StackRadar

CVE-2025-5025

Medium

Advisory

Published 28 May 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
211
of 17,781 indexed, latest versions
Container images
208
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 211 of 17,781 indexed charts deploy, on 208 images.

Affected packageAffected versionsFixed inImages
curlapk8.5.0-r0, 8.7.1-r0, 8.8.0-r0, 8.9.0-r0+9 more8.14.0-r0208
OSV records
ALPINE-CVE-2025-5025

Charts affected

211 by stars
ChartLatestAffected imagesRadar Score
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.14.0-r0

Open the chart page →

2,477
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
curl@8.12.1-r0
8.14.0-r0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
curl@8.12.1-r1
8.14.0-r0

Open the chart page →

4,768
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

4,303
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
curl@8.12.1-r1
8.14.0-r0

Open the chart page →

2,076
vote-appvote-appVerified publisher1.0.72 of 6See more

vote-app vote-app 1.0.7

2 of the 6 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
curl@8.7.1-r0
8.14.0-r0
thecloudspark/app-vote:1.0c7da7417a86a
curl@8.7.1-r0
8.14.0-r0

Open the chart page →

3,031
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

2,634
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
curl@8.9.1-r1
8.14.0-r0

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
curl@8.11.1-r0
8.14.0-r0

Open the chart page →

1,286
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
curl@8.10.1-r0
8.14.0-r0

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
curl@8.11.1-r0
8.14.0-r0

Open the chart page →

9,381

Container images carrying it

208 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
nginxinc/nginx-unprivileged8f14986c54fa
curl@8.5.0-r0
8.14.0-r0
1
nodered/node-red:3.0.2-18e2632a7a35dd
curl@8.5.0-r0
8.14.0-r0
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
curl@8.10.1-r0
8.14.0-r0
1
opea/chatqna-conversation-ui:v0.9bdb9ec215872
curl@8.9.0-r0
8.14.0-r0
1
opencsghq/csgship-portal:v1.2.1865814dc87a1
curl@8.12.1-r1
8.14.0-r0
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
curl@8.5.0-r0
8.14.0-r0
1
openruntimes/executor:0.11.42228f186dcbb
curl@8.9.1-r0
8.14.0-r0
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
curl@8.12.1-r1
8.14.0-r0
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
curl@8.12.1-r1
8.14.0-r0
1
owncloud/ocis:7.1.388e7c854517d
curl@8.12.1-r0
8.14.0-r0
1
phpipam/phpipam-cron:v1.7.354468713454e
curl@8.11.0-r2
8.14.0-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
curl@8.11.0-r2
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
curl@8.5.0-r0
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
curl@8.5.0-r0
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
curl@8.5.0-r0
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
curl@8.5.0-r0
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
curl@8.9.1-r1
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.31.7-nginx-7e3e189d9d519
curl@8.12.1-r0
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.30.11-nginx-7f9297eea817d
curl@8.12.1-r0
8.14.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
curl@8.9.1-r1
8.14.0-r0
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
curl@8.10.1-r0
8.14.0-r0
1
psono/psono-server:5.0.03b974b43ea03
curl@8.10.1-r0
8.14.0-r0
1
qbittorrentofficial/qbittorrent-nox:4.6.3-12b86d9c356ae
curl@8.5.0-r0
8.14.0-r0
1
saidsef/scapy-containerised:v2025.02f17f7c435891
curl@8.12.1-r0
8.14.0-r0
1
sealio/hermitcrab:v0.1.4a326a2f03660
curl@8.5.0-r0
8.14.0-r0
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
curl@8.5.0-r0
8.14.0-r0
1
soulteary/cronicle:0.9.80ac2512fa6e39
curl@8.12.1-r1
8.14.0-r0
1
stain/jena-fuseki:latestb1d0c96f19ad
curl@8.9.0-r0
8.14.0-r0
1
supermq/vernemq:latest944a0be3563e
curl@8.5.0-r0
8.14.0-r0
1
svcosti/cidrapp:latest8428d87bc5d0
curl@8.12.1-r1
8.14.0-r0
1
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
curl@8.5.0-r0
8.14.0-r0
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
curl@8.5.0-r0
8.14.0-r0
1
temporalio/admin-tools:1.26.237e2e33dbd7b
curl@8.9.1-r2
8.14.0-r0
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
curl@8.5.0-r0
8.14.0-r0
1
temporalio/auto-setup:1.27.2b44cbfeb43db
curl@8.12.1-r0
8.14.0-r0
1
temporalio/server:1.26.21e2626efcbc1
curl@8.9.1-r2
8.14.0-r0
1
temporalio/server:1.25.08a5798191dea
curl@8.5.0-r0
8.14.0-r0
1
temporalio/ui:2.30.25c2a3645d09c
curl@8.5.0-r0
8.14.0-r0
1
temporalio/ui:2.33.05c586a3c8ec5
curl@8.5.0-r0
8.14.0-r0
1
temporalio/ui:2.39.0b768f87f18b5
curl@8.12.1-r0
8.14.0-r0
1
thecloudspark/app-result:1.09a5302cb8312
curl@8.7.1-r0
8.14.0-r0
1
thecloudspark/app-vote:1.0c7da7417a86a
curl@8.7.1-r0
8.14.0-r0
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
curl@8.5.0-r0
8.14.0-r0
1
udhos/lambdaping:1.0.46bd2cf2ac732
curl@8.11.1-r0
8.14.0-r0
1
udhos/miniapi:1.3.28a7042db82ce
curl@8.10.1-r0
8.14.0-r0
1
udhos/mongoping:1.3.103b08b63f524
curl@8.12.1-r1
8.14.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.