StackRadar

CVE-2025-52099

High

Advisory

Published 22 May 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
555
of 17,787 indexed, latest versions
Container images
472
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 555 of 17,787 indexed charts deploy, on 472 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.8.2-1ubuntu2, 3.8.2-1ubuntu2.1, 3.8.2-1ubuntu2.2, 3.11.0-1ubuntu1+22 more3.8.2-1ubuntu2.2+esm5, 3.11.0-1ubuntu1.5+esm3, 3.22.0-1ubuntu0.7+esm2, 3.31.1-4ubuntu0.7+2 more472
OSV records
UBUNTU-CVE-2025-52099
Also known as
USN-7528-1, USN-7679-1

Charts affected

555 by stars
ChartLatestAffected imagesRadar Score
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-52099.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7

Open the chart page →

15,230
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-52099.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4

Open the chart page →

9,248
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-52099.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
sqlite3@3.31.1-4ubuntu0.6
3.31.1-4ubuntu0.7

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-52099.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4

Open the chart page →

14,100
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-52099.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
sqlite3@3.22.0-1ubuntu0.4
3.22.0-1ubuntu0.7+esm2
yandex/clickhouse-server:21.3.204eccfffb01d7
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7

Open the chart page →

9,207

Container images carrying it

472 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
psorab/elibrary:latest53b68896c4ce
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
sqlite3@3.31.1-4ubuntu0.4
3.31.1-4ubuntu0.7
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
sqlite3@3.22.0-1ubuntu0.4
3.22.0-1ubuntu0.7+esm2
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
sqlite3@3.45.1-1ubuntu2.1
3.45.1-1ubuntu2.3
1
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
sqlite3@3.22.0-1ubuntu0.4
3.22.0-1ubuntu0.7+esm2
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
sqlite3@3.11.0-1ubuntu1
3.11.0-1ubuntu1.5+esm3
1
razorbladex401/dayz:latest6a4d79248e7d
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1
resouer/redis-slave:v2e2f198b49ba7
sqlite3@3.8.2-1ubuntu2
3.8.2-1ubuntu2.2+esm5
1
resurfaceio/resurface:3.7.84d5cda2f64109
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1
rezachalak/bzen-mongo:1.0.034f694325191
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7
1
robotshop/rs-mongodb:latest119b545823cd
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7
1
rundeck/rundeck:3.2.74d64fe56f767
sqlite3@3.11.0-1ubuntu1.4
3.11.0-1ubuntu1.5+esm3
1
rundeck/rundeck:3.0.16b13e8059ad72
sqlite3@3.11.0-1ubuntu1
3.11.0-1ubuntu1.5+esm3
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1
scrapinghub/splash:3.4.1a5f89bc84606
sqlite3@3.22.0-1ubuntu0.2
3.22.0-1ubuntu0.7+esm2
1
seafileltd/seafile-mc:9.0.106693911bcc40
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7
1
seafileltd/seafile-mc:10.0.170628f29c663
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
seafileltd/seafile-mc:9.0.97ac833196f60
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7
1
seldonio/locust-core:0.81d0da98a2d76
sqlite3@3.11.0-1ubuntu1.1
3.11.0-1ubuntu1.5+esm3
1
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
sqlite3@3.22.0-1ubuntu0.4
3.22.0-1ubuntu0.7+esm2
1
sismics/docs:v1.10f4b0ef019cf1
sqlite3@3.22.0-1
3.22.0-1ubuntu0.7+esm2
1
slagattollas/weatherservice-practica:latest68e7f56393fc
sqlite3@3.22.0-1ubuntu0.4
3.22.0-1ubuntu0.7+esm2
1
snipe/snipe-it:v6.0.1455fb7636a98c
sqlite3@3.31.1-4ubuntu0.4
3.31.1-4ubuntu0.7
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
sqlite3@3.22.0-1ubuntu0.7
3.22.0-1ubuntu0.7+esm2
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
sqlite3@3.22.0-1ubuntu0.7
3.22.0-1ubuntu0.7+esm2
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlite3@3.31.1-4ubuntu0.3
3.31.1-4ubuntu0.7
1
stackstorm/st2actionrunner:3.888235ba70cad
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2api:3.86f56d239d280
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2auth:3.833ecfda16608
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2notifier:3.8f190a6212195
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2rulesengine:3.8259503496ff9
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2scheduler:3.8b1de2055c362
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2stream:3.81c8904a3bf67
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2timersengine:3.81bf35bfaf00c
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2web:3.809989a26c8b7
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stackstorm/st2workflowengine:3.819fdfffdbba8
sqlite3@3.31.1-4ubuntu0.5
3.31.1-4ubuntu0.7
1
stashapp/stash:latest24dbd7607174
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7
1
statcan/ckan:2.93921305425b8
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
sqlite3@3.31.1-4ubuntu0.2
3.31.1-4ubuntu0.7
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.