CVE-2025-5994
HighAdvisory
Published 16 Jul 2025In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.7
- base score, highest
- EPSS
- 0.002
- 10th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 26
- of 17,781 indexed, latest versions
- Container images
- 38
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: unbound security update
Carried by container images the latest versions of 26 of 17,781 indexed charts deploy, on 38 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| unbounddeb | 1.9.4-2ubuntu1.1, 1.9.4-2ubuntu1.2, 1.13.1-1ubuntu5.8, 1.17.1-2+2 more | 1.13.1-1ubuntu5.11, 1.17.1-2+deb12u3, 1.19.2-1ubuntu3.5 | 14 |
| unboundapk | 1.19.3-r0 | 1.20.0-r2 | 1 |
| unboundrpm | 1.7.3-14.el8, 1.7.3-15.el8, 1.7.3-17.el8, 1.16.2-3.el9_3.5+4 more | 0:1.16.2-5.9.el8_10, 0:1.16.2-19.el9_6.1 | 23 |
- OSV records
- ALPINE-CVE-2025-5994DEBIAN-CVE-2025-5994RHSA-2025:11849RHSA-2025:11884UBUNTU-CVE-2025-5994
- Also known as
- RHSA-2025:12416, RHSA-2025:12929, RHSA-2025:13575, RHSA-2025:13577, USN-7666-1
Charts affected
26 by stars
Container images carrying it
38 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| confluentinc/ | ac776fad95a5 | unbound | 0:1.16.2-5.9.el8_10 | 2 |
| confluentinc/ | cae577096489 | unbound | 0:1.16.2-5.9.el8_10 | 2 |
| boky/ | f3f247fd4252 | unbound | 1.17.1-2+deb12u3 | 1 |
| cockroachdb/ | 983312754620 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| codetogether/ | 4348c8a38752 | unbound | 0:1.16.2-19.el9_6.1 | 1 |
| confluentinc/ | f2975d507a2a | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | 8f1544df1f48 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | 3bf359d5e340 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | 83dbca3efd2a | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | adc392d28a1e | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | c0224a1adf7a | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | dc9b972db002 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | 4bc70a83ca6f | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | b0b7aa26254a | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | 8ec46c27982f | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | ee403d5b9090 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | b651d4b6185a | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | 0bec03c1f3ce | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | 5ca5f3269814 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| confluentinc/ | 78c190f4472c | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| ddosify/ | a43c5155fa1c | unbound | 1.17.1-2+deb12u3 | 1 |
| ddosify/ | 3c11e3182652 | unbound | 1.17.1-2+deb12u3 | 1 |
| ddosify/ | ac323d52bfb4 | unbound | 1.17.1-2+deb12u3 | 1 |
| dellemc/ | 148ada9060a9 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| domainmod/ | 4017bfe4c597 | unbound | 1.17.1-2+deb12u3 | 1 |
| kubeovn/ | 6722b54eb5c0 | unbound | 1.19.2-1ubuntu3.5 | 1 |
| library/ | 4d0bb287d87b | unbound | 1.17.1-2+deb12u3 | 1 |
| mintproject/ | 83aade2c1855 | unbound | no fix listed | 1 |
| mlikiowa/ | 1336a777f9a4 | unbound | 1.13.1-1ubuntu5.11 | 1 |
| socialmediamacroscope/ | 6418f9bdb4d2 | unbound | 1.17.1-2+deb12u3 | 1 |
| socialmediamacroscope/ | b351c21422e6 | unbound | 1.17.1-2+deb12u3 | 1 |
| socialmediamacroscope/ | ca863306314b | unbound | 1.17.1-2+deb12u3 | 1 |
| socialmediamacroscope/ | fa490acac2f8 | unbound | 1.17.1-2+deb12u3 | 1 |
| gcr.io/ | a461dc5cb96a | unbound | 0:1.16.2-19.el9_6.1 | 1 |
| ghcr.io/ | 252613692e5e | unbound | 1.20.0-r2 | 1 |
| quay.io/ | a3b9a07648b6 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| quay.io/ | 89ee6493af89 | unbound | 0:1.16.2-5.9.el8_10 | 1 |
| registry.gitlab.com/ | f6385712935f | unbound | no fix listed | 1 |