StackRadar

CVE-2025-6141

Medium

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,405
of 17,832 indexed, latest versions
Container images
2,403
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2025-6141 affecting package ncurses for versions less than 6.4-3

Carried by container images the latest versions of 2,405 of 17,832 indexed charts deploy, on 2,403 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+12 more5.9+20140118-1ubuntu1+esm7, 6.0+20160213-1ubuntu1+esm7, 6.1-1ubuntu1.18.04.1+esm4, 6.2-0ubuntu2.1+esm2+2 more2,402
ncursesrpm6.4-2.azl36.4-31
OSV records
DEBIAN-CVE-2025-6141UBUNTU-CVE-2025-6141AZL-64139
Also known as
USN-8709-1

Charts affected

2,405 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
ncurses@6.4-4
no fix listed

Open the chart page →

2,751
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
ncurses@6.5+20250216-2
no fix listed

Open the chart page →

1,623
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
ncurses@6.4-4
no fix listed

Open the chart page →

4,628
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2

Open the chart page →

9,357
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
ncurses@6.3-2ubuntu0.2
6.3-2ubuntu0.3

Open the chart page →

8,128

Container images carrying it

2,403 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
elastictranscoder/transcoder:627e21dcb4a0327029e6
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
elastiflow/flow-collector:7.26.0fee67842e16b
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
ncurses@6.5+20250216-2
no fix listed
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
emqx/ecp-ui:2.5.1e33e9816f147
ncurses@6.4-4
no fix listed
1
emqx/emqx:5.8.935b46f7aa7a0
ncurses@6.5+20250216-2
no fix listed
1
emqx/emqx-enterprise:6.3.15ecbf93d04e3
ncurses@6.5+20250216-2+dhi4
no fix listed
1
enclavenetworks/enclave:latest0a99759300d1
ncurses@6.2-0ubuntu2.1
6.2-0ubuntu2.1+esm2
1
engrmth/bnkr:2.1.06d8464e6f0e8
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
envoyproxy/envoy:v1.30.92956bd9de830
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
envoyproxy/envoy:v1.38.4447f857a0146
ncurses@6.3-2ubuntu0.2
6.3-2ubuntu0.3
1
envoyproxy/envoy:v1.31-latestcaa5b411be16
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
envoyproxy/envoy:v1.34-latestcfc0678bc03c
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
envoyproxy/envoy:v1.39.0d59f7f5fa10c
ncurses@6.3-2ubuntu0.2
6.3-2ubuntu0.3
1
envoyproxy/envoy:v1.30.1e596fda6a0ce
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
envoyproxy/envoy:v1.18.2e8b37c1d7578
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
ncurses@6.5+20250216-2
no fix listed
1
erigontech/erigon:v2.61.288706754b627
ncurses@6.4-4
no fix listed
1
erigontech/erigon:latest8cd3fbcbb35d
ncurses@6.4-4
no fix listed
1
erlangsolutions/mongooseim:6.6.0cc5bf032931f
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
escaping/core-keeper-dedicated:latest87fa79255962
ncurses@6.5+20250216-2
no fix listed
1
esphome/esphome:2026.7.44866347cb5b4
ncurses@6.5+20250216-2
no fix listed
1
esphome/esphome:2026.9.09959730a04c7
ncurses@6.5+20250216-2
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
ncurses@6.4-4
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
ncurses@6.4-4
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
ncurses@6.4-4
no fix listed
1
espocrm/espocrm:9.3.101b5a24504ed9
ncurses@6.5+20250216-2
no fix listed
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm7
1
ethersphere/bee:2.2.0a884fd84b72f
ncurses@6.4-4
no fix listed
1
ethersphere/beekeeper:lateste3bc0da9ffde
ncurses@6.4-4
no fix listed
1
ethpandaops/assertoor:latest1efa2fba6711
ncurses@6.5+20250216-2
no fix listed
1
ethpandaops/buildoor:mainb3dc726f8ba5
ncurses@6.5+20250216-2
no fix listed
1
ethpandaops/dora:mastere7c0ed360365
ncurses@6.5+20250216-2
no fix listed
1
ethpandaops/eleel:mainb8f1b707aee0
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
ethpandaops/forky:debian-latestc937f4ba737c
ncurses@6.5+20250216-2
no fix listed
1
ethpandaops/observoor:masterc7e5055defcb
ncurses@6.4-4
no fix listed
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
ncurses@6.5+20250216-2
no fix listed
1
ethpandaops/spamoor:latestc8c6ab0816c4
ncurses@6.5+20250216-2
no fix listed
1
factoriotools/factorio:latest18c07a80cacc
ncurses@6.5+20250216-2
no fix listed
1
factoriotools/factorio:stable4ec5fea2e06b
ncurses@6.5+20250216-2
no fix listed
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
ncurses@6.5+20250216-2
no fix listed
1
falcosecurity/event-generator:latest932956d86c99
ncurses@6.4-4
no fix listed
1
falcosecurity/falco-driver-loader:0.45.0d7d287d4dcee
ncurses@6.4-4
no fix listed
1
federid/webhook:0.1.0fbfb7c6510a7
ncurses@6.4-4
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
ncurses@6.4-4
no fix listed
1
filegator/filegator:latest34bf565a11a4
ncurses@6.5+20250216-2
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.