StackRadar

CVE-2025-5994

High

Advisory

Published 16 Jul 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
26
of 17,781 indexed, latest versions
Container images
38
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: unbound security update

Carried by container images the latest versions of 26 of 17,781 indexed charts deploy, on 38 images.

Affected packageAffected versionsFixed inImages
unbounddeb1.9.4-2ubuntu1.1, 1.9.4-2ubuntu1.2, 1.13.1-1ubuntu5.8, 1.17.1-2+2 more1.13.1-1ubuntu5.11, 1.17.1-2+deb12u3, 1.19.2-1ubuntu3.514
unboundapk1.19.3-r01.20.0-r21
unboundrpm1.7.3-14.el8, 1.7.3-15.el8, 1.7.3-17.el8, 1.16.2-3.el9_3.5+4 more0:1.16.2-5.9.el8_10, 0:1.16.2-19.el9_6.123
OSV records
ALPINE-CVE-2025-5994DEBIAN-CVE-2025-5994RHSA-2025:11849RHSA-2025:11884UBUNTU-CVE-2025-5994
Also known as
RHSA-2025:12416, RHSA-2025:12929, RHSA-2025:13575, RHSA-2025:13577, USN-7666-1

Charts affected

26 by stars
ChartLatestAffected imagesRadar Score
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
unbound@1.16.2-3.el9_3.5
0:1.16.2-19.el9_6.1

Open the chart page →

7,450
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
unbound@1.7.3-15.el8
0:1.16.2-5.9.el8_10

Open the chart page →

107,811
anteonanteonVerified publisher2.6.41 of 13See more

anteon anteon 2.6.4

1 of the 13 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3

Open the chart page →

22,202
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.4.4c0224a1adf7a
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10

Open the chart page →

15,562
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
unbound@1.13.1-1ubuntu5.8
1.13.1-1ubuntu5.11

Open the chart page →

7,405
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.683dbca3efd2a
unbound@1.16.2-5.8.el8_10
0:1.16.2-5.9.el8_10

Open the chart page →

16,449
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3

Open the chart page →

4,249
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
unbound@1.9.4-2ubuntu1.1
no fix listed

Open the chart page →

25,443
aktoakto0.2.02 of 7See more

akto akto 0.2.0

2 of the 7 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10

Open the chart page →

13,613
akto-mini-testing-kafkaakto1.42.12 of 5See more

akto-mini-testing-kafka akto 1.42.1

2 of the 5 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
unbound@1.16.2-5.el8_9.6
0:1.16.2-5.9.el8_10
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
unbound@1.16.2-5.el8_9.6
0:1.16.2-5.9.el8_10

Open the chart page →

6,397
akto-protectionakto0.1.02 of 4See more

akto-protection akto 0.1.0

2 of the 4 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10

Open the chart page →

11,285
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3

Open the chart page →

25,669
app-mobilityappmo0.1.01 of 5See more

app-mobility appmo 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
unbound@1.7.3-17.el8
0:1.16.2-5.9.el8_10

Open the chart page →

12,521
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10

Open the chart page →

14,728
dnsbl-exporterchristianhuthVerified publisher1.4.01 of 2See more

dnsbl-exporter christianhuth 1.4.0

1 of the 2 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.7.0-rc3252613692e5e
unbound@1.19.3-r0
1.20.0-r2

Open the chart page →

1,459
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
unbound@1.7.3-17.el8
0:1.16.2-5.9.el8_10

Open the chart page →

5,958
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
confluentinc/cp-zookeeper:6.1.078c190f4472c
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10

Open the chart page →

58,857
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3

Open the chart page →

7,141
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3

Open the chart page →

5,959
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
unbound@1.19.2-1ubuntu3.4
1.19.2-1ubuntu3.5

Open the chart page →

4,940
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
unbound@1.9.4-2ubuntu1.2
no fix listed

Open the chart page →

43,341
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
unbound@1.7.3-15.el8
0:1.16.2-5.9.el8_10

Open the chart page →

7,775
smilencsaVerified publisher1.1.04 of 23See more

smile ncsa 1.1.0

4 of the 23 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
unbound@1.17.1-2
1.17.1-2+deb12u3
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
unbound@1.17.1-2
1.17.1-2+deb12u3
socialmediamacroscope/preprocessing:0.1.3ca863306314b
unbound@1.17.1-2
1.17.1-2+deb12u3
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
unbound@1.17.1-2
1.17.1-2+deb12u3

Open the chart page →

109,294
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
unbound@1.16.2-8.el9_5.1
0:1.16.2-19.el9_6.1

Open the chart page →

9,355
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10

Open the chart page →

5,269
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-5994.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
unbound@1.7.3-15.el8
0:1.16.2-5.9.el8_10

Open the chart page →

28,165

Container images carrying it

38 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
2
boky/postfix:4.4.0f3f247fd4252
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3
1
cockroachdb/cockroach-operator:v2.1.0983312754620
unbound@1.7.3-15.el8
0:1.16.2-5.9.el8_10
1
codetogether/codetogether:latest4348c8a38752
unbound@1.16.2-3.el9_3.5
0:1.16.2-19.el9_6.1
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
unbound@1.7.3-17.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
unbound@1.16.2-5.8.el8_10
0:1.16.2-5.9.el8_10
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
unbound@1.16.2-5.el8_9.6
0:1.16.2-5.9.el8_10
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-kafka:7.5.1dc9b972db002
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
unbound@1.16.2-5.el8
0:1.16.2-5.9.el8_10
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
unbound@1.16.2-5.el8_9.6
0:1.16.2-5.9.el8_10
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
unbound@1.7.3-14.el8
0:1.16.2-5.9.el8_10
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3
1
ddosify/selfhosted_backend:3.2.93c11e3182652
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
unbound@1.7.3-17.el8
0:1.16.2-5.9.el8_10
1
domainmod/domainmod:4.23.04017bfe4c597
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
unbound@1.19.2-1ubuntu3.4
1.19.2-1ubuntu3.5
1
library/varnish:7.5.04d0bb287d87b
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u3
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
unbound@1.9.4-2ubuntu1.2
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
unbound@1.13.1-1ubuntu5.8
1.13.1-1ubuntu5.11
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
unbound@1.17.1-2
1.17.1-2+deb12u3
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
unbound@1.17.1-2
1.17.1-2+deb12u3
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
unbound@1.17.1-2
1.17.1-2+deb12u3
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
unbound@1.17.1-2
1.17.1-2+deb12u3
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
unbound@1.16.2-8.el9_5.1
0:1.16.2-19.el9_6.1
1
ghcr.io/luzilla/unbound:v0.7.0-rc3252613692e5e
unbound@1.19.3-r0
1.20.0-r2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
unbound@1.7.3-15.el8
0:1.16.2-5.9.el8_10
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
unbound@1.7.3-15.el8
0:1.16.2-5.9.el8_10
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
unbound@1.9.4-2ubuntu1.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.