CVE-2025-58056
LowAdvisory
Published 4 Sept 2025In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 2.0
- base score, highest
- EPSS
- 0.007
- 50th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 307
- of 17,787 indexed, latest versions
- Container images
- 353
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions
Carried by container images the latest versions of 307 of 17,787 indexed charts deploy, on 353 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| netty-codec-httpmaven | 4.0.27.Final, 4.0.52.Final, 4.1.12.Final, 4.1.13.Final+75 more | 4.1.125.Final, 4.2.5.Final | 353 |
- OSV records
- GHSA-fghv-69vj-qj49
Charts affected
307 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| hazelcastwenerme | 5.10.3 | 1See more | — |
| apicurio-registry-sqlwitcom-gmbh | 0.1.0 | 1 of 1See more | 3,424 |
| opendistro-eswitcom-gmbh | 1.13.3 | 1 of 3See more | 5,806 |
| ygdrassil-monitoringygdrassilVerified publisher | 0.4.0 | 1 of 10See more | 9,381 |
| zahori-processzahoriVerified publisher | 1.0.1 | 1 of 1See more | 3,480 |
| zahori-serverzahoriVerified publisher | 1.0.1 | 1 of 2See more | 5,846 |
| keycloakxzaks | 2.2.0 | 1 of 1See more | 6,016 |
Container images carrying it
353 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 58c727cd2e68 | netty-codec-http | 4.1.125.Final | 1 |
| quay.io/ | e9e03b31007c | netty-codec-http | 4.1.125.Final | 1 |
| quay.io/ | 8e928db29ee1 | netty-codec-http | 4.1.125.Final | 1 |