StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,554
of 17,821 indexed, latest versions
Container images
2,613
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,554 of 17,821 indexed charts deploy, on 2,613 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,440
coreutilsrpm8.29-lp151.3.3, 8.29-lp152.4.7, 8.32-32.el9, 8.32-34.el9+7 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more155
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.177
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,554 by stars
ChartLatestAffected imagesRadar Score
matomopockostVerified publisher1.3.03 of 3See more

matomo pockost 1.3.0

3 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
library/redis:8.10.1298e5b3bc566
coreutils@9.7-3
no fix listed
pockost/matomo:5.13.07f5d293cbe4e
coreutils@9.7-3
no fix listed

Open the chart page →

5,247
portraitportraitVerified publisher0.2.133 of 8See more

portrait portrait 0.2.13

3 of the 8 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
coreutils@8.30-3ubuntu2
no fix listed
treskon/portrait:DEV-latest88e813f22347
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
coreutils@9.1-1
no fix listed

Open the chart page →

32,232
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
coreutils@9.7-3
no fix listed

Open the chart page →

1,272
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
coreutils@9.7-3
no fix listed

Open the chart page →

2,451
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3

Open the chart page →

5,565
prowlerprowler-appVerified publisher0.0.92 of 5See more

prowler prowler-app 0.0.9

2 of the 5 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
coreutils@9.7-3
no fix listed
prowlercloud/prowler-api:5.31.14f252d579be2
coreutils@9.1-1
no fix listed

Open the chart page →

8,340
pzserverpzserver0.1.171 of 2See more

pzserver pzserver 0.1.17

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
lis314/project-zomboid-docker:latestaa2089c37920
coreutils@9.1-1
no fix listed

Open the chart page →

3,274
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3

Open the chart page →

56,594
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

6,930
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3

Open the chart page →

2,855
redis-enterprise-operatorredis-enterprise-operatorVerified publisher7.13.4-121 of 1See more

redis-enterprise-operator redis-enterprise-operator 7.13.4-12

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
redislabs/operator:7.4.2-2ecb101af0506
coreutils@8.32-34.el9
0:8.32-41.el9_8

Open the chart page →

2,637
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest2cc70b45244a
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4

Open the chart page →

67,944
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
coreutils@9.1-1
no fix listed

Open the chart page →

2,629
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
coreutils@9.7-3
no fix listed

Open the chart page →

4,298
reportportalreportportal-ioOfficialVerified publisher26.8.123 of 15See more

reportportal reportportal-io 26.8.12

3 of the 15 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
coreutils@9.1-1
no fix listed
library/postgres:18.4a02db8cac496
coreutils@9.7-3
no fix listed
library/rabbitmq:4.3.4-managementeb5295d08332
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3

Open the chart page →

12,077
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4

Open the chart page →

7,249
retyc-csiretyc-csi0.2.01 of 3See more

retyc-csi retyc-csi 0.2.0

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
coreutils@9.7-3
no fix listed

Open the chart page →

1,420
atuinrm3lVerified publisher0.11.02 of 3See more

atuin rm3l 0.11.0

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
coreutils@9.1-1
no fix listed
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
coreutils@9.1-1
no fix listed

Open the chart page →

6,477
dev-feedrm3lVerified publisher3.1.22 of 3See more

dev-feed rm3l 3.1.2

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
coreutils@9.1-1
no fix listed
rm3l/dev-feed-api:latestf03921cd3b26
coreutils@8.32-34.el9
0:8.32-41.el9_8

Open the chart page →

9,890
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

10,175
kimai2robjuz5.0.141 of 2See more

kimai2 robjuz 5.0.14

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
kimai/kimai2:2.67.03084f1e5ecdc
coreutils@9.1-1
no fix listed

Open the chart page →

4,777
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
coreutils@9.1-1
no fix listed

Open the chart page →

5,635
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

6,148
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
coreutils@9.1-1
no fix listed

Open the chart page →

7,796
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

6,957
kube-state-metricsromanow-helm-chartsVerified publisher1.7.21 of 1See more

kube-state-metrics romanow-helm-charts 1.7.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
bitnamilegacy/kube-state-metrics:204a3044b384b
coreutils@9.1-1
no fix listed

Open the chart page →

2,645
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

7,608
postgresromanow-helm-chartsVerified publisher1.7.11 of 1See more

postgres romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
coreutils@9.7-3
no fix listed

