StackRadar

CVE-2025-6141

Medium

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,370
of 17,832 indexed, latest versions
Container images
2,356
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2025-6141 affecting package ncurses for versions less than 6.4-3

Carried by container images the latest versions of 2,370 of 17,832 indexed charts deploy, on 2,356 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+12 more5.9+20140118-1ubuntu1+esm7, 6.0+20160213-1ubuntu1+esm7, 6.1-1ubuntu1.18.04.1+esm4, 6.2-0ubuntu2.1+esm2+2 more2,355
ncursesrpm6.4-2.azl36.4-31
OSV records
DEBIAN-CVE-2025-6141UBUNTU-CVE-2025-6141AZL-64139
Also known as
USN-8709-1

Charts affected

2,370 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,356 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
ncurses@6.4-4
no fix listed
1
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
ghcr.io/alethic/auth0-operator-image:1.4.122468990a8521
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
ncurses@6.4-4
no fix listed
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
ncurses@6.4-4
no fix listed
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ncurses@6.4-4
no fix listed
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
ncurses@6.4-4
no fix listed
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
ncurses@6.5+20250216-2
no fix listed
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
ncurses@6.4-4
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
ghcr.io/appscode/b3:v2026.9.1178a9fb785ec5
ncurses@6.4-4
no fix listed
1
ghcr.io/appscode/csi-driver-cacerts:v0.6.0ab213b156017
ncurses@6.4-4
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
ncurses@6.5+20250216-2
no fix listed
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
ncurses@6.4-4
no fix listed
1
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
ncurses@6.4-4
no fix listed
1
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
ncurses@6.4-4
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
ncurses@6.4-4
no fix listed
1
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
ncurses@6.4-4
no fix listed
1
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
ncurses@6.4-4
no fix listed
1
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
ncurses@6.4-4
no fix listed
1
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
ncurses@6.4-4
no fix listed
1
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
ncurses@6.4-4
no fix listed
1
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
ncurses@6.4-4
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
ncurses@6.4-4
no fix listed
1
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
ncurses@6.4-4
no fix listed
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
ncurses@6.4-4
no fix listed
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ncurses@6.4+20240113-1ubuntu2.1
6.4+20240113-1ubuntu2.2
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ncurses@6.4-4
no fix listed
1
ghcr.io/camptocamp/pgbouncer:latest19dc5663cac4
ncurses@6.5+20250216-2
no fix listed
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
ncurses@6.4-4
no fix listed
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
1
ghcr.io/caninehq/canine:latest68b19aee1c64
ncurses@6.4-4
no fix listed
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
ncurses@6.4-4
no fix listed
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
ncurses@6.5+20250216-2
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
ncurses@6.4-4
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
ncurses@6.4-4
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
ncurses@6.4-4
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
ncurses@6.4-4
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.