StackRadar

CVE-2025-6141

Medium

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,405
of 17,832 indexed, latest versions
Container images
2,403
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2025-6141 affecting package ncurses for versions less than 6.4-3

Carried by container images the latest versions of 2,405 of 17,832 indexed charts deploy, on 2,403 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+12 more5.9+20140118-1ubuntu1+esm7, 6.0+20160213-1ubuntu1+esm7, 6.1-1ubuntu1.18.04.1+esm4, 6.2-0ubuntu2.1+esm2+2 more2,402
ncursesrpm6.4-2.azl36.4-31
OSV records
DEBIAN-CVE-2025-6141UBUNTU-CVE-2025-6141AZL-64139
Also known as
USN-8709-1

Charts affected

2,405 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
ncurses@6.4-4
no fix listed

Open the chart page →

2,751
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
ncurses@6.5+20250216-2
no fix listed

Open the chart page →

1,623
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
ncurses@6.4-4
no fix listed

Open the chart page →

4,628
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2

Open the chart page →

9,357
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
ncurses@6.3-2ubuntu0.2
6.3-2ubuntu0.3

Open the chart page →

8,128

Container images carrying it

2,403 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
glasskube/operator:0.12.2be5133100d63
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
glpi/glpi:latest7b50172cdb7d
ncurses@6.5+20250216-2
no fix listed
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
ncurses@6.4-4
no fix listed
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
ncurses@6.4-4
no fix listed
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
ncurses@6.4-4
no fix listed
1
google/cloud-sdk:slimcfca8415b7ce
ncurses@6.5+20250216-2
no fix listed
1
gopaddle/gopaddle:5.0435359250b63
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
gopinatht/ovs-plugin-installer:latest632cb2e9c399
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm7
1
gotenberg/gotenberg:8-chromium0d28ae9a9644
ncurses@6.5+20250216-2
no fix listed
1
gotenberg/gotenberg:8.30206a6c708fc6
ncurses@6.5+20250216-2
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
ncurses@6.5+20250216-2
no fix listed
1
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
ncurses@6.4-4
no fix listed
1
gotson/komga:0.99.49b15ea6bfc30
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
gradiant/open5gs-dbctl:0.10.3332031245fce
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
grafana/agent:v0.44.23364714a2f64
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
grafana/alloy:v1.5.101a63f4e032c
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
grafana/alloy:v1.4.306bdcbb51fc2
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
grafana/alloy:v1.18.10f4434c92b3e
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
grafana/alloy:v1.18.0491b0578c049
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
grafana/alloy:v1.16.384b76d56c594
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
grafana/alloy:v1.11.38c7256f412fe
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
grafana/alloy:v1.19.2b8ec653c4423
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
grafana/alloy:v1.14.0f50931848bd8
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
grafana/beyla:1.3.336d07f8d276e
ncurses@6.4-4
no fix listed
1
grafana/fluent-plugin-loki:latest4f0438bdebb5
ncurses@6.4-4
no fix listed
1
grafana/mcp-grafana:1.5.107c6614a8f8b
ncurses@6.4-4
no fix listed
1
grafana/mcp-grafana:0.14.042f541f22063
ncurses@6.4-4
no fix listed
1
grafana/promtail:3.5.165bfae480b57
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
grafana/promtail:3.6.18dcfdf466da0
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
graphprotocol/graph-node:latestb0436347fb24
ncurses@6.4-4
no fix listed
1
graphprotocol/graph-node:v0.37.0f4452cdedd68
ncurses@6.4-4
no fix listed
1
graylog/graylog:6.1.1019de1aff48c2
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
greenkube/greenkube:0.3.00c01932282a4
ncurses@6.4-4
no fix listed
1
grpl/grapple-cli:0.2.127c00aafee6629
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
guacamole/guacamole:1.5.50f62f6d17ab3
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
ncurses@6.4-4
no fix listed
1
gulacedia/web-dvwa-new:v367b467d961ca
ncurses@6.4-4
no fix listed
1
hamidyousefi93/saam-test:latestc34f071f6ed0
ncurses@6.4-4
no fix listed
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
ncurses@6.4-4
no fix listed
1
hamzaarshad10/querypodpy:1.7154f38e8668e
ncurses@6.4-4
no fix listed
1
hansehe/locust:1.1.0bc8e45262bc4
ncurses@6.4-4
no fix listed
1
haohanyang/compass-web:0.5.054f2112602ee
ncurses@6.4-4
no fix listed
1
haohanyang/compass-web:0.1.1e3952b14ae8e
ncurses@6.4-4
no fix listed
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ncurses@6.4-4
no fix listed
1
hassroutyyoussef/accountservice:latest1f01edf1ee0c
ncurses@6.4-4
no fix listed
1
hassroutyyoussef/orderservice:latest2fc3d1617928
ncurses@6.4-4
no fix listed
1
hassroutyyoussef/userservice:lateste0392e2b4a90
ncurses@6.4-4
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.