StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,492
of 17,803 indexed, latest versions
Container images
2,511
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,492 of 17,803 indexed charts deploy, on 2,511 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,345
coreutilsrpm8.29-lp151.3.3, 8.32-32.el9, 8.32-34.el9, 8.32-35.el9+6 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more154
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.174
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,492 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,511 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
btcpayserver/tor:0.4.8.10e9585b68dc6b
coreutils@9.1-1
no fix listed
1
budibase/database:2.1.0d90f656261c9
coreutils@9.1-1
no fix listed
1
budibase/proxy:3.41.38d780b6ee602
coreutils@9.7-3
no fix listed
1
bugsink/bugsink:2ecdd84587746
coreutils@9.7-3
no fix listed
1
burakince/mlflow:3.16.0ab4b566644b9
coreutils@9.7-3
no fix listed
1
calltelemetry/web:0.8.1-rc7205d13269e350
coreutils@9.1-1
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
coreutils@8.32-4.1ubuntu1.1
8.32-4.1ubuntu1.4
1
carbone/carbone-ee:full-5.11.0518172cbad49
coreutils@9.7-3
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
coreutils@9.1-1
no fix listed
1
castai/hibernate:v0.14da62858c8381
coreutils@9.7-3
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
castopod/castopod:1.12.101fd37280cbb2
coreutils@9.1-1
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
coreutils@9.7-3
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
cccs/assemblyline-core:4.7.4.stable20098127270065
coreutils@9.1-1
no fix listed
1
cccs/assemblyline-rust:4.7.4.stable202be5e6a57427
coreutils@9.1-1
no fix listed
1
cccs/assemblyline-socketio:4.7.4.stable202b88493b62f7
coreutils@9.1-1
no fix listed
1
cccs/assemblyline-ui:4.7.4.stable20efa75509b854
coreutils@9.1-1
no fix listed
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
coreutils@8.29-lp151.3.3
9.7-3.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
coreutils@8.29-lp151.3.3
9.7-3.1
1
chaerr/kridge:demo-operator-v0.1.266833deec017
coreutils@8.30-3ubuntu2
no fix listed
1
chainsafe/lodestar:latest5593f6e97912
coreutils@9.1-1
no fix listed
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
coreutils@9.1-1
no fix listed
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
coreutils@8.21-1ubuntu5.4
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
coreutils@8.30-3ubuntu2
no fix listed
1
cheveo/azp-agent:1.0.282240f890884
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
cheyang/distributed-tf:1.6.046cc34755493
coreutils@8.25-2ubuntu3~16.04
no fix listed
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
coreutils@9.7-3
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
coreutils@9.7-3
no fix listed
1
chriseaton/adventureworks:latest54c3384ce701
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
chromadb/chroma:1.5.7fc8dc8e11fb2
coreutils@9.7-3
no fix listed
1
circleci/runner:launch-agent9bdc62f02162
coreutils@8.30-3ubuntu2
no fix listed
1
ciscolabs/msm-nc:0710202336d02faad958
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
citizenstig/httpbin:latestb81c818ccb86
coreutils@8.25-2ubuntu2
no fix listed
1
ckan/ckan-base:2.12.087ecf3f27ad6
coreutils@9.1-1
no fix listed
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
ckulka/baikal:0.10.1-nginx434bdd162247
coreutils@9.1-1
no fix listed
1
cleveritcz/opencve:1.5.0c75c1636e0b7
coreutils@8.32-34.el9
0:8.32-41.el9_8
1
clickhouse/clickhouse-server:24.81ffa82edee00
coreutils@8.30-3ubuntu2
no fix listed
1
clickhouse/clickhouse-server:24.4.12e6587b81a26
coreutils@8.30-3ubuntu2
no fix listed
1
clickhouse/clickhouse-server:23.8512bb8a21483
coreutils@8.30-3ubuntu2
no fix listed
1
clickhouse/clickhouse-server:26.3810861a2e2d0
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:25.3.2.398745843b17f9
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:26.3.1092098d3b31dd
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:26.8.2:latestfa394da808cc
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.