StackRadar

CVE-2025-61728

Medium

Advisory

Published 28 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,835
of 17,926 indexed, latest versions
Container images
4,259
deployed by those charts
Fix available
1 of 2
affected packages

Excessive CPU consumption when building archive index in archive/zip

Carried by container images the latest versions of 3,835 of 17,926 indexed charts deploy, on 4,259 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+174 more1.24.124,259
OSV records
DEBIAN-CVE-2025-61728GO-2026-4342
Also known as
BIT-golang-2025-61728

Charts affected

3,835 by stars
ChartLatestAffected imagesRadar Score
pagesnarasimha-pages1.0.01 of 3See more

pages narasimha-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.24.12

Open the chart page →

20,573
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
stdlib@go1.13.15
1.24.12

Open the chart page →

2,192
nats-kafkanatsVerified publisher0.15.41 of 1See more

nats-kafka nats 0.15.4

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
natsio/nats-kafka:1.4.2bb241956b0dc
stdlib@go1.20
1.24.12

Open the chart page →

1,742
nats-operatornatsVerified publisher0.8.31 of 1See more

nats-operator nats 0.8.3

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
natsio/nats-operator:0.8.31261dae38389
stdlib@go1.16.10
1.24.12

Open the chart page →

2,359
account-servernatz-operatorVerified publisher0.9.51 of 1See more

account-server natz-operator 0.9.5

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/zeiss/natz-operator/account-server:0.9.5b380b5f17c3f
stdlib@go1.23.3
1.24.12

Open the chart page →

740
navidromenavidrome0.2.51 of 1See more

navidrome navidrome 0.2.5

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
deluan/navidrome:0.41.1fc4d8b6ad9f9
stdlib@go1.16.2
1.24.12

Open the chart page →

3,330
pagesnavin-brixton1.0.01 of 3See more

pages navin-brixton 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.24.12

Open the chart page →

20,573
incorencsaVerified publisher1.38.02 of 29See more

incore ncsa 1.38.0

2 of the 29 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
stdlib@go1.21.10
1.24.12
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
stdlib@go1.15.8
1.24.12

Open the chart page →

15,997
jupyterhub-metricsncsaVerified publisher1.3.02 of 5See more

jupyterhub-metrics ncsa 1.3.0

2 of the 5 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
library/postgres:15-alpinea46e076249ce
stdlib@go1.24.6
1.24.12
timescale/timescaledb:latest-pg156343bdc87ca1
stdlib@go1.24.6
1.24.12

Open the chart page →

3,311
uptime-kumancsaVerified publisher1.7.31 of 1See more

uptime-kuma ncsa 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.5c74379ac4509
stdlib@go1.20.5
1.24.12

Open the chart page →

31,884
redisneomanexlabsVerified publisher1.1.01 of 1See more

redis neomanexlabs 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.24.12

Open the chart page →

1,463
neosyncneosyncVerified publisher0.5.412 of 3See more

neosync neosync 0.5.41

2 of the 3 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
stdlib@go1.24.5
1.24.12
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
stdlib@go1.24.5
1.24.12

Open the chart page →

7,551
apineosync-apiVerified publisher0.5.411 of 1See more

api neosync-api 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
stdlib@go1.24.5
1.24.12

Open the chart page →

3,001
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
stdlib@go1.24.5
1.24.12

Open the chart page →

2,979
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.24.12

Open the chart page →

4,170
netbirdnetbird1.9.03 of 4See more

netbird netbird 1.9.0

3 of the 4 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
stdlib@go1.23.9
1.24.12
netbirdio/relay:0.46.0d32f82514a24
stdlib@go1.23.9
1.24.12
netbirdio/signal:0.46.0e8f392611152
stdlib@go1.23.9
1.24.12

Open the chart page →

6,715
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
stdlib@go1.16.6
1.24.12

Open the chart page →

2,888
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
stdlib@go1.17
1.24.12

Open the chart page →

3,986
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
stdlib@go1.16.5
1.24.12
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
stdlib@go1.16.8
1.24.12

Open the chart page →

5,195
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
stdlib@go1.24.4
1.24.12

Open the chart page →

7,939
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
stdlib@go1.24.6
1.24.12

Open the chart page →

4,038
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
stdlib@go1.23.6
1.24.12
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
stdlib@go1.23.6
1.24.12
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
stdlib@go1.23.6
1.24.12

Open the chart page →

5,611
nexus-freenexus-freeVerified publisher1.0.31 of 1See more

nexus-free nexus-free 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
quay.io/fossa/postgres:17.2-15af45ac79f38
stdlib@go1.18.2
1.24.12

Open the chart page →

1,124
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
wernight/ngrok:latestd211f29ebcfe
stdlib@go1.21.6
1.24.12

Open the chart page →

2,791
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
stdlib@go1.16.9
1.24.12

Open the chart page →

25,076
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
stdlib@go1.16.9
1.24.12

