StackRadar

CVE-2025-59775

High

Advisory

Published 5 Dec 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
2 of 2
affected packages

Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
apache2apk2.4.62-r0, 2.4.63-r42.4.66-r08
apachebitnami2.4.54-157, 2.4.65-12.4.662
OSV records
ALPINE-CVE-2025-59775BIT-apache-2025-59775

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
apache2@2.4.62-r0
2.4.66-r0

Open the chart page →

2,811
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
leantime/leantime:3.3.3ad4bfb0699d3
apache2@2.4.62-r0
2.4.66-r0

Open the chart page →

6,416
phpipamphpipam-helmVerified publisher1.0.122 of 3See more

phpipam phpipam-helm 1.0.12

2 of the 3 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
phpipam/phpipam-cron:v1.7.354468713454e
apache2@2.4.62-r0
2.4.66-r0
phpipam/phpipam-www:v1.7.3ace0efd24830
apache2@2.4.62-r0
2.4.66-r0

Open the chart page →

3,778
smokepingdjjudas21Verified publisher0.1.31 of 1See more

smokeping djjudas21 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.8.2b7f906899cd3
apache2@2.4.62-r0
2.4.66-r0

Open the chart page →

2,053
heimdallegebackVerified publisher2.0.41 of 1See more

heimdall egeback 2.0.4

1 of the 1 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
linuxserver/heimdall:2.6.371597f4461e4
apache2@2.4.62-r0
2.4.66-r0

Open the chart page →

1,664
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.66

Open the chart page →

7,541
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.66

Open the chart page →

7,541
webdavlinuxoid690.1.01 of 1See more

webdav linuxoid69 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
ghcr.io/linuxoid69/webdav:1.26.2-r065bacf19caa7
apache2@2.4.62-r0
2.4.66-r0

Open the chart page →

1,081
matomopetbattle11.0.11 of 2See more

matomo petbattle 11.0.1

1 of the 2 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
apache@2.4.65-1
2.4.66

Open the chart page →

11,061
restic-serverschoolguys-helmcharts0.3.11 of 1See more

restic-server schoolguys-helmcharts 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-59775.

Container imageDigestPackageFixed in
restic/rest-server:0.14.0d2aff06f47eb
apache2@2.4.63-r4
2.4.66-r0

Open the chart page →

2,257

Container images carrying it

10 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.66
2
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
apache@2.4.65-1
2.4.66
1
leantime/leantime:3.3.3ad4bfb0699d3
apache2@2.4.62-r0
2.4.66-r0
1
linuxserver/heimdall:2.6.371597f4461e4
apache2@2.4.62-r0
2.4.66-r0
1
linuxserver/smokeping:2.8.2b7f906899cd3
apache2@2.4.62-r0
2.4.66-r0
1
phpipam/phpipam-cron:v1.7.354468713454e
apache2@2.4.62-r0
2.4.66-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
apache2@2.4.62-r0
2.4.66-r0
1
restic/rest-server:0.14.0d2aff06f47eb
apache2@2.4.63-r4
2.4.66-r0
1
ghcr.io/linuxoid69/webdav:1.26.2-r065bacf19caa7
apache2@2.4.62-r0
2.4.66-r0
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
apache2@2.4.62-r0
2.4.66-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.