StackRadar

CVE-2025-58183

High

Advisory

Published 29 Oct 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,574
of 17,844 indexed, latest versions
Container images
4,008
deployed by those charts
Fix available
8 of 9
affected packages

Red Hat Security Advisory: skopeo security update

Carried by container images the latest versions of 3,574 of 17,844 indexed charts deploy, on 4,008 images.

Affected packageAffected versionsFixed inImages
skopeorpm2:1.11.2-0.1.el9, 2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.5-5.module+el8.10.0+23772+e5018371, 2:1.20.0-2.el9_72
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-82.module+el8.10.0+23772+e50183711
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+23772+e50183711
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+23772+e50183711
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+23772+e50183711
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc4:1.2.9-2.module+el8.10.0+23772+e50183711
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+23772+e50183711
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+165 more1.24.84,008
OSV records
RHSA-2025:23326RHSA-2025:23374DEBIAN-CVE-2025-58183GO-2025-4014
Also known as
BIT-golang-2025-58183, RHSA-2026:5234

Charts affected

3,574 by stars
ChartLatestAffected imagesRadar Score
secretssecrets-proxy1.0.61 of 1See more

secrets secrets-proxy 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
udhos/secrets:1.0.6daa2b4eaac09
stdlib@go1.24.2
1.24.8

Open the chart page →

1,181
secret-syncsecret-syncVerified publisher0.1.111 of 1See more

secret-sync secret-sync 0.1.11

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
csepulvedab/secret-sync:0.5227a6f2b0ff8
stdlib@go1.19.4
1.24.8

Open the chart page →

1,446
cloudflaredsectionmeVerified publisher2022.3.41 of 1See more

cloudflared sectionme 2022.3.4

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
stdlib@go1.17.1
1.24.8

Open the chart page →

2,444
influxdb_exportersectionmeVerified publisher0.0.21 of 1See more

influxdb_exporter sectionme 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
quay.io/prometheus/influxdb-exporter:v0.10.03854d8af7bd4
stdlib@go1.18.3
1.24.8

Open the chart page →

923
security-smellssecurity-smells0.1.01 of 1See more

security-smells security-smells 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
durellirsd/security-smells-api:v17398aca4fc2e
stdlib@go1.22.4
1.24.8

Open the chart page →

1,446
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.24.8

Open the chart page →

20,585
seldon-core-analyticsseldon1.17.14 of 8See more

seldon-core-analytics seldon 1.17.1

4 of the 8 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.24.8
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.24.8
prom/prometheus:v2.18.15880ec936055
stdlib@go1.14.2
1.24.8
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.24.8

Open the chart page →

10,760
postgresself-hosters-by-nightVerified publisher0.14.31 of 1See more

postgres self-hosters-by-night 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.24.8

Open the chart page →

2,553
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest98ad9bc7a2a0
stdlib@go1.23.3
1.24.8

Open the chart page →

1,426
s3managersergeyshevch0.1.01 of 1See more

s3manager sergeyshevch 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
quay.io/sergeyshevch/s3manager:feature_refactoringff59fcdf44eb
stdlib@go1.18
1.24.8

Open the chart page →

2,159
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
stdlib@go1.21.8
1.24.8

Open the chart page →

3,381
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
stdlib@go1.24.1
1.24.8

Open the chart page →

3,498
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
stdlib@go1.19.11
1.24.8

Open the chart page →

4,425
service-binding-operatorservice-binding-operator-helm-chart1.4.11 of 1See more

service-binding-operator service-binding-operator-helm-chart 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
quay.io/redhat-developer/servicebinding-operatordigest-pinned16286ac84ddd
stdlib@go1.20.6
1.24.8

Open the chart page →

799
serviceexampleserviceexample0.1.03 of 5See more

serviceexample serviceexample 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/nats:2.9.20-alpined6c6ae7df4a0
stdlib@go1.19.11
1.24.8
natsio/nats-box:0.13.559cf2e949181
stdlib@go1.19.5
1.24.8
natsio/nats-server-config-reloader:0.11.0c3a755eab2cc
stdlib@go1.20.5
1.24.8

Open the chart page →

5,471
service-exampleservice-example-10.1.05 of 7See more

service-example service-example-1 0.1.0

5 of the 7 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.24.8
library/nats:2.9.11-alpineccbe811b8575
stdlib@go1.19.4
1.24.8
natsio/nats-box:0.13.3c507bd7e3831
stdlib@go1.19.4
1.24.8
natsio/nats-server-config-reloader:0.8.06bdaceb63aa5
stdlib@go1.19.4
1.24.8
natsio/prometheus-nats-exporter:0.10.1bce728062c4f
stdlib@go1.19.3
1.24.8

Open the chart page →

8,449
serviceexampleserviceexample-chart0.3.01 of 4See more

serviceexample serviceexample-chart 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.24.8

Open the chart page →

3,457
serviceexampleservice-example-helm-chart0.1.01 of 4See more

serviceexample service-example-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.24.8

Open the chart page →

1,613
service-exampleservice-example-jt0.1.11 of 9See more

service-example service-example-jt 0.1.1

1 of the 9 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.24.8

Open the chart page →

7,520
ccx-monitoringseveralnines0.6.214 of 7See more

ccx-monitoring severalnines 0.6.21

4 of the 7 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.120.0a1cb2f3dfd45
stdlib@go1.24.4
1.24.8
victoriametrics/vmalert:v1.96.0150cd08fde94
stdlib@go1.21.5
1.24.8
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.24.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
stdlib@go1.20.10
1.24.8

