StackRadar

CVE-2025-5278

Medium

Advisory

Published 27 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,554
of 17,821 indexed, latest versions
Container images
2,613
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: coreutils security update

Carried by container images the latest versions of 2,554 of 17,821 indexed charts deploy, on 2,613 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb8.21-1ubuntu5, 8.21-1ubuntu5.1, 8.21-1ubuntu5.4, 8.25-2ubuntu2+17 more8.32-4.1ubuntu1.4, 9.4-3ubuntu6.3, 9.7-3ubuntu2.12,440
coreutilsrpm8.29-lp151.3.3, 8.29-lp152.4.7, 8.32-32.el9, 8.32-34.el9+7 more0:8.32-41.el9_8, 0:9.5-8.el10_2, 8.32-150400.9.9.1, 9.4-7+1 more155
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu24, 9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.177
OSV records
DEBIAN-CVE-2025-5278RHSA-2026:28911RHSA-2026:33124RLSA-2026:28911UBUNTU-CVE-2025-5278AZL-93060openSUSE-SU-2025:15327-1SUSE-SU-2025:02362-1
Also known as
USN-8697-1

Charts affected

2,554 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
coreutils@9.1-1
no fix listed

Open the chart page →

2,710
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
coreutils@9.7-3
no fix listed

Open the chart page →

1,593
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
coreutils@8.28-1ubuntu1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
coreutils@8.30-3ubuntu2
no fix listed

Open the chart page →

9,297
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-5278.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
coreutils@8.32-4.1ubuntu1.3
8.32-4.1ubuntu1.4

Open the chart page →

7,966

Container images carrying it

2,613 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v2.14.115fc69e31c755
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
2
quay.io/keycloak/keycloak:26.1.4044a457e0498
coreutils@8.32-36.el9
0:8.32-41.el9_8
2
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
coreutils@8.32-39.el9
0:8.32-41.el9_8
2
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
coreutils@8.32-39.el9
0:8.32-41.el9_8
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
coreutils@8.32-36.el9
0:8.32-41.el9_8
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
coreutils@8.32-39.el9
0:8.32-41.el9_8
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
coreutils@9.1-1
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
coreutils@9.1-1
no fix listed
1
5200710/hadoop:3.2.3-java8092d3088a5fb
coreutils@8.30-3ubuntu2
no fix listed
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
coreutils@8.28-1ubuntu1
no fix listed
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
coreutils@9.7-3
no fix listed
1
aboogie/login_test_backend:new9c41a4483ac8
coreutils@9.1-1
no fix listed
1
actualbudget/actual-server:25.3.158fecd9088b7
coreutils@9.1-1
no fix listed
1
adamzammit/limesurvey:7.1.2b642712ce9a6
coreutils@9.7-3
no fix listed
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
coreutils@8.30-3ubuntu2
no fix listed
1
agentarea/agentarea-api:latest9e15e16fa758
coreutils@9.7-3
no fix listed
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
coreutils@9.1-1
no fix listed
1
agentarea/agentarea-worker:latest1e5cb68ee77a
coreutils@9.7-3
no fix listed
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
aibrix/metadata-service:v0.7.063fb81a64377
coreutils@9.1-1
no fix listed
1
airbyte/manifest-server:7.28.2deec511b51c3
coreutils@9.1-1
no fix listed
1
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
coreutils@8.32-34.el9
0:8.32-41.el9_8
1
airbyte/pod-sweeper:1.5.198d2c39d512e
coreutils@9.1-1
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
coreutils@8.30-3ubuntu2
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
coreutils@9.1-1
no fix listed
1
akeyless/base:latest759e4289fae8
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
1
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
coreutils@9.7-3
no fix listed
1
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
coreutils@9.7-3
no fix listed
1
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
coreutils@9.7-3
no fix listed
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
aktosecurity/data-ingestion-service213aded7adc5
coreutils@9.4-3ubuntu6.1
9.4-3ubuntu6.3
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
alazidis/stornx:1.1.1602d4f7f090c
coreutils@9.1-1
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
coreutils@9.1-1
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
coreutils@8.28-1ubuntu1
no fix listed
1
alquimiaai/studio:certification38a1f0341982
coreutils@8.32-39.el9
0:8.32-41.el9_8
1
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
coreutils@9.4-3ubuntu6.2
9.4-3ubuntu6.3
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
coreutils@9.4-3ubuntu6
9.4-3ubuntu6.3
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
coreutils@8.32-4.1ubuntu1
8.32-4.1ubuntu1.4
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
coreutils@8.32-4.1ubuntu1.2
8.32-4.1ubuntu1.4
1
andrianrf/backoffice-be:latest6036614803d4
coreutils@8.32-34.el9
0:8.32-41.el9_8
1
andrianrf/iso-server:latest7da47f525c7d
coreutils@8.32-34.el9
0:8.32-41.el9_8
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.