StackRadar

CVE-2025-6141

Medium

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,369
of 17,837 indexed, latest versions
Container images
2,344
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2025-6141 affecting package ncurses for versions less than 6.4-3

Carried by container images the latest versions of 2,369 of 17,837 indexed charts deploy, on 2,344 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+12 more5.9+20140118-1ubuntu1+esm7, 6.0+20160213-1ubuntu1+esm7, 6.1-1ubuntu1.18.04.1+esm4, 6.2-0ubuntu2.1+esm2+2 more2,343
ncursesrpm6.4-2.azl36.4-31
OSV records
DEBIAN-CVE-2025-6141UBUNTU-CVE-2025-6141AZL-64139
Also known as
USN-8709-1

Charts affected

2,369 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,344 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mariadb:10.692e50059ea0a
ncurses@6.3-2ubuntu0.2
6.3-2ubuntu0.3
2
library/mariadb:11.3.2e101f9db3191
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
2
library/mongo:8.0.20098862b1339f
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
2
library/mongo:5.041108d183e97
ncurses@6.2-0ubuntu2.1
6.2-0ubuntu2.1+esm2
2
library/mongo:4.2.358b25d51baa1
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
2
library/nginx:latest6e23479198b9
ncurses@6.5+20250216-2
no fix listed
2
library/nginx:1.27.098f8ec75657d
ncurses@6.4-4
no fix listed
2
library/nginx:1.29.49dd288848f44
ncurses@6.5+20250216-2
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
ncurses@6.4-4
no fix listed
2
library/postgres:16.109f23e02d766
ncurses@6.4-4
no fix listed
2
library/postgres:18.11090bc3a8ccf
ncurses@6.5+20250216-2
no fix listed
2
library/postgres:16.24aea012537ed
ncurses@6.4-4
no fix listed
2
library/postgres:17-bookworm639ab7ceb90e
ncurses@6.4-4
no fix listed
2
library/postgres:1767f41722b7a8
ncurses@6.5+20250216-2
no fix listed
2
library/postgres:18.06f3e42ad37de
ncurses@6.5+20250216-2
no fix listed
2
library/postgres:16.4e62fbf9d3e2b
ncurses@6.4-4
no fix listed
2
library/python:3.12-slim2f17fc044b57
ncurses@6.5+20250216-2
no fix listed
2
library/python:3.14-slim:3-slimcaaf356f4066
ncurses@6.5+20250216-2
no fix listed
2
library/python:3.7eedf63967cdb
ncurses@6.4-4
no fix listed
2
library/rabbitmq:4.1.0-management935b3f84c1e4
ncurses@6.4+20240113-1ubuntu2
6.4+20240113-1ubuntu2.2
2
library/rabbitmq:3.12.1-managementf020c06da226
ncurses@6.3-2ubuntu0.1
6.3-2ubuntu0.3
2
library/redis:8.10.1602d361c4da9
ncurses@6.5+20250216-2
no fix listed
2
library/redis:7:7.4:7.4.1171da9275c5f3
ncurses@6.4-4
no fix listed
2
library/redis:7.2.3a7cee7c8178f
ncurses@6.4-4
no fix listed
2
library/redis:8.2.2f0957bcaa75f
ncurses@6.4-4
no fix listed
2
library/redmine:6.1.3-trixief474a901faec
ncurses@6.5+20250216-2
no fix listed
2
library/ubuntu:16.04:xenial1f1a2d56de1d
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm7
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
ncurses@6.5+20250216-2
no fix listed
2
library/wordpress:latest8746e7e072e3
ncurses@6.5+20250216-2
no fix listed
2
library/wordpress:latesta85a30d9e752
ncurses@6.5+20250216-2
no fix listed
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm7
2
linuxserver/cloud9:latest:version-1.29.245c5fe102ff3
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1+esm4
2
locustio/locust:2.32.2a0d4b88e42c1
ncurses@6.4-4
no fix listed
2
longhornio/longhorn-manager:v1.2.3dca34321452c
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
2
louislam/uptime-kuma:2.5.4917318f9d7be
ncurses@6.4-4
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
ncurses@6.4-4
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
ncurses@6.4-4
no fix listed
2
mbentley/omada-controller:4.3f4e682274bed
ncurses@6.1-1ubuntu1.18.04.1
6.1-1ubuntu1.18.04.1+esm4
2
mcp/grafana:latest9362bcf6aa0e
ncurses@6.4-4
no fix listed
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
ncurses@6.4-4
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
ncurses@6.4-4
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
ncurses@6.4-4
no fix listed
2
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
ncurses@6.1-1ubuntu1
6.1-1ubuntu1.18.04.1+esm4
2
nginxinc/nginx-unprivileged:stable0918d093d608
ncurses@6.5+20250216-2
no fix listed
2
nutanix/nai-jobs:v2.8.09c373718e1b1
ncurses@6.5+20250216-2
no fix listed
2
obolnetwork/charon:v1.10.0278c7e2897b6
ncurses@6.5+20250216-2
no fix listed
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1+esm2
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm7
2
opea/embedding-tei:1.05c9639de61c1
ncurses@6.4-4
no fix listed
2

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.