StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,554
of 17,813 indexed, latest versions
Container images
2,599
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,554 of 17,813 indexed charts deploy, on 2,599 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,428
coreutilsrpm8.29-lp151.3.3, 8.29-lp152.4.7, 8.32-32.el9, 8.32-34.el9+7 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more155
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.176
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,554 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
coreutils@9.1-1
no fix listed

Open the chart page →

2,697
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,956
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
coreutils@8.28-1ubuntu1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4

Open the chart page →

7,966

Container images carrying it

2,599 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
schemahero/schemahero-manager:0.22.11609e1a05cd3
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
scrapinghub/splash:3.4.1a5f89bc84606
coreutils@8.28-1ubuntu1
no fix listed
1
scsibug/nostr-rs-relay:0.9.003f54bfbffff
coreutils@9.1-1
no fix listed
1
seafileltd/seafile-mc:9.0.106693911bcc40
coreutils@8.30-3ubuntu2
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
coreutils@8.30-3ubuntu2
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
coreutils@8.30-3ubuntu2
no fix listed
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
coreutils@8.30-3ubuntu2
no fix listed
1
sebt3/kuberest:1.4.00ccce5d6d4d2
coreutils@9.1-1
no fix listed
1
seldonio/locust-core:0.81d0da98a2d76
coreutils@8.25-2ubuntu3~16.04
no fix listed
1
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
seoulorigin/janus-ml-sidecar:v3.192cbaad0c540
coreutils@9.7-3
no fix listed
1
sepehrmdn/mirasys-assignment:1.0.12567228e33c8
coreutils@9.1-1
no fix listed
1
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
coreutils@9.7-3
no fix listed
1
shamimkuet/nginx:1.0.2b82902a76a04
coreutils@9.1-1
no fix listed
1
shaowenchen/ops-server:latest6bac5cebd125
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
sharanalwar/redchef-backend:latest8d3cab80df49
coreutils@9.1-1
no fix listed
1
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
coreutils@8.28-1ubuntu1
no fix listed
1
shwcloud/seawise-backup:v1.7.1a97479a54df4
coreutils@9.7-3
no fix listed
1
sifrai/grandine:unstable59ef4c0d4d7f
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
1
signalen/backend:2.50.14760256000738
coreutils@9.1-1
no fix listed
1
signoz/signoz-otel-collector:v0.144.1034ecb436b687
coreutils@9.1-1
no fix listed
1
sigp/lighthouse:v7.0.12cae720e9a35
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
sigp/lighthouse:v7.1.0870934e38931
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
sigp/lighthouse:v2.1.2ad501f02cfef
coreutils@8.30-3ubuntu2
no fix listed
1
sigp/siren:v3.0.42c219b04758e
coreutils@9.1-1
no fix listed
1
sigscale/cse:latest67d0c886516b
coreutils@9.1-1
no fix listed
1
sigscale/ocs:latest3c1bdc9732e2
coreutils@9.1-1
no fix listed
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
coreutils@9.1-1
no fix listed
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
coreutils@9.1-1
no fix listed
1
sirrend/helmup-notifications-service:0.1.3997866417011
coreutils@9.1-1
no fix listed
1
sismics/docs:v1.10f4b0ef019cf1
coreutils@8.28-1ubuntu1
no fix listed
1
sissbruecker/linkding:1.35.00c5dddf0b37c
coreutils@9.1-1
no fix listed
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
coreutils@9.1-1
no fix listed
1
sissbruecker/linkding:1.47.0e35cb50e0581
coreutils@9.7-3
no fix listed
1
slagattollas/weatherservice-practica:latest68e7f56393fc
coreutils@8.28-1ubuntu1
no fix listed
1
snipe/snipe-it:v8.3.1141ebf2386fe
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
snipe/snipe-it:v6.0.1455fb7636a98c
coreutils@8.30-3ubuntu2
no fix listed
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
coreutils@8.30-3ubuntu2
no fix listed
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
coreutils@8.28-1ubuntu1
no fix listed
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
coreutils@9.1-1
no fix listed
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
coreutils@8.28-1ubuntu1
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.