StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,554
of 17,821 indexed, latest versions
Container images
2,613
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,554 of 17,821 indexed charts deploy, on 2,613 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,440
coreutilsrpm8.29-lp151.3.3, 8.29-lp152.4.7, 8.32-32.el9, 8.32-34.el9+7 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more155
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.177
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,554 by stars
ChartLatestAffected imagesRadar Score
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
coreutils@9.1-1
no fix listed

Open the chart page →

4,565
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
coreutils@9.1-1
no fix listed

Open the chart page →

4,875
gitlab-omnibusslamdev0.1.61 of 2See more

gitlab-omnibus slamdev 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
daedalusproject/base_kubectl:latest6f72b5119eda
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

2,872
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
coreutils@9.1-1
no fix listed

Open the chart page →

2,915
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
coreutils@8.30-3ubuntu2
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
coreutils@8.30-3ubuntu2
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

251,257
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
coreutils@9.7-3
no fix listed
valkey/valkey:8.1.61f84517eca8e
coreutils@9.7-3
no fix listed

Open the chart page →

2,946
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
coreutils@9.7-3
no fix listed

Open the chart page →

14,542
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/redis:8.10.18a1efc5f4795
coreutils@9.7-3
no fix listed

Open the chart page →

1,936
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
coreutils@9.7-3
no fix listed

Open the chart page →

7,365
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
coreutils@9.1-1
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
coreutils@9.1-1
no fix listed

Open the chart page →

4,703
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
coreutils@9.1-1
no fix listed

Open the chart page →

5,689
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
coreutils@9.1-1
no fix listed

Open the chart page →

10,239
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4

Open the chart page →

2,671
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
coreutils@9.1-1
no fix listed

Open the chart page →

4,660
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

13,622
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

102,725
stornxstornxVerified publisher1.1.14 of 9See more

stornx stornx 1.1.1

4 of the 9 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
alazidis/stornx:1.1.1602d4f7f090c
coreutils@9.1-1
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
quay.io/kiali/kiali:v2.23.07652b1285f50
coreutils@8.32-39.el9
0:8.32-41.el9_8

Open the chart page →

11,773
consolestratosVerified publisher4.4.04 of 4See more

console stratos 4.4.0

4 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
splatform/stratos-config-init:4.4.0-bc65c315c9f4edaca0af7
coreutils@8.29-lp152.4.7
9.7-3.1
splatform/stratos-console:4.4.0-bc65c315c406b95a98b4a
coreutils@8.29-lp152.4.7
9.7-3.1
splatform/stratos-jetstream:4.4.0-bc65c315c886311c331b9
coreutils@8.29-lp152.4.7
9.7-3.1
splatform/stratos-mariadb:4.4.0-bc65c315c28560b598108
coreutils@8.29-lp152.4.7
9.7-3.1

Open the chart page →

22,735
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3

Open the chart page →

2,941
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
kong/kong:3.9.16addf50e6bd8
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
supabase/edge-runtime:v1.74.02781daf92394
coreutils@9.1-1
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
coreutils@9.1-1
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
coreutils@9.1-1
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
coreutils@9.1-1
no fix listed

Open the chart page →

17,986
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4

Open the chart page →

2,162
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
coreutils@9.7-3
no fix listed

Open the chart page →

3,304
mumblesyntaxerror404Verified publisher1.0.51 of 1See more

mumble syntaxerror404 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3

Open the chart page →

2,176
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
coreutils@9.7-3
no fix listed

Open the chart page →

1,593
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
coreutils@9.7-3
no fix listed

Open the chart page →

1,593
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/haproxy:3.2ad870ce41292
coreutils@9.7-3
no fix listed

Open the chart page →

583
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
coreutils@9.7-3+dhi3
no fix listed

Open the chart page →

2,411
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
coreutils@9.1-1
no fix listed

Open the chart page →

9,069
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
coreutils@9.1-1
no fix listed

Open the chart page →

9,069
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
coreutils@9.7-3
no fix listed

Open the chart page →

13,745
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3

Open the chart page →

4,105
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
coreutils@9.7-3
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
coreutils@9.7-3
no fix listed

Open the chart page →

5,416
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4

Open the chart page →

1,931
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4

Open the chart page →

3,982
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4

Open the chart page →

3,982
u-storeunifieVerified publisher1.2.01 of 1See more

u-store unifie 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
coreutils@9.1-1
no fix listed

Open the chart page →

15,342
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
coreutils@9.1-1
no fix listed

Open the chart page →

12,819
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
coreutils@9.7-3
no fix listed
taigaio/taiga-protected:latestfd4568a97a59
coreutils@9.7-3
no fix listed

Open the chart page →

9,103
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
coreutils@9.1-1
no fix listed

Open the chart page →

4,459
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
coreutils@9.7-3
no fix listed

Open the chart page →

2,292
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3

Open the chart page →

4,105
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
coreutils@9.1-1
no fix listed

Open the chart page →

5,213
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4

Open the chart page →

7,098
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
coreutils@9.7-3
no fix listed
opennode/waldur-mastermind:8.1.24c82b15d9042
coreutils@9.7-3
no fix listed

Open the chart page →

4,599
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
coreutils@8.28-1ubuntu1
no fix listed

Open the chart page →

16,053
reflectorwener10.0.651 of 1See more

reflector wener 10.0.65

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
emberstack/kubernetes-reflector:10.0.6551dbd5880929
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3

Open the chart page →

723
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
coreutils@8.21-1ubuntu5
no fix listed

Open the chart page →

41,495
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

56,318
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
coreutils@9.7-3
no fix listed

Open the chart page →

7,847
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
coreutils@9.7-3
no fix listed

Open the chart page →

8,524

Container images carrying it

2,613 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
coreutils@9.7-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
coreutils@9.1-1
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.