StackRadar

CVE-2025-59530

High

Advisory

Published 10 Oct 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
61
of 17,781 indexed, latest versions
Container images
54
deployed by those charts
Fix available
1 of 1
affected package

quic-go: Panic occurs when queuing undecryptable packets after handshake completion

Carried by container images the latest versions of 61 of 17,781 indexed charts deploy, on 54 images.

Affected packageAffected versionsFixed inImages
github.com/quic-go/quic-gogolangv0.32.0, v0.33.0, v0.37.5, v0.38.1+20 more0.49.1, 0.54.154
OSV records
GHSA-47m2-4cr7-mhcw
Also known as
GO-2025-4017

Charts affected

61 by stars
ChartLatestAffected imagesRadar Score
cloudflare-tunnelportefaix-hub0.4.01 of 1See more

cloudflare-tunnel portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.8.314d9c6b01b29
github.com/quic-go/quic-go@v0.45.0
0.49.1

Open the chart page →

1,306
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
github.com/quic-go/quic-go@v0.46.0
0.49.1

Open the chart page →

7,084
chainrss30.1.281 of 8See more

chain rss3 0.1.28

1 of the 8 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.49.1

Open the chart page →

8,528
vsl-chainrss30.1.01 of 7See more

vsl-chain rss3 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/quic-go/quic-go@v0.39.3
0.49.1

Open the chart page →

6,044
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.49.1

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.49.1

Open the chart page →

4,610
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.49.1

Open the chart page →

1,239
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/quic-go/quic-go@v0.46.0
0.49.1

Open the chart page →

6,779
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.49.1

Open the chart page →

1,239
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
github.com/quic-go/quic-go@v0.40.1
0.49.1

Open the chart page →

2,336
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-59530.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/quic-go/quic-go@v0.32.0
0.49.1

Open the chart page →

2,015

Container images carrying it

54 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
github.com/quic-go/quic-go@v0.39.0
0.49.1
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/quic-go/quic-go@v0.32.0
0.49.1
1
quay.io/backube/volsync:0.16.00d03a6aad575
github.com/quic-go/quic-go@v0.52.0
0.54.1
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
github.com/quic-go/quic-go@v0.37.5
0.49.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.