StackRadar

CVE-2025-5283

Medium

Advisory

Published 27 May 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
54
deployed by those charts
Fix available
1 of 2
affected packages

libvpx - security update

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 54 images.

Affected packageAffected versionsFixed inImages
libvpxdeb1.5.0-2ubuntu1, 1.7.0-3, 1.7.0-3ubuntu0.18.04.1, 1.8.2-1build1+10 more1.5.0-2ubuntu1.1+esm4, 1.7.0-3ubuntu0.18.04.1+esm3, 1.8.2-1ubuntu0.4, 1.9.0-1+deb11u4+3 more53
mozjs68deb68.6.0-1ubuntu1no fix listed1
OSV records
DEBIAN-CVE-2025-5283UBUNTU-CVE-2025-5283DLA-4201-1
Also known as
DSA-5928-1, USN-7551-1

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4

Open the chart page →

4,105
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4

Open the chart page →

9,616
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4

Open the chart page →

3,958
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libvpx@1.11.0-2ubuntu2.2
1.11.0-2ubuntu2.4

Open the chart page →

9,347
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.4

Open the chart page →

14,100

Container images carrying it

54 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
libvpx@1.9.0-1
1.9.0-1+deb11u4
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
libvpx@1.9.0-1
1.9.0-1+deb11u4
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.