StackRadar

CVE-2025-5222

High

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
826
of 17,787 indexed, latest versions
Container images
873
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: icu security update

Carried by container images the latest versions of 826 of 17,787 indexed charts deploy, on 873 images.

Affected packageAffected versionsFixed inImages
icudeb55.1-7ubuntu0.2, 55.1-7ubuntu0.3, 55.1-7ubuntu0.4, 55.1-7ubuntu0.5+12 more67.1-7+deb11u1, 72.1-3+deb12u1826
icuapk73.2-r2, 74.1-r0, 74.2-r0, 76.1-r074.1-r1, 74.2-r1, 76.1-r144
icurpm67.1-9.el90:67.1-10.el9_63
OSV records
ALPINE-CVE-2025-5222DEBIAN-CVE-2025-5222RHSA-2025:12083UBUNTU-CVE-2025-5222DLA-4217-1
Also known as
DSA-5951-1, RHSA-2025:12332

Charts affected

826 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
icu@74.2-r0
74.2-r1

Open the chart page →

4,768
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
icu@70.1-2
no fix listed

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
icu@72.1-3
72.1-3+deb12u1

Open the chart page →

10,795
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
icu@74.2-1ubuntu3.1
no fix listed

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
icu@70.1-2
no fix listed

Open the chart page →

13,459
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

3,392
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
icu@74.2-1ubuntu3.1
no fix listed

Open the chart page →

7,628
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
icu@66.1-2ubuntu2.1
no fix listed

Open the chart page →

11,405
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

2,132
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

9,397
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
icu@66.1-2ubuntu2.1
no fix listed

Open the chart page →

9,130
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
icu@66.1-2ubuntu2.1
no fix listed

Open the chart page →

9,130
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
icu@72.1-3
72.1-3+deb12u1

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
icu@66.1-2ubuntu2
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
icu@66.1-2ubuntu2
no fix listed

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

7,552
apisixwenerme2.17.01 of 3See more

apisix wenerme 2.17.0

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
apache/apisix:3.18.0-ubuntu9ee5df1611f9
icu@74.2-1ubuntu3.1
no fix listed

Open the chart page →

3,045
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
icu@66.1-2ubuntu2.1
no fix listed

Open the chart page →

15,230
reflectorwenerme10.0.651 of 1See more

reflector wenerme 10.0.65

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
emberstack/kubernetes-reflector:10.0.6551dbd5880929
icu@74.2-1ubuntu3.1
no fix listed

Open the chart page →

656
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
icu@70.1-2
no fix listed

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
icu@72.1-3
72.1-3+deb12u1

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
icu@72.1-3
72.1-3+deb12u1

Open the chart page →

7,673
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
icu@67.1-7
67.1-7+deb11u1

Open the chart page →

1,838
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-5222.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
icu@70.1-2
no fix listed

Open the chart page →

7,849

Container images carrying it

873 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gradiant/open5gs:2.7.575277742fc8a
icu@67.1-7
67.1-7+deb11u1
16
oomk8s/readiness-check:2.0.2875814cc853d
icu@55.1-7ubuntu0.4
no fix listed
11
library/nginx:1.21:1.21.62bcabc23b454
icu@67.1-7
67.1-7+deb11u1
6
oomk8s/readiness-check:2.0.07daa08b81954
icu@55.1-7ubuntu0.3
no fix listed
6
quay.io/devtron/postgres:14.91b594392f7cb
icu@72.1-3
72.1-3+deb12u1
6
library/postgres:122f2a8c2a7d10
icu@72.1-3
72.1-3+deb12u1
5
bitnamilegacy/postgresql:16233f361c5819
icu@72.1-3
72.1-3+deb12u1
4
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
icu@67.1-7
67.1-7+deb11u1
4
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
icu@55.1-7ubuntu0.4
no fix listed
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
icu@55.1-7ubuntu0.4
no fix listed
4
library/nginx:1.27.1287ff321f9e3
icu@72.1-3
72.1-3+deb12u1
4
opea/llm-tgi:1.00c25aab3f106
icu@72.1-3
72.1-3+deb12u1
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
icu@60.2-3ubuntu3.1
no fix listed
4
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
icu@67.1-7
67.1-7+deb11u1
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
icu@72.1-3
72.1-3+deb12u1
3
ciscolabs/rtsp-client:latesta7b60ec88285
icu@66.1-2ubuntu2.1
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
icu@66.1-2ubuntu2.1
no fix listed
3
gchq/hdfs:3.3.35ec58edbb2db
icu@74.2-1ubuntu3.1
no fix listed
3
guacamole/guacamole:1.6.0f344085e618b
icu@74.2-1ubuntu3.1
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
icu@72.1-3
72.1-3+deb12u1
3
library/postgres:14.13162a6ead070
icu@67.1-7
67.1-7+deb11u1
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
icu@74.2-r0
74.2-r1
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
icu@55.1-7ubuntu0.4
no fix listed
3
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
icu@67.1-7
67.1-7+deb11u1
3
siddharth67/block-buster-dev:7.6.04e1151ea5774
icu@67.1-7
67.1-7+deb11u1
3
signoz/zookeeper:3.7.1fcc4a3288154
icu@67.1-7
67.1-7+deb11u1
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
icu@72.1-3
72.1-3+deb12u1
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
icu@72.1-3
72.1-3+deb12u1
3
quay.io/devtron/ai-agent:0.0.16545dac92173
icu@72.1-3
72.1-3+deb12u1
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
icu@70.1-2
no fix listed
3
apache/apisix:3.18.0-ubuntu9ee5df1611f9
icu@74.2-1ubuntu3.1
no fix listed
2
apache/nifi-registry:1.26.07cdfd8deec92
icu@70.1-2
no fix listed
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
icu@74.2-1ubuntu3
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
icu@72.1-3
72.1-3+deb12u1
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
icu@67.1-7
67.1-7+deb11u1
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
icu@72.1-3
72.1-3+deb12u1
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
icu@67.1-7
67.1-7+deb11u1
2
blakeblackshear/frigate:0.11.18330b0a265b8
icu@67.1-7
67.1-7+deb11u1
2
cculianu/fulcrum:v1.9.76445fb75abea
icu@67.1-7
67.1-7+deb11u1
2
cribl/cribl:4.19.2044f9a5fac9a
icu@74.2-1ubuntu3.1
no fix listed
2
emberstack/kubernetes-reflector:10.0.6551dbd5880929
icu@74.2-1ubuntu3.1
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
icu@72.1-3
72.1-3+deb12u1
2
gradiant/ueransim:3.2.6015b30d5fa0f
icu@70.1-2
no fix listed
2
homebridge/homebridge:latest77c685a40911
icu@74.2-1ubuntu3.1
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
icu@66.1-2ubuntu2
no fix listed
2
kurento/kurento-media-server:latest03c0d34d0828
icu@74.2-1ubuntu3.1
no fix listed
2
ldapaccountmanager/lam:8.0.1d46cf25d1dda
icu@67.1-7
67.1-7+deb11u1
2
library/adminer:4.8.1-standalone34d37131366c
icu@67.1-7
67.1-7+deb11u1
2
library/nginx:1.27.098f8ec75657d
icu@72.1-3
72.1-3+deb12u1
2
library/nginx:1.24.0f6daac2445b0
icu@67.1-7
67.1-7+deb11u1
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.