

Open the chart page →

4,768
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

4,303
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
curl@8.12.1-r1
8.14.0-r0

Open the chart page →

2,076
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

2,634
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
curl@8.9.1-r1
8.14.0-r0

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
curl@8.11.1-r0
8.14.0-r0

Open the chart page →

1,286
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
curl@8.10.1-r0
8.14.0-r0

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-4947.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
curl@8.11.1-r0
8.14.0-r0

Open the chart page →

9,381

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
curl@8.11.0-r2
8.14.0-r0
6
grafana/grafana:11.3.0a0f881232a6f
curl@8.10.1-r0
8.14.0-r0
3
alpine/git:2.47.2062a01ad7a0e
curl@8.12.1-r1
8.14.0-r0
2
excalidraw/excalidraw:latestf7ee194addd6
curl@8.12.1-r1
8.14.0-r0
2
grafana/grafana:11.1.4886b56d5534e
curl@8.9.0-r0
8.14.0-r0
2
grafana/grafana:11.4.0d8ea37798ccc
curl@8.11.0-r2
8.14.0-r0
2
hazelcast/hazelcast:5.5.05dd5d31c7a06
curl@8.9.0-r0
8.14.0-r0
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
curl@8.9.1-r0
8.14.0-r0
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
curl@8.9.1-r1
8.14.0-r0
2
linuxserver/ubooquity:2.1.2-ls369932d6759112
curl@8.9.0-r0
8.14.0-r0
2
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
curl@8.12.1-r1
8.14.0-r0
2
opea/chatqna-conversation-ui:1.002d5674ca863
curl@8.9.1-r1
8.14.0-r0
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
curl@8.12.1-r0
8.14.0-r0
2
uselagoon/docker-host:v3.6.12c89ed939b8b
curl@8.12.1-r1
8.14.0-r0
2
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
curl@8.12.1-r0
8.14.0-r0
2
ghcr.io/smarter-project/home-orchestrator:maind44135b02d77
curl@8.12.1-r0
8.14.0-r0
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
curl@8.12.1-r1
8.14.0-r0
2
alpine/curl:8.12.08943e8c7e8e4
curl@8.12.0-r0
8.14.0-r0
1
alpine/helm105741fa6621
curl@8.9.0-r0
8.14.0-r0
1
alpine/k8s:1.32.47e1e7d5b7a96
curl@8.12.1-r1
8.14.0-r0
1
alpine/k8s:1.31.49c4976d47656
curl@8.11.1-r0
8.14.0-r0
1
alpine/k8s:1.30.2cd560fce90f7
curl@8.8.0-r0
8.14.0-r0
1
alpine/k8s:1.28.13e5c0b053fed7
curl@8.9.0-r0
8.14.0-r0
1
alpine/k8s:1.32.3eec354133193
curl@8.12.1-r0
8.14.0-r0
1
appwrite/console:7.5.7aaa11ceab999
curl@8.12.1-r0
8.14.0-r0
1
buddyspencer/gickup:0.10.386b656f19b0c1
curl@8.12.1-r0
8.14.0-r0
1
carlosmz87/test_helm_frontend:latest79f4b528f42a
curl@8.11.0-r2
8.14.0-r0
1
casbin/casdoor:v1.753.0770ad9ec3190
curl@8.11.0-r2
8.14.0-r0
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
curl@8.12.1-r0
8.14.0-r0
1
clsen2024/daejeon_2-3:latest1156cd87c8fb
curl@8.9.0-r0
8.14.0-r0
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
curl@8.9.0-r0
8.14.0-r0
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
curl@8.9.0-r0
8.14.0-r0
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
curl@8.9.0-r0
8.14.0-r0
1
cometbft/cometbft:v0.38.1722c2ac018f40
curl@8.11.1-r0
8.14.0-r0
1
cryptexlabs/authf:0.12.11189c07411d7c
curl@8.9.1-r1
8.14.0-r0
1
dannyben/madness:latestebdf50556c02
curl@8.9.0-r0
8.14.0-r0
1
davidy/giphy-app:1.0.2-arm41b2355cc23a
curl@8.11.0-r2
8.14.0-r0
1
djjudas21/bearhugmugs:0.1.14fa898a52d97
curl@8.11.0-r2
8.14.0-r0
1
dwdraju/alpine-curl-jq:latest83bd9be2b14b
curl@8.9.1-r1
8.14.0-r0
1
extrim/perlite:1.5.99cb7eb5598b6
curl@8.12.1-r1
8.14.0-r0
1
getmeili/meilisearch:v1.11.0b9be3d2d4251
curl@8.10.1-r0
8.14.0-r0
1
getmeili/meilisearch:v1.13.3bed3fb650e62
curl@8.12.1-r0
8.14.0-r0
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
curl@8.9.1-r2
8.14.0-r0
1
gitea/act_runner:0.2.11c57233403eff
curl@8.9.1-r2
8.14.0-r0
1
gitea/gitea:1.22.376f516a1a8c2
curl@8.10.1-r0
8.14.0-r0
1
grafana/grafana:11.2.2-security-01464eac539793
curl@8.10.1-r0
8.14.0-r0
1
grafana/grafana:11.5.15781759b3d27
curl@8.11.1-r0
8.14.0-r0
1
grafana/grafana:11.6.062d2b9d20a19
curl@8.12.1-r1
8.14.0-r0
1
grafana/grafana:11.5.28b37a2f028f1
curl@8.12.1-r0
8.14.0-r0
1
grafana/grafana:10.4.19a9043254ba16
curl@8.12.1-r1
8.14.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.