StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,511
of 17,790 indexed, latest versions
Container images
2,543
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,511 of 17,790 indexed charts deploy, on 2,543 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,376
coreutilsrpm8.29-lp151.3.3, 8.32-32.el9, 8.32-34.el9, 8.32-35.el9+6 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more155
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.175
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,511 by stars
ChartLatestAffected imagesRadar Score
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
coreutils@8.28-1ubuntu1
no fix listed

Open the chart page →

15,602
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

7,920
camel-kcamel-kVerified publisher2.11.01 of 1See more

camel-k camel-k 2.11.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
apache/camel-k:2.11.0d173e7efe258
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,293
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

11,987
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
coreutils@9.1-1
no fix listed

Open the chart page →

5,375
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
coreutils@8.32-39.el9
0:8.32-41.el9_8
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
coreutils@8.32-39.el9
0:8.32-41.el9_8

Open the chart page →

4,885
milvusmilvus-helm5.0.283 of 4See more

milvus milvus-helm 5.0.28

3 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
milvusdb/etcd:3.5.25-r1fededb2f2d63
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
coreutils@8.32-36.el9
0:8.32-41.el9_8

Open the chart page →

10,782
prefect-serverprefectVerified publisher2026.9.141419102 of 2See more

prefect-server prefect 2026.9.14141910

2 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
coreutils@9.1-1
no fix listed
prefecthq/prefect:3.8.6-python3.11f518ebb9c353
coreutils@9.7-3
no fix listed

Open the chart page →

5,556
rocketmqrocketmq12.6.02 of 2See more

rocketmq rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
coreutils@8.32-39.el9
0:8.32-41.el9_8

Open the chart page →

6,400
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

18,589
codefreshcodefresh-onpremOfficialVerified publisher2.12.144 of 42See more

codefresh codefresh-onprem 2.12.14

4 of the 42 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
coreutils@9.1-1
no fix listed
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
coreutils@9.1-1
no fix listed
bitnamilegacy/rabbitmq:4.1.39e635efba431
coreutils@9.1-1
no fix listed
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
coreutils@9.1-1
no fix listed

Open the chart page →

15,093
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4

Open the chart page →

1,524
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
coreutils@9.7-3
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
coreutils@9.7-3
no fix listed

Open the chart page →

4,852
redisgroundhog2k2.4.71 of 1See more

redis groundhog2k 2.4.7

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
coreutils@9.7-3
no fix listed

Open the chart page →

978
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
coreutils@9.7-3
no fix listed

Open the chart page →

3,752
memcachedkubelauncherVerified publisher0.1.321 of 1See more

memcached kubelauncher 0.1.32

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/memcacheddigest-pinnedb599ca6b3ff3
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

640
mysqlkubelauncherVerified publisher0.4.41 of 1See more

mysql kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnede9609bd50416
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

982
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,159
velero-uiotwldVerified publisher0.15.01 of 1See more

velero-ui otwld 0.15.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.2d1954b759e47
coreutils@9.1-1
no fix listed

Open the chart page →

1,354
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2api:3.86f56d239d280
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2auth:3.833ecfda16608
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2notifier:3.8f190a6212195
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2web:3.809989a26c8b7
coreutils@8.30-3ubuntu2
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

96,933
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
library/kong:3.8.0712e407b20ea
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
supabase/edge-runtime:v1.59.0eff9c554d649
coreutils@9.1-1
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
coreutils@9.1-1
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
coreutils@9.1-1
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
coreutils@9.1-1
no fix listed

Open the chart page →

23,365
wekanwekanVerified publisher11.83.02 of 3See more

wekan wekan 11.83.0

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest6cb94aa01999
coreutils@9.7-3
no fix listed
ghcr.io/wekan/wekan:v11.83137951e3fb40
coreutils@9.7-3
no fix listed

Open the chart page →

1,619
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
coreutils@9.1-1
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
coreutils@9.1-1
no fix listed

Open the chart page →

8,586
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3

Open the chart page →

1,778
budibasebudibase0.0.0-master4 of 7See more

budibase budibase 0.0.0-master

4 of the 7 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
coreutils@9.1-1
no fix listed
budibase/proxy:3.41.38d780b6ee602
coreutils@9.7-3
no fix listed
library/redis:latest298e5b3bc566
coreutils@9.7-3
no fix listed
minio/minio:latest14cea493d9a3
coreutils@8.32-39.el9
0:8.32-41.el9_8

Open the chart page →

10,856
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.23 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

3 of the 5 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
coreutils@9.4-6.azl3
9.4-7
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
coreutils@9.4-6.azl3
9.4-7
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
coreutils@9.4-6.azl3
9.4-7

Open the chart page →

2,263
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

3,496
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
coreutils@9.1-1
no fix listed

Open the chart page →

3,048
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

7,923
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,496
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

818
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,404
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,296
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,261
mariadbkubelauncherVerified publisher0.5.71 of 1See more

mariadb kubelauncher 0.5.7

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinnede25056a6ec52
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,107
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,386
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3

Open the chart page →

1,284
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3

Open the chart page →

1,124
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

814
zookeeperkubelauncherVerified publisher0.2.111 of 1See more

zookeeper kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/zookeeperdigest-pinned7826e9caa461
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,033
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

3,124
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
coreutils@9.1-1
no fix listed

Open the chart page →

3,503
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

11,449
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4

Open the chart page →

1,740
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
coreutils@9.7-3
no fix listed

Open the chart page →

2,962
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

4,284
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
coreutils@9.1-1
no fix listed

Open the chart page →

3,041
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3

Open the chart page →

4,641
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
coreutils@9.1-1
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/postgres:14.91b594392f7cb
coreutils@9.1-1
no fix listed

Open the chart page →

33,180
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3

Open the chart page →

3,675

Container images carrying it

2,543 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
coreutils@9.7-3
no fix listed
1
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
coreutils@8.32-35.el9
0:8.32-41.el9_8
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
coreutils@9.1-1
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
coreutils@9.1-1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
coreutils@9.1-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
coreutils@9.1-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
coreutils@9.1-1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
coreutils@9.1-1
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
coreutils@9.1-1
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
coreutils@9.1-1
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
coreutils@9.1-1
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
coreutils@9.1-1
no fix listed
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
coreutils@8.32-36.el9
0:8.32-41.el9_8
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
coreutils@8.32-36.el9
0:8.32-41.el9_8
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
coreutils@8.28-1ubuntu1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
coreutils@8.30-3ubuntu2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
coreutils@9.1-1
no fix listed
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
coreutils@8.32-35.el9
0:8.32-41.el9_8
1
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
coreutils@8.32-36.el9
0:8.32-41.el9_8
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
coreutils@8.32-36.el9
0:8.32-41.el9_8
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
quay.io/aerokube/keygen:1.0.1578934444f04
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
coreutils@8.32-35.el9
0:8.32-41.el9_8
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
coreutils@9.7-3
no fix listed
1
quay.io/backube/volsync:0.16.00d03a6aad575
coreutils@8.32-40.el9
0:8.32-41.el9_8
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
coreutils@9.1-1
no fix listed
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
coreutils@9.1-1
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
coreutils@8.32-36.el9
0:8.32-41.el9_8
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
coreutils@8.28-1ubuntu1
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
coreutils@9.7-3
no fix listed
1
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
coreutils@8.32-35.el9
0:8.32-41.el9_8
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.