CVE-2025-58189
MediumAdvisory
Published 29 Oct 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.004
- 37th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,505
- of 17,828 indexed, latest versions
- Container images
- 3,957
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
ALPN negotiation error contains attacker controlled information in crypto/tls
Carried by container images the latest versions of 3,505 of 17,828 indexed charts deploy, on 3,957 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+165 more | 1.24.8 | 3,957 |
- OSV records
- DEBIAN-CVE-2025-58189GO-2025-4008
- Also known as
- BIT-golang-2025-58189
Charts affected
3,505 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| zahori-moonzahoriVerified publisher | 1.0.1 | 3 of 3See more | 2,908 |
| zahori-schedulerzahoriVerified publisher | 1.0.1 | 1 of 1See more | 2,482 |
| posthogzeet | 0.23.2 | 1 of 9See more | 3,702 |
| zookeeper-exporterzookeeper-exporter | 0.1.0 | 1 of 1See more | 1,249 |
| zoo-project-druzoo-projectOfficialVerified publisher | 0.10.4 | 1 of 6See more | 8,105 |
Container images carrying it
3,957 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| prom/ | 4f6c47e39a90 | stdlib | 1.24.8 | 1 |
| prom/ | 5880ec936055 | stdlib | 1.24.8 | 1 |
| prom/ | b440bc0e8aa5 | stdlib | 1.24.8 | 1 |
| prom/ | cd134bd4fca0 | stdlib | 1.24.8 | 1 |
| prom/ | f7ffebdd428b | stdlib | 1.24.8 | 1 |
| prom/ | 28fe26c8b8b1 | stdlib | 1.24.8 | 1 |
| prom/ | 3496e0f85943 | stdlib | 1.24.8 | 1 |
| prom/ | 9d226d7de223 | stdlib | 1.24.8 | 1 |
| prom/ | 61d866e93b56 | stdlib | 1.24.8 | 1 |
| prom/ | 8be660470961 | stdlib | 1.24.8 | 1 |
| promzeus/ | 82f6d56e280b | stdlib | 1.24.8 | 1 |
| pschiffe/ | 37ebba8c2b8f | stdlib | 1.24.8 | 1 |
| pschiffe/ | d196c796cafb | stdlib | 1.24.8 | 1 |
| pschiffe/ | a227d41bc665 | stdlib | 1.24.8 | 1 |
| pysga1996/ | 3af6d0c7db19 | stdlib | 1.24.8 | 1 |
| qichenxu4pd/ | d758d41d9c6b | stdlib | 1.24.8 | 1 |
| qmcgaw/ | 2b42bfa04675 | stdlib | 1.24.8 | 1 |
| qonstrukt/ | 089af7925aa1 | stdlib | 1.24.8 | 1 |
| qoveryrd/ | b30a9398a83c | stdlib | 1.24.8 | 1 |
| quiq/ | 91281da47036 | stdlib | 1.24.8 | 1 |
| qumine/ | f2c8a2148381 | stdlib | 1.24.8 | 1 |
| qumine/ | c0b650d51132 | stdlib | 1.24.8 | 1 |
| rabbitmqoperator/ | 231e7ce0e905 | stdlib | 1.24.8 | 1 |
| rabbitmqoperator/ | 8651dd3cec51 | stdlib | 1.24.8 | 1 |
| rahulbhiwagade122/ | 08490b70998c | stdlib | 1.24.8 | 1 |
| ralexstokes/ | c0d4bbefd31f | stdlib | 1.24.8 | 1 |
| rancher/ | 2581c5490bab | stdlib | 1.24.8 | 1 |
| rancher/ | 7d0f41b72eb7 | stdlib | 1.24.8 | 1 |
| rancher/ | 8c2599ecfca8 | stdlib | 1.24.8 | 1 |
| rancher/ | eaa270df79cc | stdlib | 1.24.8 | 1 |
| rancher/ | 85a0d1148784 | stdlib | 1.24.8 | 1 |
| rancher/ | 9289da488b07 | stdlib | 1.24.8 | 1 |
| rancher/ | 9b9148811700 | stdlib | 1.24.8 | 1 |
| rancher/ | d5999b20a1b1 | stdlib | 1.24.8 | 1 |
| rancher/ | e34c88ae0aff | stdlib | 1.24.8 | 1 |
| rancher/ | febfd0517838 | stdlib | 1.24.8 | 1 |
| rancher/ | 0842af6afcdf | stdlib | 1.24.8 | 1 |
| rancher/ | 934863015367 | stdlib | 1.24.8 | 1 |
| rancher/ | deac027820ae | stdlib | 1.24.8 | 1 |
| rancher/ | a41cd716c412 | stdlib | 1.24.8 | 1 |
| rancher/ | 3126395b966c | stdlib | 1.24.8 | 1 |
| raspbernetes/ | a552705225fd | stdlib | 1.24.8 | 1 |
| rclone/ | 08e1af3c8814 | stdlib | 1.24.8 | 1 |
| rclone/ | 1e6eeabddc01 | stdlib | 1.24.8 | 1 |
| rclone/ | a693c46a6b8b | stdlib | 1.24.8 | 1 |
| rclone/ | f2fc45c8bc57 | stdlib | 1.24.8 | 1 |
| reaper99/ | 7f7ec3aeb88c | stdlib | 1.24.8 | 1 |
| redislabs/ | ecb101af0506 | stdlib | 1.24.8 | 1 |
| redislabs/ | 33561794c5c8 | stdlib | 1.24.8 | 1 |
| regclient/ | 3d8d8e40afb7 | stdlib | 1.24.8 | 1 |