StackRadar

CVE-2025-6021

High

Advisory

Published 12 Jun 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
556
of 17,787 indexed, latest versions
Container images
549
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 556 of 17,787 indexed charts deploy, on 549 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more485
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r064
OSV records
ALPINE-CVE-2025-6021DEBIAN-CVE-2025-6021UBUNTU-CVE-2025-6021
Also known as
USN-7694-1

Charts affected

556 by stars
ChartLatestAffected imagesRadar Score
giteawenerme12.7.02 of 4See more

gitea wenerme 12.7.0

2 of the 4 container images this version deploys carry CVE-2025-6021.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

8,811
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-6021.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

15,230
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-6021.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,624
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-6021.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-6021.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-6021.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,673

Container images carrying it

549 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/codegen:1.058f91683892d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/codegen-ui:1.02bee4eb66f3e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/codetrans:1.0e2436483b73d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/codetrans-ui:1.03ef121f34610
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/docsum:1.03eaa91849512
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/docsum-ui:1.07f854e9bffaf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/guardrails-tgi:1.0262c6048aab8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/guardrails-tgi:latestf68bec6a1271
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/speecht5:1.0249afad3d268
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opea/web-retriever-chroma:1.0fe08165d7770
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opencsghq/csgship-portal:v1.2.1865814dc87a1
libxml2@2.13.4-r5
2.13.9-r0
1
opencsghq/kubectl:latestb6d87e1048c2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
opendatacube/pipelines:wofs-1.225d810e8504b8
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
opendatacube/restcube:latest91870111837c
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
opendatacube/wms:latest1b90cdf68831
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
opendatacube/wps:latest80df355a660b
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.8
1
openelevation/open-elevation:latest82fb21612e86
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
openkm/openkm-ce:6.3.113bc465a7461b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
openproject/hocuspocus:release-338001b288dc1359dfb5
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
openthread/otbr:latestf307f59f6432
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
openvino/model_server:2025.2.11e7cd1d70cc1
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.4
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
libxml2@2.13.4-r5
2.13.9-r0
1
opsmx11/issuegen:v2.1.05c50ca123d88
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm8
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
libxml2@2.13.4-r6
2.13.9-r0
1
owncloud/server:10.15.051d9b74fc2a8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
penpotapp/backend:2.2.147853d9bb9dd
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
penpotapp/exporter:2.2.15c835ffd87ab
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
phan2410/dummy-service:0.0.89c6ed6de26ca
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
photoprism/photoprism:220629-jammy2954334adbda
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
photoprism/photoprism:240711-cefc6fd632ca74
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
1
pk910/powfaucet:v2-stable3dcae6a62896
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm9
1
praravind1801/helmimages:3.0.0f29d637b9ce1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
project2team4/react:latest3ff031a08887
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9
1
razorbladex401/dayz:latest6a4d79248e7d
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
reaper99/recipya:v1.2.27f7ec3aeb88c
libxml2@2.13.4-r3
2.13.9-r0
1
redash/redash:25.8.000d813437db5
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
1
resouer/redis-slave:v2e2f198b49ba7
libxml2@2.9.1+dfsg1-3ubuntu4.4
2.9.1+dfsg1-3ubuntu4.13+esm8
1
resurfaceio/resurface:3.7.84d5cda2f64109
libxml2@2.9.13+dfsg-1ubuntu0.6
2.9.13+dfsg-1ubuntu0.8
1
rocm/k8s-device-plugin:1.31.0.926212c665aab
libxml2@2.13.4-r3
2.13.9-r0
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libxml2@2.9.13+dfsg-1ubuntu0.6
2.9.13+dfsg-1ubuntu0.8
1
saidsef/scapy-containerised:v2025.02f17f7c435891
libxml2@2.13.4-r3
2.13.9-r0
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.