StackRadar

CVE-2025-5025

Medium

Advisory

Published 28 May 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
211
of 17,781 indexed, latest versions
Container images
208
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 211 of 17,781 indexed charts deploy, on 208 images.

Affected packageAffected versionsFixed inImages
curlapk8.5.0-r0, 8.7.1-r0, 8.8.0-r0, 8.9.0-r0+9 more8.14.0-r0208
OSV records
ALPINE-CVE-2025-5025

Charts affected

211 by stars
ChartLatestAffected imagesRadar Score
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.14.0-r0

Open the chart page →

2,477
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
curl@8.12.1-r0
8.14.0-r0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
curl@8.12.1-r1
8.14.0-r0

Open the chart page →

4,768
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

4,303
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
curl@8.12.1-r1
8.14.0-r0

Open the chart page →

2,076
vote-appvote-appVerified publisher1.0.72 of 6See more

vote-app vote-app 1.0.7

2 of the 6 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
curl@8.7.1-r0
8.14.0-r0
thecloudspark/app-vote:1.0c7da7417a86a
curl@8.7.1-r0
8.14.0-r0

Open the chart page →

3,031
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
curl@8.9.0-r0
8.14.0-r0

Open the chart page →

2,634
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
curl@8.9.1-r1
8.14.0-r0

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
curl@8.11.1-r0
8.14.0-r0

Open the chart page →

1,286
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
curl@8.10.1-r0
8.14.0-r0

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-5025.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
curl@8.11.1-r0
8.14.0-r0

Open the chart page →

9,381

Container images carrying it

208 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
udhos/rabbitping:1.3.0474c467bbf42
curl@8.12.1-r1
8.14.0-r0
1
udhos/secrets:1.0.6daa2b4eaac09
curl@8.12.1-r1
8.14.0-r0
1
udhos/snsping:1.2.96ae70677b6a3
curl@8.11.1-r0
8.14.0-r0
1
vcnngr/pnbackend:latesteaf44ad0ad1f
curl@8.12.1-r1
8.14.0-r0
1
venturenox/sagawise:latestc11d32f18718
curl@8.11.0-r2
8.14.0-r0
1
wmbusmeters/wmbusmeters:release-1.18.0d82715d9ae22
curl@8.11.0-r2
8.14.0-r0
1
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
curl@8.11.0-r2
8.14.0-r0
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/appscode/marketplace-ui:0.3.1d52177072013
curl@8.11.0-r2
8.14.0-r0
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
curl@8.11.1-r0
8.14.0-r0
1
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
curl@8.9.1-r1
8.14.0-r0
1
ghcr.io/colanode/web:latestbcad696f03ee
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/dani-garcia/vaultwarden:1.33.2-alpine63cce7624f65
curl@8.12.0-r0
8.14.0-r0
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/data-fair/notify:3c739b74dabb0
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/debridmediamanager/zurg-testing:v0.9.3-final5c47ef99443a
curl@8.8.0-r0
8.14.0-r0
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
curl@8.12.0-r0
8.14.0-r0
1
ghcr.io/devops-ia/kafka-cruise-control-ui:0.4.096c25035cb02
curl@8.5.0-r0
8.14.0-r0
1
ghcr.io/element-hq/hydrogen-web:v0.5.12d15d14b201a
curl@8.10.1-r0
8.14.0-r0
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/gabe565/mnemonic-ninja:latest1fd90a9e4d04
curl@8.5.0-r0
8.14.0-r0
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/huscker/townsquare-frontend:2.15.2dc6384d10cc8
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/kubiyabot/workflow-engine:v1.46.2560a16a56d4e
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/kuoss/lethe:v0.3.1c59f082ba8b2
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/lldap/lldap:2025-05-193de697c3ba57
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
curl@8.5.0-r0
8.14.0-r0
1
ghcr.io/onedr0p/qbittorrent:4.6.3a4ad890e8c4a
curl@8.5.0-r0
8.14.0-r0
1
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
curl@8.5.0-r0
8.14.0-r0
1
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
curl@8.5.0-r0
8.14.0-r0
1
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
curl@8.11.0-r2
8.14.0-r0
1
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
curl@8.11.1-r0
8.14.0-r0
1
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
curl@8.11.1-r0
8.14.0-r0
1
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
curl@8.11.1-r0
8.14.0-r0
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
curl@8.12.1-r1
8.14.0-r0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
curl@8.11.1-r0
8.14.0-r0
1
ghcr.io/thoroslives/zilean:v3.10.1bce6aca0f6ca
curl@8.12.1-r0
8.14.0-r0
1
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
curl@8.10.1-r0
8.14.0-r0
1
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
curl@8.11.1-r0
8.14.0-r0
1
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
curl@8.7.1-r0
8.14.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.