StackRadar

CVE-2025-6141

Medium

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,405
of 17,832 indexed, latest versions
Container images
2,403
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2025-6141 affecting package ncurses for versions less than 6.4-3

Carried by container images the latest versions of 2,405 of 17,832 indexed charts deploy, on 2,403 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+12 more5.9+20140118-1ubuntu1+esm7, 6.0+20160213-1ubuntu1+esm7, 6.1-1ubuntu1.18.04.1+esm4, 6.2-0ubuntu2.1+esm2+2 more2,402
ncursesrpm6.4-2.azl36.4-31
OSV records
DEBIAN-CVE-2025-6141UBUNTU-CVE-2025-6141AZL-64139
Also known as
USN-8709-1

Charts affected

2,405 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
ncurses@6.4-4
no fix listed

Open the chart page →

2,751
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
ncurses@6.5+20250216-2
no fix listed

Open the chart page →

1,623
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
ncurses@6.4-4
no fix listed

Open the chart page →

4,628
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2

Open the chart page →

9,357
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-6141.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
ncurses@6.3-2ubuntu0.2
6.3-2ubuntu0.3

Open the chart page →

8,128

Container images carrying it

2,403 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mariadb:10.6.15e22328f4d714
ncurses@6.2-0ubuntu2.1
6.2-0ubuntu2.1+esm2
1
library/mariadb:10.9.4fbb8456ebdb1
ncurses@6.3-2
6.3-2ubuntu0.3
1
library/mariadb:11.7.2fcc7fcd7114a
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
library/matomo:5.1.2-apache2415789e1602
ncurses@6.4-4
no fix listed
1
library/matomo:5.13.0-apache369723bd31cd
ncurses@6.5+20250216-2
no fix listed
1
library/memcached:1.6.4226983a43c918
ncurses@6.5+20250216-2
no fix listed
1
library/memcached:1.6.409ae868852d0b
ncurses@6.5+20250216-2
no fix listed
1
library/memcached:1.6.40cc523a19da58
ncurses@6.5+20250216-2
no fix listed
1
library/memcached:1.6.45dc561d52bb8a
ncurses@6.5+20250216-2
no fix listed
1
library/memcached:1.6.42-trixiee2a8683c7fbb
ncurses@6.5+20250216-2
no fix listed
1
library/mongo:7.0.140032d2ca20db
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
library/mongo:8.002a0cc7939f5
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
library/mongo:4.4.1305678ae4e5e1
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
library/mongo:3.6146c1fd999a6
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm7
1
library/mongo:5.0.32-focal3b6c281e1c08
ncurses@6.2-0ubuntu2.1
6.2-0ubuntu2.1+esm2
1
library/mongo:4.4-bionic3d0e6df9fd5b
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
library/mongo:5.0.14-focal50cae5081ab4
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
library/mongo:6.0.12646902910d6a
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
library/mongo:4.2699d652ed674
ncurses@6.1-1ubuntu1.18.04.1
6.1-1ubuntu1.18.04.1+esm4
1
library/mongo:4.2.16ca49afbcb2b
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
library/mongo:noble6ede2806c78e
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
library/mongo:6.0.271a63fc2438e
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
library/mongo:5.0.217c81758cb295
ncurses@6.2-0ubuntu2.1
6.2-0ubuntu2.1+esm2
1
library/mongo:7.0.28-jammy88785f6f665a
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
library/mongo:4.2.21-bionic9cb28f7291d9
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
1
library/mongo:7.0.12ae1cf99fa7bf
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
library/mongo:4.4.18d23ec07162ca
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
library/mongo:8.0.11dca8d11fe467
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
library/mysql:8.0-debian9382e4f6f7f0
ncurses@6.4-4
no fix listed
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
ncurses@6.5+20250216-2
no fix listed
1
library/neo4j:2026.02.25ab4ab0358cf
ncurses@6.5+20250216-2
no fix listed
1
library/neo4j:2026.05.06c162e2432f8
ncurses@6.5+20250216-2
no fix listed
1
library/nextcloud:35.0.0:35.0.0-apache3e9f6eaa5dc8
ncurses@6.5+20250216-2
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
ncurses@6.4-4
no fix listed
1
library/nextcloud:34.0.4-apachea5ace30c695a
ncurses@6.5+20250216-2
no fix listed
1
library/nextcloud:34.0.4-apacheb13a87affb7e
ncurses@6.5+20250216-2
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
ncurses@6.5+20250216-2
no fix listed
1
library/nginx:1.27.409369da6b103
ncurses@6.4-4
no fix listed
1
library/nginx:1.291881968aff6f
ncurses@6.5+20250216-2
no fix listed
1
library/nginx:1.276784fb0834aa
ncurses@6.4-4
no fix listed
1
library/nginx:1.25.167f9a4f10d14
ncurses@6.4-4
no fix listed
1
library/nginx:1.25.49ff236ed47fe
ncurses@6.4-4
no fix listed
1
library/nginx:1.31a53fc6c27208
ncurses@6.5+20250216-2
no fix listed
1
library/nginx:latestcfb8a89ac237
ncurses@6.5+20250216-2
no fix listed
1
library/nginx:1.27.3fb197595ebe7
ncurses@6.4-4
no fix listed
1
library/node:22-bookworm-slim48e4b67d85f8
ncurses@6.4-4
no fix listed
1
library/node:208f693eaa7e0a
ncurses@6.4-4
no fix listed
1
library/node:latestfa271c47a5d8
ncurses@6.5+20250216-2
no fix listed
1
library/php:8.4-fpm223115611852
ncurses@6.5+20250216-2
no fix listed
1
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
ncurses@6.5+20250216-2
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.