StackRadar

CVE-2025-5283

Medium

Advisory

Published 27 May 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
54
deployed by those charts
Fix available
1 of 2
affected packages

libvpx - security update

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 54 images.

Affected packageAffected versionsFixed inImages
libvpxdeb1.5.0-2ubuntu1, 1.7.0-3, 1.7.0-3ubuntu0.18.04.1, 1.8.2-1build1+10 more1.5.0-2ubuntu1.1+esm4, 1.7.0-3ubuntu0.18.04.1+esm3, 1.8.2-1ubuntu0.4, 1.9.0-1+deb11u4+3 more53
mozjs68deb68.6.0-1ubuntu1no fix listed1
OSV records
DEBIAN-CVE-2025-5283UBUNTU-CVE-2025-5283DLA-4201-1
Also known as
DSA-5928-1, USN-7551-1

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4

Open the chart page →

4,105
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4

Open the chart page →

9,616
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4

Open the chart page →

3,958
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libvpx@1.11.0-2ubuntu2.2
1.11.0-2ubuntu2.4

Open the chart page →

9,347
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-5283.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.4

Open the chart page →

14,100

Container images carrying it

54 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ciscolabs/rtsp-client:latesta7b60ec88285
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
3
ciscolabs/rtsp-server:latestb59fc10bb821
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libvpx@1.5.0-2ubuntu1
1.5.0-2ubuntu1.1+esm4
3
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libvpx@1.11.0-2ubuntu2
1.11.0-2ubuntu2.4
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
2
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libvpx@1.8.2-1ubuntu0.2
1.8.2-1ubuntu0.4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
castopod/castopod:1.12.101fd37280cbb2
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libvpx@1.7.0-3ubuntu0.18.04.1
1.7.0-3ubuntu0.18.04.1+esm3
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libvpx@1.7.0-3ubuntu0.18.04.1
1.7.0-3ubuntu0.18.04.1+esm3
1
erlangsolutions/wombatoam:4.1.284680c990147a
libvpx@1.9.0-1
1.9.0-1+deb11u4
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
mozjs68@68.6.0-1ubuntu1
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
jaedb/iris:latest048cfbf58d57
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4
1
jellyfin/jellyfin:10.8.1305a9734d7e83
libvpx@1.9.0-1+deb11u2
1.9.0-1+deb11u4
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4
1
jellyfin/jellyfin:10.10.77ae36aab93ef
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4
1
jellyfin/jellyfin:10.10.696b09723b22f
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4
1
jellyfin/jellyfin:10.8.1ee24f4459a40
libvpx@1.9.0-1
1.9.0-1+deb11u4
1
josh5/unmanic:0.2.64d49c4816260
libvpx@1.11.0-2ubuntu2.2
1.11.0-2ubuntu2.4
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
libvpx@1.9.0-1
1.9.0-1+deb11u4
1
langgenius/dify-api:0.6.11fca918260dd6
libvpx@1.12.0-1+deb12u2
1.12.0-1+deb12u4
1
linuxserver/jellyfin:10.7.72427dde159a2
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
livekit/ingress:v1.2.21ab01641b366
libvpx@1.11.0-2ubuntu2
1.11.0-2ubuntu2.4
1
mlikiowa/napcat-docker:latest1336a777f9a4
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.4
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libvpx@1.7.0-3
1.7.0-3ubuntu0.18.04.1+esm3
1
opea/speecht5:1.0249afad3d268
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4
1
photoprism/photoprism:220629-jammy2954334adbda
libvpx@1.11.0-2ubuntu2
1.11.0-2ubuntu2.4
1
photoprism/photoprism:240711-cefc6fd632ca74
libvpx@1.14.0-1ubuntu2.1
1.14.0-1ubuntu2.2
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.4
1
scrapinghub/splash:3.4.1a5f89bc84606
libvpx@1.7.0-3ubuntu0.18.04.1
1.7.0-3ubuntu0.18.04.1+esm3
1
sismics/docs:v1.10f4b0ef019cf1
libvpx@1.7.0-3ubuntu0.18.04.1
1.7.0-3ubuntu0.18.04.1+esm3
1
stashapp/stash:latest24dbd7607174
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libvpx@1.5.0-2ubuntu1
1.5.0-2ubuntu1.1+esm4
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.4
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libvpx@1.11.0-2ubuntu2.2
1.11.0-2ubuntu2.4
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libvpx@1.8.2-1build1
1.8.2-1ubuntu0.4
1
ghcr.io/linuxoid69/motion:4.7.0-0.1.0f0f000c3fc47
libvpx@1.9.0-1+deb11u3
1.9.0-1+deb11u4
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libvpx@1.7.0-3ubuntu0.18.04.1
1.7.0-3ubuntu0.18.04.1+esm3
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
libvpx@1.9.0-1
1.9.0-1+deb11u4
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u4
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
libvpx@1.9.0-1
1.9.0-1+deb11u4
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libvpx@1.12.0-1+deb12u2
1.12.0-1+deb12u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.