Open the chart page →

26,228
filezillanicholaswildeVerified publisher1.0.11 of 1See more

filezilla nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/filezilla:version-3.51.0-r15103cdd266ce
stdlib@go1.15.12
1.24.12

Open the chart page →

3,208
golinksnicholaswildeVerified publisher1.0.01 of 1See more

golinks nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/golinks:version-154c5818e67b26324c5
stdlib@go1.16.5
1.24.12

Open the chart page →

1,119
notesnicholaswildeVerified publisher1.0.01 of 1See more

notes nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/notes:version-ee287b9ab9bc16465bc
stdlib@go1.16.5
1.24.12

Open the chart page →

1,485
olivetinnicholaswildeVerified publisher1.0.21 of 1See more

olivetin nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/olivetin:version-2021-07-19e1d5c8a01008
stdlib@go1.16.5
1.24.12

Open the chart page →

1,677
podgrabnicholaswildeVerified publisher0.1.01 of 1See more

podgrab nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
stdlib@go1.15.2
1.24.12

Open the chart page →

2,397
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
stdlib@go1.17.11
1.24.12

Open the chart page →

23,129
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
stdlib@go1.16.12
1.24.12

Open the chart page →

24,361
staticnicholaswildeVerified publisher1.0.01 of 1See more

static nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/static:version-ee8a20cd1d47c730bc4
stdlib@go1.16.5
1.24.12

Open the chart page →

1,156
todonicholaswildeVerified publisher0.1.01 of 1See more

todo nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/todo:941c0d3-ls1d7ba1341a940
stdlib@go1.14.15
1.24.12

Open the chart page →

1,231
twtxtnicholaswildeVerified publisher1.0.01 of 1See more

twtxt nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/twtxt:version-0.1.158736a73ca10
stdlib@go1.16.5
1.24.12

Open the chart page →

2,339
wikinicholaswildeVerified publisher1.0.01 of 1See more

wiki nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/wiki:version-900b76a6c4f261d8f5e
stdlib@go1.16.5
1.24.12

Open the chart page →

1,792
cert-managernicklasfrahm-cert-managerVerified publisher0.1.24 of 4See more

cert-manager nicklasfrahm-cert-manager 0.1.2

4 of the 4 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.18.2af59e01ad975
stdlib@go1.24.4
1.24.12
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
stdlib@go1.24.4
1.24.12
quay.io/jetstack/cert-manager-startupapicheck:v1.18.21075e0974151
stdlib@go1.24.4
1.24.12
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
stdlib@go1.24.4
1.24.12

Open the chart page →

2,846
ciliumnicklasfrahm-ciliumVerified publisher0.7.45 of 6See more

cilium nicklasfrahm-cilium 0.7.4

5 of the 6 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
stdlib@go1.24.2
1.24.12
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
stdlib@go1.24.7
1.24.12
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
stdlib@go1.24.7
1.24.12
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
stdlib@go1.24.5
1.24.12
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
stdlib@go1.24.7
1.24.12

Open the chart page →

7,588
metrics-servernicklasfrahm-metrics-serverVerified publisher0.1.11 of 1See more

metrics-server nicklasfrahm-metrics-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
stdlib@go1.24.4
1.24.12

Open the chart page →

800
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
stdlib@go1.21.5
1.24.12

Open the chart page →

2,319
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
stdlib@go1.17.6
1.24.12

Open the chart page →

2,067
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.24.12

Open the chart page →

1,889
airflownineinfra-charts1.12.12 of 4See more

airflow nineinfra-charts 1.12.1

2 of the 4 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.24.12
quay.io/prometheus/statsd-exporter:v0.22.8f53cca722a03
stdlib@go1.18.6
1.24.12

Open the chart page →

2,263
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
stdlib@go1.21.3
1.24.12

Open the chart page →

1,189
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
stdlib@go1.19.13
1.24.12

Open the chart page →

873
hdfs-operatornineinfra-charts0.7.01 of 1See more

hdfs-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
nineinfra/hdfs-operator:v0.7.0debb1e3410e2
stdlib@go1.21.3
1.24.12

Open the chart page →

727
kyuubi-operatornineinfra-charts0.7.01 of 1See more

kyuubi-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
stdlib@go1.20.8
1.24.12

Open the chart page →

819
metastore-operatornineinfra-charts0.7.01 of 1See more

metastore-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
nineinfra/metastore-operator:v0.7.011259032fb04
stdlib@go1.20.8
1.24.12

Open the chart page →

819
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2025-61728.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
stdlib@go1.20.3
1.24.12
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
stdlib@go1.20.3
1.24.12
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
stdlib@go1.20.3
1.24.12
quay.io/minio/directpv:v4.0.84560083eb77d
stdlib@go1.21.0
1.24.12
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
stdlib@go1.20.3
1.24.12

Open the chart page →

7,171

Container images carrying it

4,259 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.24.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.24.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.24.12
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.24.12
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.24.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.24.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.24.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.24.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.24.12
1

syft 1.42.1 · advisories as of 28 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.