StackRadar

CVE-2025-57822

Medium

Advisory

Published 29 Aug 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.025
84th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
53
deployed by those charts
Fix available
1 of 1
affected package

Next.js Improper Middleware Redirect Handling Leads to SSRF

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
nextnpm3.2.3, 9.3.2, 11.0.1, 12.1.0+29 more14.2.32, 15.4.753
OSV records
GHSA-4342-x723-ch2f

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-57822.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
next@9.3.2
14.2.32

Open the chart page →

3,696
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2025-57822.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
next@15.2.4
15.4.7
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
next@15.2.4
15.4.7
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
next@15.2.4
15.4.7

Open the chart page →

6,994
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-57822.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
next@13.5.11
14.2.32

Open the chart page →

2,789
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2025-57822.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
next@13.2.4
14.2.32

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-57822.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
next@14.2.25
14.2.32

Open the chart page →

5,984

Container images carrying it

53 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
next@12.3.1
14.2.32
3
gradiant/open5gs-webui:2.7.5fbd10c017541
next@3.2.3
14.2.32
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
next@14.2.3
14.2.32
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
next@15.3.1
15.4.7
2
alquimiaai/studio:certification38a1f0341982
next@15.2.4
15.4.7
1
documenso/documenso:v1.8.17f16a9449f18
next@14.2.6
14.2.32
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
next@15.2.3
15.4.7
1
ethpandaops/blobscan:latest7a9ab6370657
next@12.3.1
14.2.32
1
factly/mande-web:0.34.1742355964b0e
next@13.5.3
14.2.32
1
fallenbagel/jellyseerr:latest4538137bc5af
next@14.2.25
14.2.32
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
next@12.3.4
14.2.32
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
next@14.2.2
14.2.32
1
kyso/kyso-front:lateste52595c5c16f
next@13.5.2
14.2.32
1
langgenius/dify-web:0.6.11a2a294743634
next@14.1.0
14.2.32
1
langgenius/dify-web:1.0.0d64914ff0d6d
next@14.2.15
14.2.32
1
linuxserver/overseerr:1.35.06108ed066d4a
next@12.3.4
14.2.32
1
lobehub/lobe-chat:1.96.9da0c21fefcd3
next@15.3.4
15.4.7
1
lsstsqre/squareone:0.4.09ded78e7fe03
next@11.0.1
14.2.32
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
next@12.1.0
14.2.32
1
ondrejsika/parking:latestb1fd497416c8
next@9.3.2
14.2.32
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
next@13.5.3
14.2.32
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
next@15.2.4
15.4.7
1
sigp/siren:v3.0.42c219b04758e
next@14.2.25
14.2.32
1
supabase/studio:20241021-9f9b08326d8070c55e9
next@14.2.13
14.2.32
1
treskon/portrait-ui:DEV-lateste7970783bc8d
next@14.1.3
14.2.32
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
next@14.2.26
14.2.32
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
next@14.1.1
14.2.32
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
next@15.3.4
15.4.7
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
next@13.4.12
14.2.32
1
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
next@13.4.12
14.2.32
1
ghcr.io/ajnart/homarr:lateste103abadfb52
next@13.5.11
14.2.32
1
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
next@14.1.4
14.2.32
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
next@15.2.3
15.4.7
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
next@14.2.25
14.2.32
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
next@15.3.3
15.4.7
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
next@14.2.25
14.2.32
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
next@13.5.6
14.2.32
1
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
next@12.1.6
14.2.32
1
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
next@12.1.6
14.2.32
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
next@13.0.7
14.2.32
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
next@14.2.4
14.2.32
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
next@14.2.5
14.2.32
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
next@14.2.5
14.2.32
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
next@11.0.1
14.2.32
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
next@12.3.4
14.2.32
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
next@15.2.4
15.4.7
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
next@15.2.4
15.4.7
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
next@15.2.4
15.4.7
1
ghcr.io/umami-software/umami:postgresql-v1.39.560fa8875aff8
next@12.3.2
14.2.32
1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
next@13.2.4
14.2.32
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.