StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,507
of 17,803 indexed, latest versions
Container images
2,535
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,507 of 17,803 indexed charts deploy, on 2,535 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,368
coreutilsrpm8.29-lp151.3.3, 8.32-32.el9, 8.32-34.el9, 8.32-35.el9+6 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more154
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.175
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,507 by stars
ChartLatestAffected imagesRadar Score
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

72,223
apachedevops0.1.02 of 4See more

apache devops 0.1.0

2 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
ghcr.io/codingducksrl/laravel:8.15be52524664c
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

111,395
laraveldevops0.10.32 of 4See more

laravel devops 0.10.3

2 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/mariadb:10.9.4fbb8456ebdb1
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
ghcr.io/codingducksrl/laravel:8.15be52524664c
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

110,396
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

13,054
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
coreutils@9.1-1
no fix listed

Open the chart page →

9,743
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

13,159
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

4,704
devtron-enterprisedevtron48.0.08 of 28See more

devtron-enterprise devtron 48.0.0

8 of the 28 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
coreutils@9.1-1
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
coreutils@8.25-2ubuntu3~16.04
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
coreutils@9.1-1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
coreutils@9.1-1
no fix listed

Open the chart page →

69,552
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

4,983
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

11,990
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
coreutils@9.1-1
no fix listed

Open the chart page →

3,947
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
coreutils@9.1-1
no fix listed

Open the chart page →

9,743
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

13,159
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

4,704
devtron-enterprisedevtron-labs48.0.08 of 28See more

devtron-enterprise devtron-labs 48.0.0

8 of the 28 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
coreutils@9.1-1
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
coreutils@8.25-2ubuntu3~16.04
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
coreutils@9.1-1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
coreutils@9.1-1
no fix listed

Open the chart page →

69,552
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

4,983
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
coreutils@9.1-1
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
quay.io/devtron/postgres:14.91b594392f7cb
coreutils@9.1-1
no fix listed

Open the chart page →

33,352
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

11,990
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
coreutils@9.1-1
no fix listed

Open the chart page →

3,947
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.03 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
coreutils@8.28-1ubuntu1
no fix listed
library/rabbitmq:3-managemente582c0bc7766
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
oscarsotosanchez/weatherservice:v1.0911ec961d10b
coreutils@8.28-1ubuntu1
no fix listed

Open the chart page →

27,703
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
coreutils@9.1-1
no fix listed

Open the chart page →

4,103
difydify1.0.03 of 4See more

dify dify 1.0.0

3 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
coreutils@9.1-1
no fix listed
langgenius/dify-plugin-daemon:main-localda995c129e2f
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
langgenius/dify-sandbox:0.2.009b7e8705673
coreutils@9.1-1
no fix listed

Open the chart page →

47,013
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
coreutils@8.30-3ubuntu2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
coreutils@8.28-1ubuntu1
no fix listed

Open the chart page →

20,261
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
coreutils@9.7-3
no fix listed

Open the chart page →

7,570
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
coreutils@9.1-1
no fix listed

Open the chart page →

2,421
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
coreutils@9.1-1
no fix listed

Open the chart page →

7,342
ownclouddjjudas21Verified publisher0.3.233 of 3See more

owncloud djjudas21 0.3.23

3 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
coreutils@9.1-1
no fix listed
owncloud/server:10.16.3b3f9efdcd7f7
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4
valkey/valkey:8.1.481db6d39e1bb
coreutils@9.7-3
no fix listed

Open the chart page →

10,254
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3

Open the chart page →

87,945
spoolmandjjudas21Verified publisher0.1.81 of 1See more

spoolman djjudas21 0.1.8

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.24.042135965c42d
coreutils@9.1-1
no fix listed

Open the chart page →

1,877
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
coreutils@9.7-3
no fix listed

Open the chart page →

5,374
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
coreutils@9.7-3
no fix listed

Open the chart page →

6,031
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
coreutils@9.1-1
no fix listed

Open the chart page →

14,737
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
coreutils@9.1-1
no fix listed

Open the chart page →

3,864
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
coreutils@9.1-1
no fix listed

Open the chart page →

3,864
dnation-kubernetes-monitoring-stackdnationcloud4.0.21 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

1 of the 17 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
coreutils@9.1-1
no fix listed

Open the chart page →

22,020
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
coreutils@8.28-1ubuntu1
no fix listed

Open the chart page →

9,006
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
coreutils@9.7-3
no fix listed

Open the chart page →

3,098
dominodomino-iisasVerified publisher0.3.13 of 3See more

domino domino-iisas 0.3.1

3 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
coreutils@9.7-3
no fix listed
ghcr.io/iisas/domino-frontend:k8s8e53861be292
coreutils@9.1-1
no fix listed
ghcr.io/iisas/domino-rest:latest3009350bfc11
coreutils@9.7-3
no fix listed

Open the chart page →

10,389
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
coreutils@8.32-36.el9
0:8.32-41.el9_8

Open the chart page →

3,202
exim4dossif0.2.01 of 1See more

exim4 dossif 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
tianon/exim4:latestb489049cdbca
coreutils@9.7-3
no fix listed

Open the chart page →

1,496
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

25,002
healthchecksdoubanVerified publisher1.0.101 of 2See more

healthchecks douban 1.0.10

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
healthchecks/healthchecks:latestaa08a61b0dcf
coreutils@9.7-3
no fix listed

Open the chart page →

1,750
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

11,890
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.03 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
coreutils@8.28-1ubuntu1
no fix listed
library/rabbitmq:3-managemente582c0bc7766
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
oscarsotosanchez/weatherservice:v1.0911ec961d10b
coreutils@8.28-1ubuntu1
no fix listed

Open the chart page →

24,793
drogue-cloud-coredrogue-iotVerified publisher0.7.1118 of 22See more

drogue-cloud-core drogue-iot 0.7.11

18 of the 22 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
coreutils@8.32-32.el9
0:8.32-41.el9_8
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
coreutils@8.32-32.el9
0:8.32-41.el9_8

Open the chart page →

56,284
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

30,804
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
coreutils@9.1-1
no fix listed

Open the chart page →

4,486
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
coreutils@9.7-3
no fix listed

Open the chart page →

3,509
rundeckdwardu-helm-charts0.3.42 of 2See more

rundeck dwardu-helm-charts 0.3.4

2 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
coreutils@9.7-3
no fix listed
rundeck/rundeck:3.2.74d64fe56f767
coreutils@8.25-2ubuntu3~16.04
no fix listed

Open the chart page →

19,905
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
coreutils@9.1-1
no fix listed

Open the chart page →

9,439

Container images carrying it

2,535 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
coreutils@8.32-35.el9
0:8.32-41.el9_8
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
coreutils@8.32-34.el9
0:8.32-41.el9_8
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
coreutils@8.32-35.el9
0:8.32-41.el9_8
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
coreutils@9.1-1
no fix listed
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
coreutils@8.32-36.el9
0:8.32-41.el9_8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
coreutils@9.1-1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
coreutils@8.30-3ubuntu2
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
coreutils@9.7-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
coreutils@9.1-1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.