StackRadar

CVE-2025-61723

High

Advisory

Published 29 Oct 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,468
of 17,821 indexed, latest versions
Container images
3,921
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic complexity when parsing some invalid inputs in encoding/pem

Carried by container images the latest versions of 3,468 of 17,821 indexed charts deploy, on 3,921 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+165 more1.24.83,921
OSV records
DEBIAN-CVE-2025-61723GO-2025-4009
Also known as
BIT-golang-2025-61723

Charts affected

3,468 by stars
ChartLatestAffected imagesRadar Score
matomodigitalist-open-cloud-matomo12.0.201 of 3See more

matomo digitalist-open-cloud-matomo 12.0.20

1 of the 3 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
hipages/php-fpm_exporter:2.2.09b5be9d3d955
stdlib@go1.17.10
1.24.8

Open the chart page →

3,540
directusdirectus-io2.1.03 of 3See more

directus directus-io 2.1.0

3 of the 3 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.24.8
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.24.8
directus/directus:12.0.29c8470ea465c
stdlib@go1.23.12
1.24.8

Open the chart page →

7,513
alertmanager-ntfydjjudas21Verified publisher0.1.21 of 1See more

alertmanager-ntfy djjudas21 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/alexbakker/alertmanager-ntfy:1.0.12f4db8064595
stdlib@go1.24.4
1.24.8

Open the chart page →

641
myappdl-grafana-webappVerified publisher0.1.01 of 2See more

myapp dl-grafana-webapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
onkar17/grafana:latestaef3ebd6e24e
stdlib@go1.16.1
1.24.8

Open the chart page →

2,527
dnation-pingdnationcloud0.1.94 of 5See more

dnation-ping dnationcloud 0.1.9

4 of the 5 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
stdlib@go1.15.5
1.24.8
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.24.8
prom/blackbox-exporter:v0.18.01ffc3f109eb3
stdlib@go1.15.2
1.24.8
prom/prometheus:v2.21.0d43417c260e5
stdlib@go1.15.2
1.24.8

Open the chart page →

10,475
docker-in-dockerdocker-in-docker0.0.31 of 2See more

docker-in-docker docker-in-docker 0.0.3

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
library/docker:24.0.2-dind1d148deae16a
stdlib@go1.20.4
1.24.8

Open the chart page →

2,595
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
stdlib@go1.22.7
1.24.8

Open the chart page →

1,559
thermitedollarshaveclubOfficialVerified publisher0.1.171 of 1See more

thermite dollarshaveclub 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
dollarshaveclub/thermite:0.0.31663cbf25fcfe
stdlib@go1.17.1
1.24.8

Open the chart page →

2,740
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.24.8

Open the chart page →

1,889
dominodominoVerified publisher0.1.111 of 3See more

domino domino 0.1.11

1 of the 3 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
stdlib@go1.24.6
1.24.8

Open the chart page →

8,820
archerydoubanVerified publisher0.4.32 of 6See more

archery douban 0.4.3

2 of the 6 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
stdlib@go1.22.1
1.24.8
hhyo/archery:v1.9.11aa41843419e
stdlib@go1.15.6
1.24.8

Open the chart page →

5,864
karmadoubanVerified publisher1.9.21 of 1See more

karma douban 1.9.2

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/prymitive/karma:v0.85d06892218680
stdlib@go1.16.3
1.24.8

Open the chart page →

2,018
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
stdlib@go1.21.4
1.24.8

Open the chart page →

73,518
dragonfly-stackdragonflyVerified publisher0.1.24 of 7See more

dragonfly-stack dragonfly 0.1.2

4 of the 7 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
stdlib@go1.21.5
1.24.8
dragonflyoss/manager:v2.1.49c3ef7f10698d
stdlib@go1.21.1
1.24.8
dragonflyoss/scheduler:v2.1.49523785c77787
stdlib@go1.21.1
1.24.8
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
stdlib@go1.18.10
1.24.8

Open the chart page →

18,788
nydus-snapshotterdragonflyVerified publisher0.0.101 of 2See more

nydus-snapshotter dragonfly 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
stdlib@go1.18.10
1.24.8

Open the chart page →

3,669
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
stdlib@go1.20.12
1.24.8