Open the chart page →

7,823
apache-shardingsphere-operator-chartsshardingsphere0.3.01 of 2See more

apache-shardingsphere-operator-charts shardingsphere 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
stdlib@go1.19.10
1.24.8

Open the chart page →

1,701
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.24.8

Open the chart page →

3,230
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.24.8

Open the chart page →

20,585
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
stdlib@go1.24.6
1.24.8

Open the chart page →

2,869
backendsignalen4.25.02 of 4See more

backend signalen 4.25.0

2 of the 4 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.24.8
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.24.8

Open the chart page →

11,388
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.24.8

Open the chart page →

2,177
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
stdlib@go1.24.6
1.24.8

Open the chart page →

1,319
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.24.8

Open the chart page →

2,978
ctlogsigstoreVerified publisher0.2.683 of 4See more

ctlog sigstore 0.2.68

3 of the 4 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
stdlib@go1.25.0
1.24.8
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
stdlib@go1.25.0
1.24.8
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
stdlib@go1.25.0
1.24.8

Open the chart page →

2,779
trilliansigstoreVerified publisher0.3.202 of 5See more

trillian sigstore 0.3.20

2 of the 5 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.24.8
ghcr.io/sigstore/scaffolding/createdbdigest-pinned3cee6c78973b
stdlib@go1.25.0
1.24.8

Open the chart page →

2,789
tsasigstoreVerified publisher2.1.31 of 1See more

tsa sigstore 2.1.3

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
ghcr.io/sigstore/timestamp-server:v2.1.08637f0482ed1
stdlib@go1.25.1
1.24.8

Open the chart page →

610
tufsigstoreVerified publisher0.1.321 of 1See more

tuf sigstore 0.1.32

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/serverdigest-pinnedae8eb69c7b70
stdlib@go1.25.0
1.24.8

Open the chart page →

773
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
stdlib@go1.19.6
1.24.8

Open the chart page →

2,873
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
stdlib@go1.21.4
1.24.8

Open the chart page →

2,345
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.24.8

Open the chart page →

2,383
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
stdlib@go1.22.3
1.24.8

Open the chart page →

1,151
signpostsikalabs0.5.01 of 1See more

signpost sikalabs 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
sikalabs/signpost:v0.7.0c8b0e21d61b4
stdlib@go1.24.6
1.24.8

Open the chart page →

317
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
stdlib@go1.20.5
1.24.8

Open the chart page →

1,510
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
stdlib@go1.18.10
1.24.8

Open the chart page →

2,173
mongosqldsinextraVerified publisher0.3.71 of 1See more

mongosqld sinextra 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
stdlib@go1.23.8
1.24.8

Open the chart page →

2,728
mongosyncsinextraVerified publisher0.4.01 of 1See more

mongosync sinextra 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
stdlib@go1.24.4
1.24.8

Open the chart page →

3,001
pgbouncersinextraVerified publisher0.17.01 of 1See more

pgbouncer sinextra 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
stdlib@go1.24.6
1.24.8

Open the chart page →

2,109
talos-backupsinextraVerified publisher0.1.21 of 1See more

talos-backup sinextra 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
ghcr.io/siderolabs/talos-backup:v0.1.0-beta.203a71e140f1d
stdlib@go1.23.0
1.24.8

Open the chart page →

909
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
stdlib@go1.21.11
1.24.8

Open the chart page →

2,471
mariadbsitepilot1.0.31 of 1See more

mariadb sitepilot 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
library/mariadb:10.640153feb479c
stdlib@go1.24.6
1.24.8

Open the chart page →

2,897
mimirskyloud-helm-chartsVerified publisher5.5.14 of 5See more

mimir skyloud-helm-charts 5.5.1

4 of the 5 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
grafana/mimir:r292-5f018727476e456c738
stdlib@go1.22.3
1.24.8
grafana/rollout-operator:v0.14.03409edfb45c7
stdlib@go1.22.1
1.24.8
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
stdlib@go1.21.1
1.24.8
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
stdlib@go1.21.1
1.24.8

Open the chart page →

10,961
tailscale-operatorskyloud-helm-chartsVerified publisher1.70.31 of 1See more

tailscale-operator skyloud-helm-charts 1.70.3

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
tailscale/k8s-operator:v1.70.08edd06cf5bac
stdlib@go1.22.5
1.24.8

Open the chart page →

1,042
skypilot-prometheus-serverskypilotVerified publisher0.11.13 of 3See more

skypilot-prometheus-server skypilot 0.11.1

3 of the 3 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.83.078aec597d87a
stdlib@go1.24.3
1.24.8
quay.io/prometheus/prometheus:v3.4.19abc6cf6aea7
stdlib@go1.24.3
1.24.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
stdlib@go1.23.5
1.24.8

Open the chart page →

2,344
config-connector-templaterslamdev0.0.51 of 1See more

config-connector-templater slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
slamdev/config-connector-templater:0.0.3a234541c9fa8
stdlib@go1.16.5
1.24.8

Open the chart page →

2,106
flux-notifierslamdev0.0.71 of 1See more

flux-notifier slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2025-58183.

Container imageDigestPackageFixed in
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.24.8

Open the chart page →

2,017

Container images carrying it

4,008 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.