Open the chart page →

1,272
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

12,918
rstmdbrstmdb0.2.01 of 1See more

rstmdb rstmdb 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
rstmdb/rstmdb:lateste5187f2aaace
coreutils@9.1-1
no fix listed

Open the chart page →

1,023
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
coreutils@9.7-3
no fix listed

Open the chart page →

3,940
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
coreutils@9.1-1
no fix listed

Open the chart page →

5,323
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
coreutils@8.28-1ubuntu1
no fix listed

Open the chart page →

13,604
kyoorubxkubeVerified publisher0.1.104 of 9See more

kyoo rubxkube 0.1.10

4 of the 9 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
coreutils@9.1-1
no fix listed
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
coreutils@9.1-1
no fix listed
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
coreutils@9.1-1
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
coreutils@9.1-1
no fix listed

Open the chart page →

30,550
conference-appsalaboy1.0.03 of 7See more

conference-app salaboy 1.0.0

3 of the 7 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

11,095
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
coreutils@9.1-1
no fix listed

Open the chart page →

38,725
teamcityscalified-teamcityVerified publisher2026.2.01 of 3See more

teamcity scalified-teamcity 2026.2.0

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
coreutils@9.7-3
no fix listed

Open the chart page →

1,272
sceptresceptreai0.1.122 of 5See more

sceptre sceptreai 0.1.12

2 of the 5 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
coreutils@9.7-3
no fix listed
maponyacharles/sceptreai:api-0.1.127b37b092130a
coreutils@9.7-3
no fix listed

Open the chart page →

4,527
schemaheroschemahero1.4.01 of 1See more

schemahero schemahero 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
schemahero/schemahero-manager:0.22.11609e1a05cd3
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3

Open the chart page →

2,208
searxngsearxngVerified publisher0.1.111 of 3See more

searxng searxng 0.1.11

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
valkey/valkey:9.1.1-trixie64e361b630ec
coreutils@9.7-3
no fix listed

Open the chart page →

780
securosecuroVerified publisher0.16.02 of 4See more

securo securo 0.16.0

2 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
pgvector/pgvector:pg16ccc6e83d6e35
coreutils@9.1-1
no fix listed
ghcr.io/securo-finance/securo-backend:0.16.0f452147e07f1
coreutils@9.7-3
no fix listed

Open the chart page →

3,597
immichsecustorVerified publisher2.0.61 of 1See more

immich secustor 2.0.6

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.279cc1623323d
coreutils@9.7-3
no fix listed

Open the chart page →

3,151
viya4-home-dir-builderselerityVerified publisher1.1.01 of 2See more

viya4-home-dir-builder selerity 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/python:3.12-slim2f17fc044b57
coreutils@9.7-3
no fix listed

Open the chart page →

628
sentry-k8ssentry-k8sVerified publisher1.4.15 of 11See more

sentry-k8s sentry-k8s 1.4.1

5 of the 11 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
library/postgres:16f1c3376c26f2
coreutils@9.7-3
no fix listed
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
coreutils@9.1-1
no fix listed
ghcr.io/getsentry/snuba:26.7.210f8d164109b
coreutils@9.7-3
no fix listed
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
coreutils@9.1-1
no fix listed

Open the chart page →

17,006
seq-input-gelfseq-input-gelfVerified publisher0.3.11 of 2See more

seq-input-gelf seq-input-gelf 0.3.1

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
datalust/seq-input-gelf:3.0.441-x643de34aed5642
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

3,427
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
coreutils@9.1-1
no fix listed
dserio83/velero-watchdog:0.1.8d5deae589229
coreutils@9.1-1
no fix listed

Open the chart page →

11,518
sigscale-csesigscale-cseOfficialVerified publisher1.4.221 of 1See more

sigscale-cse sigscale-cse 1.4.22

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
sigscale/cse:latest67d0c886516b
coreutils@9.1-1
no fix listed

Open the chart page →

2,327
sigscale-ocssigscale-ocsOfficialVerified publisher1.1.171 of 1See more

sigscale-ocs sigscale-ocs 1.1.17

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
sigscale/ocs:latest3c1bdc9732e2
coreutils@9.1-1
no fix listed

Open the chart page →

2,327
mssqlserver-2019simcube1.2.31 of 1See more

mssqlserver-2019 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

6,926
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4

Open the chart page →

2,036

Container images carrying it

2,613 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
coreutils@9.7-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
coreutils@9.1-1
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.