Open the chart page →

69,465
gethdysnixVerified publisher1.1.21 of 1See more

geth dysnix 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ethereum/client-go:v1.14.8886ec69b35b0
stdlib@go1.22.6
1.24.8

Open the chart page →

1,627
glpieftechcombr-glpiVerified publisher2.12.11 of 5See more

glpi eftechcombr-glpi 2.12.1

1 of the 5 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
library/mariadb:12.3.2a02fe89cb597
stdlib@go1.24.6
1.24.8

Open the chart page →

4,544
glideeinstackOfficialVerified publisher0.0.21 of 1See more

glide einstack 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
stdlib@go1.21.6
1.24.8

Open the chart page →

1,335
elchi-discoveryelchi1.0.01 of 1See more

elchi-discovery elchi 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
jhonbrownn/elchi-discovery:latest8f6551ecc98c
stdlib@go1.23.1
1.24.8

Open the chart page →

638
elchi-stackelchi1.13.04 of 10See more

elchi-stack elchi 1.13.0

4 of the 10 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
grafana/grafana:12.2.074144189b384
stdlib@go1.24.6
1.24.8
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.24.8
otel/opentelemetry-collector-contrib:0.89.0995f17004231
stdlib@go1.21.4
1.24.8
victoriametrics/victoria-metrics:v1.93.577a9815d0640
stdlib@go1.21.1
1.24.8

Open the chart page →

15,785
navidromeemmas-chartsVerified publisher0.0.61 of 1See more

navidrome emmas-charts 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
deluan/navidrome:0.50.02cf4442b0099
stdlib@go1.21.0
1.24.8

Open the chart page →

2,130
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2025-61723.

Open the chart page →

31,614
eoapieoapiOfficialVerified publisher0.16.31 of 7See more

eoapi eoapi 0.16.3

1 of the 7 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
stdlib@go1.24.6
1.24.8

Open the chart page →

2,992
nexus-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

nexus-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
stdlib@go1.17.2
1.24.8

Open the chart page →

2,267
httpbingoestahnVerified publisher0.1.11 of 1See more

httpbingo estahn 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
mccutchen/go-httpbin:v2.2.25994403ef75b
stdlib@go1.16.2
1.24.8

Open the chart page →

1,360
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
stdlib@go1.23.5
1.24.8

Open the chart page →

3,121
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
stdlib@go1.23.12
1.24.8

Open the chart page →

1,593
genesis-generatorethereum-helm-chartsVerified publisher0.2.31 of 2See more

genesis-generator ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
skylenet/ethereum-genesis-generator:latest210353ce7c89
stdlib@go1.17.13
1.24.8

Open the chart page →

3,138
ipfs-clusterethereum-helm-chartsVerified publisher0.1.142 of 3See more

ipfs-cluster ethereum-helm-charts 0.1.14

2 of the 3 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ipfs/kubo:latestb293923d66e4
stdlib@go1.19.8
1.24.8
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
stdlib@go1.19.3
1.24.8

Open the chart page →

4,717
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.19.8
1.24.8

Open the chart page →

11,495
event-exporterevent-exporterVerified publisher0.1.171 of 1See more

event-exporter event-exporter 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
kubestar/event-exporter:latest656606941255
stdlib@go1.20.14
1.24.8

Open the chart page →

1,211
events-exporterevents-exporter0.0.41 of 1See more

events-exporter events-exporter 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
stdlib@go1.19.5
1.24.8

Open the chart page →

2,135
github-actions-runner-operatorevryfs-ossVerified publisher2.8.11 of 1See more

github-actions-runner-operator evryfs-oss 2.8.1

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
stdlib@go1.21.1
1.24.8

Open the chart page →

1,237
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
stdlib@go1.24.5
1.24.8

Open the chart page →

4,180
vidcheckfactlyVerified publisher0.5.21 of 2See more

vidcheck factly 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
factly/vidcheck-server:0.12.087064eb0463c
stdlib@go1.14.2
1.24.8

Open the chart page →

3,621
ecr-cleanupfairwinds-stableVerified publisher1.2.81 of 1See more

ecr-cleanup fairwinds-stable 1.2.8

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
stdlib@go1.19.6
1.24.8

Open the chart page →

1,005
fastapi-microservice-appfast-api-microservice-app1.3.01 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

