StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,519
of 17,821 indexed, latest versions
Container images
2,564
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,519 of 17,821 indexed charts deploy, on 2,564 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,394
coreutilsrpm8.29-lp151.3.3, 8.29-lp152.4.7, 8.32-32.el9, 8.32-34.el9+7 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more154
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.175
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,519 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,564 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
circleci/runner:launch-agent9bdc62f02162
coreutils@8.30-3ubuntu2
no fix listed
1
ciscolabs/msm-nc:0710202336d02faad958
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
citizenstig/httpbin:latestb81c818ccb86
coreutils@8.25-2ubuntu2
no fix listed
1
ckan/ckan-base:2.12.087ecf3f27ad6
coreutils@9.1-1
no fix listed
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
ckulka/baikal:0.10.1-nginx434bdd162247
coreutils@9.1-1
no fix listed
1
cleveritcz/opencve:1.5.0c75c1636e0b7
coreutils@8.32-34.el9
0:8.32-41.el9_8
1
clickhouse/clickhouse-server:24.81ffa82edee00
coreutils@8.30-3ubuntu2
no fix listed
1
clickhouse/clickhouse-server:24.4.12e6587b81a26
coreutils@8.30-3ubuntu2
no fix listed
1
clickhouse/clickhouse-server:23.8512bb8a21483
coreutils@8.30-3ubuntu2
no fix listed
1
clickhouse/clickhouse-server:26.3810861a2e2d0
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:26.584d05b9c205e
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:25.3.2.398745843b17f9
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:26.3.1092098d3b31dd
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
clickhouse/clickhouse-server:26.8.2:latestfa394da808cc
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
cloudtooling/moodle:5.2.3f4f04e0fc401
coreutils@9.1-1
no fix listed
1
cloudtooling/wordpress:7.1.1db89d95f1d14
coreutils@9.1-1
no fix listed
1
cloudve/janis-terminal:latestaf56e77ca587
coreutils@8.28-1ubuntu1
no fix listed
1
cloudve/ttyd:latestd79c1c5881c0
coreutils@8.28-1ubuntu1
no fix listed
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
coreutils@9.1-1
no fix listed
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
coreutils@9.1-1
no fix listed
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
coreutils@9.1-1
no fix listed
1
cm2network/squad:latest8cba47f53df5
coreutils@9.7-3
no fix listed
1
cockroachdb/cockroachdb-operator-v2:v1.0.04335d8bcbd3d
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
codetogether/codetogether:latest4348c8a38752
coreutils@8.32-35.el9
0:8.32-41.el9_8
1
collabora/code:24.04.13.2.101dc4ab83977
coreutils@9.1-1
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
coreutils@9.1-1
no fix listed
1
conductoross/conductor:3.31.09fba127693e6
coreutils@9.7-3
no fix listed
1
consensys/teku:latest3a4f5761ae1c
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
1
consensys/teku:25.4.1bf6ecd2ea716
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
consensys/web3signer:latestf146a51a1ba3
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
coreutils@9.1-1
no fix listed
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
coreutils@9.1-1
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
cortezaproject/corteza:2024.9.08eb7a26605c9
coreutils@8.30-3ubuntu2
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
coreutils@9.1-1
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
coreutils@9.7-3
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
coreutils@8.30-3ubuntu2
no fix listed
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
coreutils@8.28-1ubuntu1
no fix listed
1
cribl/cribl:3.0.2762747cb6796
coreutils@8.28-1ubuntu1
no fix listed
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
coreutils@8.25-2ubuntu3~16.04
no fix listed
1
cspconsole/config-provider:1.0.365524a26a6c23
coreutils@9.1-1
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
coreutils@9.1-1
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
coreutils@9.1-1
no fix listed
1
cspconsole/report-processor:1.0.279a2d8840bfdf
coreutils@9.1-1
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.