StackRadar

CVE-2025-6141

Medium

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,369
of 17,837 indexed, latest versions
Container images
2,340
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2025-6141 affecting package ncurses for versions less than 6.4-3

Carried by container images the latest versions of 2,369 of 17,837 indexed charts deploy, on 2,340 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+12 more5.9+20140118-1ubuntu1+esm7, 6.0+20160213-1ubuntu1+esm7, 6.1-1ubuntu1.18.04.1+esm4, 6.2-0ubuntu2.1+esm2+2 more2,339
ncursesrpm6.4-2.azl36.4-31
OSV records
DEBIAN-CVE-2025-6141UBUNTU-CVE-2025-6141AZL-64139
Also known as
USN-8709-1

Charts affected

2,369 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,340 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
openebs/node-disk-operator:2.1.06afe2123c457
ncurses@6.3-2
6.3-2ubuntu0.3
3
selenium/hub:3.141.5902f251d48d5f
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
3
sigp/lighthouse:latest-amd6450f66cfebb6d
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
3
vaultwarden/server:1.37.3:latest1587c45feaa4
ncurses@6.5+20250216-2
no fix listed
3
vaultwarden/server:1.37.1ebdfe70701c6
ncurses@6.5+20250216-2
no fix listed
3
xenondb/percona:5.7.330e26872a2b67
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
3
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
3
ghcr.io/api7/adc:0.27.1f65f53dd9668
ncurses@6.4-4
no fix listed
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
ncurses@6.4-4
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
ncurses@6.4-4
no fix listed
3
ghcr.io/dgtlmoon/changedetection.io:0.60.7:latest096dae27b5d6
ncurses@6.4-4
no fix listed
3
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
ncurses@6.4-4
no fix listed
3
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
ncurses@6.4-4
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
ncurses@6.4-4
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
ncurses@6.4-4
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
ncurses@6.4-4
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
ncurses@6.3-2
6.3-2ubuntu0.3
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm7
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
ncurses@6.3-2
6.3-2ubuntu0.3
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
ncurses@6.4-4
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
ncurses@6.4-4
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
2
apache/iotdb:0.13.3-nodeafa47bf1692a
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
2
apache/nifi-registry:1.26.07cdfd8deec92
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
2
apache/rocketmq:5.4.0319cd8a81ed1
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
2
apache/tika:2.9.0.092d055a84e9e
ncurses@6.3-2
6.3-2ubuntu0.3
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
ncurses@6.4-4
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
ncurses@6.4-4
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
ncurses@6.4-4
no fix listed
2
bitnamilegacy/redis:latest5927ff3702df
ncurses@6.4-4
no fix listed
2
bitnami/minideb:latest3e8d78d6682d
ncurses@6.5+20250216-2
no fix listed
2
blockstack/stacks-core:3.2.0.0.0f79944317326
ncurses@6.4-4
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
ncurses@6.5+20250216-2
no fix listed
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
ncurses@6.4-4
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
ncurses@6.5+20250216-2
no fix listed
2
clickhouse/clickhouse-server:24.2ed9640bfff07
ncurses@6.2-0ubuntu2.1
6.2-0ubuntu2.1+esm2
2
csiplugin/csi-neonsan:v1.2.21fa83d45417f
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm7
2
dagster/user-code-example:1.13.24206c454797f7
ncurses@6.5+20250216-2
no fix listed
2
datagrok/grok_connect:latestf5876d3aebb8
ncurses@6.3-2ubuntu0.2
6.3-2ubuntu0.3
2
dbeaver/cloudbeaver:21.3.00c0985098263
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
2
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
2

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.