1 of the 4 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
library/mongo:7.09854f7139445
stdlib@go1.24.6
1.24.8

Open the chart page →

9,387
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.24.8
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.24.8
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.24.8

Open the chart page →

8,691
federidfederidOfficialVerified publisher0.1.21 of 1See more

federid federid 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
federid/webhook:0.1.0fbfb7c6510a7
stdlib@go1.23.3
1.24.8

Open the chart page →

2,041
taigafermosit0.0.112 of 7See more

taiga fermosit 0.0.11

2 of the 7 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
stdlib@go1.24.4
1.24.8
taigaio/taiga-protected:latestfd4568a97a59
stdlib@go1.24.4
1.24.8

Open the chart page →

8,451
ferriskeyferriskey0.8.01 of 3See more

ferriskey ferriskey 0.8.0

1 of the 3 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.24.8

Open the chart page →

2,131
file-manager-serverfile-manager-server1.11.01 of 1See more

file-manager-server file-manager-server 1.11.0

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
stdlib@go1.23.11
1.24.8

Open the chart page →

770
fission-corefission-chartsVerified publisher1.14.13 of 3See more

fission-core fission-charts 1.14.1

3 of the 3 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
fission/fission-bundle:1.14.13fcfd8a0fa5d
stdlib@go1.15.14
1.24.8
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
stdlib@go1.15.14
1.24.8
fission/reporter:1.14.104c6e06af175
stdlib@go1.15.14
1.24.8

Open the chart page →

7,110
openldapfluktuid0.1.11 of 2See more

openldap fluktuid 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.24.8

Open the chart page →

3,315
flyway-operatorflyway-operatorVerified publisher0.2.131 of 1See more

flyway-operator flyway-operator 0.2.13

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/davidkarlsen/flyway-operator:0.2.1366f60b461c0d
stdlib@go1.24.4
1.24.8

Open the chart page →

641
free5gcfree5gcVerified publisher0.1.311 of 12See more

free5gc free5gc 0.1.3

11 of the 12 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
stdlib@go1.21.8
1.24.8
free5gc/ausf:v3.4.3687ff4daf5da
stdlib@go1.21.8
1.24.8
free5gc/chf:v3.4.3e2a4dd98a4ed
stdlib@go1.21.8
1.24.8
free5gc/nrf:v3.4.399e46b860efb
stdlib@go1.21.8
1.24.8
free5gc/nssf:v3.4.3dfe8c68c04b4
stdlib@go1.21.8
1.24.8
free5gc/pcf:v3.4.3f712e8ecd927
stdlib@go1.21.8
1.24.8
free5gc/smf:v3.4.360e38baa4b10
stdlib@go1.21.8
1.24.8
free5gc/udm:v3.4.32f68df062a50
stdlib@go1.21.8
1.24.8
free5gc/udr:v3.4.3c0783bcdcbdc
stdlib@go1.21.8
1.24.8
free5gc/upf:v3.4.3b6b362a39fdd
stdlib@go1.21.8
1.24.8
free5gc/webui:v3.4.39adeb18492cb
stdlib@go1.21.8
1.24.8

Open the chart page →

10,717
fsmfsmOfficialVerified publisher0.2.112 of 5See more

fsm fsm 0.2.11

2 of the 5 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
stdlib@go1.19.13
1.24.8
flomesh/fsm-manager:0.2.1122f849c70b25
stdlib@go1.19.13
1.24.8

Open the chart page →

4,228
adguard-homegabe565Verified publisher0.3.251 of 2See more

adguard-home gabe565 0.3.25

1 of the 2 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.56c64a0b37f7b9
stdlib@go1.23.5
1.24.8

Open the chart page →

815
home-assistantgabe565Verified publisher0.17.01 of 1See more

home-assistant gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-61723.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:latestd89226851697
stdlib@go1.23.3
1.24.8

Open the chart page →

2,162

Container images carrying it

3,921 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.24.8
1
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
stdlib@go1.24.6
1.24.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.24.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.24.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.24.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.24.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.24.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.24.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.24.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.24.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.24.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.24.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.24.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.24.8
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.24.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.24.8
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.24.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.24.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.24.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.24.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.24.8
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.