StackRadar

CVE-2025-55173

Medium

Advisory

Published 29 Aug 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
53
deployed by those charts
Fix available
1 of 1
affected package

Next.js Content Injection Vulnerability for Image Optimization

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
nextnpm3.2.3, 9.3.2, 11.0.1, 12.1.0+29 more14.2.31, 15.4.553
OSV records
GHSA-xv57-4mr9-wg8v

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-55173.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
next@9.3.2
14.2.31

Open the chart page →

3,696
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2025-55173.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
next@15.2.4
15.4.5
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
next@15.2.4
15.4.5
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
next@15.2.4
15.4.5

Open the chart page →

6,994
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-55173.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
next@13.5.11
14.2.31

Open the chart page →

2,789
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2025-55173.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
next@13.2.4
14.2.31

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-55173.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
next@14.2.25
14.2.31

Open the chart page →

5,984

Container images carrying it

53 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
next@15.2.4
15.4.5
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
next@14.2.5
14.2.31
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
next@3.2.3
14.2.31
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.