StackRadar

CVE-2025-59682

Low

Advisory

Published 1 Oct 2025In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

Django vulnerable to partial directory traversal via archives

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
djangopypi4.2, 4.2.7, 4.2.11, 4.2.15+9 more4.2.25, 5.1.13, 5.2.721
OSV records
GHSA-q95w-c7qg-hrff
Also known as
BIT-django-2025-59682, PYSEC-2026-1296

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
django@4.2.22
4.2.25

Open the chart page →

16,251
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
django@4.2.23
4.2.25

Open the chart page →

27,267
netboxstartechnicaVerified publisher5.1.01 of 4See more

netbox startechnica 5.1.0

1 of the 4 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
django@4.2.11
4.2.25

Open the chart page →

1,650
healthchecksgabe565Verified publisher0.17.01 of 1See more

healthchecks gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
django@5.1.4
5.1.13

Open the chart page →

2,286
psonoankra-chartsVerified publisher1.2.01 of 2See more

psono ankra-charts 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
psono/psono-server:5.0.03b974b43ea03
django@4.2.16
4.2.25

Open the chart page →

2,388
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
django@4.2.21
4.2.25

Open the chart page →

9,971
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
django@5.1.1
5.1.13

Open the chart page →

13,761
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
django@4.2.15
4.2.25

Open the chart page →

10,858
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
django@4.2.23
4.2.25

Open the chart page →

12,397
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
django@5.2.3
5.2.7

Open the chart page →

6,873
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
django@4.2
4.2.25

Open the chart page →

2,236
ddosifyanteonVerified publisher1.7.51 of 13See more

ddosify anteon 1.7.5

1 of the 13 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
django@4.2.11
4.2.25

Open the chart page →

25,669
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
django@5.1.1
5.1.13

Open the chart page →

6,075
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
django@4.2.7
4.2.25
codecov/self-hosted-worker:24.4.1837f546b479b
django@4.2.11
4.2.25

Open the chart page →

24,917
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
django@4.2.18
4.2.25

Open the chart page →

2,183
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
django@4.2.7
4.2.25

Open the chart page →

16,384
ja-shortenerja-shortenerVerified publisher0.1.01 of 2See more

ja-shortener ja-shortener 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
cr0hn/ja-shortener:v0.1.414482d0bc4a1
django@5.2.3
5.2.7

Open the chart page →

2,089
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
django@5.1.10
5.1.13

Open the chart page →

37,942
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-api:latesteae026cc8909
django@4.2.23
4.2.25

Open the chart page →

11,149
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2025-59682.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
4.2.25

Open the chart page →

4,731

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codecov/self-hosted-api:24.4.10475cb1c3136
django@4.2.7
4.2.25
1
codecov/self-hosted-worker:24.4.1837f546b479b
django@4.2.11
4.2.25
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
django@5.2.3
5.2.7
1
datamate/seafile-professional:11.0.202dd66b722464
django@4.2.23
4.2.25
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
django@4.2.11
4.2.25
1
gethue/hue:latest7d5c1b9f8a79
django@4.2.23
4.2.25
1
grafana/oncall:v1.16.5499851658393
django@4.2.22
4.2.25
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
django@4.2
4.2.25
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
django@4.2.11
4.2.25
1
psono/psono-server:5.0.03b974b43ea03
django@4.2.16
4.2.25
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
django@4.2.15
4.2.25
1
sissbruecker/linkding:1.35.00c5dddf0b37c
django@5.1.1
5.1.13
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
django@5.1.10
5.1.13
1
ghcr.io/libretime/libretime-api:latesteae026cc8909
django@4.2.23
4.2.25
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
django@5.1.4
5.1.13
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
django@5.1.1
5.1.13
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
django@4.2.7
4.2.25
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
4.2.25
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
django@4.2.18
4.2.25
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
django@5.2.3
5.2.7
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
django@4.2.21
4.2.25
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.