StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,519
of 17,821 indexed, latest versions
Container images
2,564
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,519 of 17,821 indexed charts deploy, on 2,564 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,394
coreutilsrpm8.29-lp151.3.3, 8.29-lp152.4.7, 8.32-32.el9, 8.32-34.el9+7 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more154
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.175
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,519 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,564 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
coreutils@9.1-1
no fix listed
1
bitnamilegacy/valkey:8.1.3-debian-12-r1a185655855b3
coreutils@9.1-1
no fix listed
1
bitnami/mariadb:11.7.216a7dae804fb
coreutils@9.1-1
no fix listed
1
bitnami/memcached:1.6.38dd8f2cba9a5b
coreutils@9.1-1
no fix listed
1
bitnami/minideb:latest835e5f8392c3
coreutils@9.7-3
no fix listed
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
coreutils@9.1-1
no fix listed
1
bitnami/redis:7.4.24e65bf641805
coreutils@9.1-1
no fix listed
1
blackducksoftware/bdba-fluentd:2026.6.3c14bbbf45536
coreutils@9.7-3
no fix listed
1
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
coreutils@9.7-3
no fix listed
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
coreutils@8.30-3ubuntu2
no fix listed
1
blockstream/bitcoind:27.29472492530e3
coreutils@9.1-1
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
coreutils@9.1-1
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
coreutils@9.1-1
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
coreutils@9.1-1
no fix listed
1
boky/postfix:5.1.0:v5.1.0aafc77238423
coreutils@9.7-3
no fix listed
1
boky/postfix:4.4.0f3f247fd4252
coreutils@9.1-1
no fix listed
1
boxcutter/meshcmd:1.1.384e13f01bcab
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
coreutils@8.30-3ubuntu2
no fix listed
1
btcpayserver/tor:0.4.8.10e9585b68dc6b
coreutils@9.1-1
no fix listed
1
budibase/database:2.1.0d90f656261c9
coreutils@9.1-1
no fix listed
1
budibase/proxy:3.41.38d780b6ee602
coreutils@9.7-3
no fix listed
1
bugsink/bugsink:2ecdd84587746
coreutils@9.7-3
no fix listed
1
burakince/mlflow:3.16.0ab4b566644b9
coreutils@9.7-3
no fix listed
1
calltelemetry/web:0.8.1-rc7205d13269e350
coreutils@9.1-1
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
coreutils@8.32-4.1ubuntu1.1
8.32-4.1ubuntu1.4
1
carbone/carbone-ee:full-5.11.0518172cbad49
coreutils@9.7-3
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
coreutils@9.1-1
no fix listed
1
castai/hibernate:v0.14da62858c8381
coreutils@9.7-3
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
castopod/castopod:1.12.101fd37280cbb2
coreutils@9.1-1
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
coreutils@9.7-3
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
cccs/assemblyline-core:4.7.4.stable20098127270065
coreutils@9.1-1
no fix listed
1
cccs/assemblyline-rust:4.7.4.stable202be5e6a57427
coreutils@9.1-1
no fix listed
1
cccs/assemblyline-socketio:4.7.4.stable202b88493b62f7
coreutils@9.1-1
no fix listed
1
cccs/assemblyline-ui:4.7.4.stable20efa75509b854
coreutils@9.1-1
no fix listed
1
ceresdb/ceresdb-server:v1.0.053b2d0dbba1f
coreutils@8.30-3ubuntu2
no fix listed
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
coreutils@8.29-lp151.3.3
9.7-3.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
coreutils@8.29-lp151.3.3
9.7-3.1
1
chaerr/kridge:demo-operator-v0.1.266833deec017
coreutils@8.30-3ubuntu2
no fix listed
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
coreutils@9.1-1
no fix listed
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
coreutils@8.21-1ubuntu5.4
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
coreutils@8.30-3ubuntu2
no fix listed
1
cheveo/azp-agent:1.0.282240f890884
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
cheyang/distributed-tf:1.6.046cc34755493
coreutils@8.25-2ubuntu3~16.04
no fix listed
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
coreutils@9.7-3
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
coreutils@9.7-3
no fix listed
1
chriseaton/adventureworks:latest54c3384ce701
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
chromadb/chroma:1.5.7fc8dc8e11fb2
coreutils@9.7-3
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.