StackRadar

CVE-2025-5222

High

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
826
of 17,787 indexed, latest versions
Container images
873
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: icu security update

Carried by container images the latest versions of 826 of 17,787 indexed charts deploy, on 873 images.

Affected packageAffected versionsFixed inImages
icudeb55.1-7ubuntu0.2, 55.1-7ubuntu0.3, 55.1-7ubuntu0.4, 55.1-7ubuntu0.5+12 more67.1-7+deb11u1, 72.1-3+deb12u1826
icuapk73.2-r2, 74.1-r0, 74.2-r0, 76.1-r074.1-r1, 74.2-r1, 76.1-r144
icurpm67.1-9.el90:67.1-10.el9_63
OSV records
ALPINE-CVE-2025-5222DEBIAN-CVE-2025-5222RHSA-2025:12083UBUNTU-CVE-2025-5222DLA-4217-1
Also known as
DSA-5951-1, RHSA-2025:12332

Charts affected

826 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
icu@74.2-r0
74.2-r1

Open the chart page →

4,768
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
icu@70.1-2
no fix listed

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
icu@72.1-3
72.1-3+deb12u1

Open the chart page →

10,795
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
icu@74.2-1ubuntu3.1
no fix listed

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
icu@70.1-2
no fix listed

Open the chart page →

13,459
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

3,392
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
icu@74.2-1ubuntu3.1
no fix listed

Open the chart page →

7,628
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
icu@66.1-2ubuntu2.1
no fix listed

Open the chart page →

11,405
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

2,132
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

9,397
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
icu@66.1-2ubuntu2.1
no fix listed

Open the chart page →

9,130
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
icu@66.1-2ubuntu2.1
no fix listed

Open the chart page →

9,130
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
icu@72.1-3
72.1-3+deb12u1

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
icu@66.1-2ubuntu2
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
icu@66.1-2ubuntu2
no fix listed

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

7,552
apisixwenerme2.17.01 of 3See more

apisix wenerme 2.17.0

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
apache/apisix:3.18.0-ubuntu9ee5df1611f9
icu@74.2-1ubuntu3.1
no fix listed

Open the chart page →

3,045
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
icu@66.1-2ubuntu2.1
no fix listed

Open the chart page →

15,230
reflectorwenerme10.0.651 of 1See more

reflector wenerme 10.0.65

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
emberstack/kubernetes-reflector:10.0.6551dbd5880929
icu@74.2-1ubuntu3.1
no fix listed

Open the chart page →

656
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
icu@70.1-2
no fix listed

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
icu@72.1-3
72.1-3+deb12u1

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
icu@72.1-3
72.1-3+deb12u1

Open the chart page →

7,673
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

1,838
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
icu@70.1-2
no fix listed

Open the chart page →

7,849

Container images carrying it

873 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
a10networks/acos-prometheus-exporter:latest8dc58d434d71
icu@60.2-3ubuntu3.1
no fix listed
1
activepieces/activepieces:0.23.0c26188b44e62
icu@67.1-7
67.1-7+deb11u1
1
adolfintel/speedtest:latest1f828fe83374
icu@67.1-7
67.1-7+deb11u1
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
icu@66.1-2ubuntu2
no fix listed
1
aidasi/swpapi:v1-1-net6-k8s-test-beta838b5e2080bc
icu@67.1-7
67.1-7+deb11u1
1
aidasi/swpbom:v1-1-net6-k8s-test-betafee6857b9bc9
icu@67.1-7
67.1-7+deb11u1
1
aidasi/swpgateway:v1-1-net6-k8s-test-beta5ce8dbff7fdc
icu@67.1-7
67.1-7+deb11u1
1
aidasi/swpidentity:v1-1-net6-k8s-test-betad433285c7d5a
icu@67.1-7
67.1-7+deb11u1
1
aidasi/swpspa:v1-1-net6-k8s-test-betadee4ec566312
icu@67.1-7
67.1-7+deb11u1
1
airbyte/pod-sweeper:1.5.198d2c39d512e
icu@72.1-3
72.1-3+deb12u1
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
icu@66.1-2ubuntu2
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
icu@72.1-3
72.1-3+deb12u1
1
akeyless/base:latest759e4289fae8
icu@74.2-1ubuntu3.1
no fix listed
1
akeyless/gateway:5.3.13d2e7dce5eb9
icu@74.2-1ubuntu3.1
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
icu@72.1-3
72.1-3+deb12u1
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
icu@60.2-3ubuntu3.2
no fix listed
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
icu@67.1-7
67.1-7+deb11u1
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
icu@67.1-7
67.1-7+deb11u1
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
icu@70.1-2
no fix listed
1
anguda/ant-media:2.5c435285fc241
icu@66.1-2ubuntu2.1
no fix listed
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
icu@72.1-3
72.1-3+deb12u1
1
apache/airflow:2.8.4-python3.964e58748b6b9
icu@72.1-3
72.1-3+deb12u1
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
icu@72.1-3
72.1-3+deb12u1
1
apache/airflow:2.8.1e5560ad0b86e
icu@72.1-3
72.1-3+deb12u1
1
apache/hertzbeat:1.8.075d48a62748f
icu@74.2-1ubuntu3.1
no fix listed
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
icu@74.2-1ubuntu3.1
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
icu@70.1-2
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
icu@70.1-2
no fix listed
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
icu@66.1-2ubuntu2.1
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
icu@70.1-2
no fix listed
1
apachepulsar/pulsar:2.9.0d056c89b7131
icu@66.1-2ubuntu2
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
icu@66.1-2ubuntu2.1
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
icu@70.1-2
no fix listed
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
icu@67.1-7
67.1-7+deb11u1
1
apache/tika:latest-full80072bb73dd3
icu@78.2-2ubuntu1
no fix listed
1
archish27/python-fastapi-postgres:latest6610071a2101
icu@67.1-7
67.1-7+deb11u1
1
aristidetm/basic-notebook:3.6.5469dbc951224
icu@72.1-3
72.1-3+deb12u1
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
icu@67.1-7
67.1-7+deb11u1
1
arunvelsriram/utils:latest655ad18fd8d6
icu@74.2-1ubuntu3.1
no fix listed
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
icu@67.1-7
67.1-7+deb11u1
1
assistiot/identity-manager_db:latest0d3e6d35f168
icu@72.1-3
72.1-3+deb12u1
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
icu@67.1-7
67.1-7+deb11u1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
icu@72.1-3
72.1-3+deb12u1
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
icu@66.1-2ubuntu2.1
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
icu@72.1-3
72.1-3+deb12u1
1
avzini/web-app:latestf40b30210ed0
icu@72.1-3
72.1-3+deb12u1
1
azhar008/flaskapplication:latesta1e827b0adea
icu@67.1-7
67.1-7+deb11u1
1
baserow/backend:1.31.1e0b3c8130b91
icu@72.1-3
72.1-3+deb12u1
1
baserow/baserow:1.30.1df0c42eb67e8
icu@72.1-3
72.1-3+deb12u1
1
beanbag/reviewboard:latest6b840f546e1c
icu@70.1-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.