StackRadar

CVE-2025-61729

High

Advisory

Published 2 Dec 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,601
of 17,832 indexed, latest versions
Container images
4,034
deployed by those charts
Fix available
2 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 3,601 of 17,832 indexed charts deploy, on 4,034 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-7.el8_101
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+171 more1.24.114,034
OSV records
DEBIAN-CVE-2025-61729RHSA-2026:2323GO-2025-4155
Also known as
BIT-golang-2025-61729

Charts affected

3,601 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-61729.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
stdlib@go1.24.6
1.24.11

Open the chart page →

8,105

Container images carrying it

4,034 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
haproxytech/haproxy-alpine:2.9.57f3dc8c7e031
stdlib@go1.22.0
1.24.11
1
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
stdlib@go1.20.5
1.24.11
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
stdlib@go1.22.2
1.24.11
1
hashicorp/boundary:0.15.3339b78b61750
stdlib@go1.21.8
1.24.11
1
hashicorp/boundary:0.21.037bf86488b74
stdlib@go1.25.1
1.24.11
1
hashicorp/boundary:0.8.1fb70bd9210ff
stdlib@go1.17.10
1.24.11
1
hashicorp/consul:1.17.0712fe02d2f84
stdlib@go1.20.10
1.24.11
1
hashicorp/consul:1.15.3ddff34041c5c
stdlib@go1.20.4
1.24.11
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
stdlib@go1.20.10
1.24.11
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
stdlib@go1.20.4
1.24.11
1
hashicorp/terraform:1.44dcb45513699
stdlib@go1.19.6
1.24.11
1
hashicorp/terraform:1.9.7b77efab1a448
stdlib@go1.22.7
1.24.11
1
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
stdlib@go1.22.4
1.24.11
1
hashicorp/terraform-k8s:1.1.2b19857bab620
stdlib@go1.18.8
1.24.11
1
hashicorp/vault:1.15.40b01ed3924e6
stdlib@go1.21.4
1.24.11
1
hashicorp/vault:1.14.0b2177a8bfe85
stdlib@go1.20.5
1.24.11
1
hashicorp/vault:1.19.0bbb7f98dc67d
stdlib@go1.23.6
1.24.11
1
hashicorp/vault:1.8.4dfc3500beb0e
stdlib@go1.16.7
1.24.11
1
hashicorp/vault:1.9.2ff9b17b0cefe
stdlib@go1.17.5
1.24.11
1
hashicorp/vault-k8s:1.6.2103a2d817a74
stdlib@go1.23.6
1.24.11
1
hashicorp/vault-k8s:1.2.14500e988b7ce
stdlib@go1.20.3
1.24.11
1
hashicorp/vault-k8s:0.6.05697b85bc69a
stdlib@go1.13.5
1.24.11
1
hashicorp/vault-k8s:0.14.0aff47b5ba39c
stdlib@go1.17.2
1.24.11
1
hashicorp/waypoint:0.11.397d521a27498
stdlib@go1.19.4
1.24.11
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
stdlib@go1.15.6
1.24.11
1
headscale/headscale:0.25.1a7a8ae9616bb
stdlib@go1.23.4
1.24.11
1
headscale/headscale:0.27.1cd37b3001857
stdlib@go1.25.1
1.24.11
1
helga09/my_sql_shoes:v1.1.1a03657d97897
stdlib@go1.18.2
1.24.11
1
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
stdlib@go1.20.5
1.24.11
1
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
stdlib@go1.19
1.24.11
1
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
stdlib@go1.17
1.24.11
1
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
stdlib@go1.15.3
1.24.11
1
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
stdlib@go1.19.7
1.24.11
1
hfoxy4/kubefaas-builder:main-2afc7570bfb65aaad93
stdlib@go1.21.11
1.24.11
1
hfoxy4/kubefaas-controller:main-2afc7570761fe08f14c
stdlib@go1.22.4
1.24.11
1
hhaluk/mocktail:2.0.3350d19360038
stdlib@go1.17.7
1.24.11
1
hhyo/archery:v1.9.11aa41843419e
stdlib@go1.15.6
1.24.11
1
hibiken/asynqmon:latestac80bcffd2f9
stdlib@go1.18.10
1.24.11
1
hipages/php-fpm_exporter:2.2.09b5be9d3d955
stdlib@go1.17.10
1.24.11
1
hiversh/antigravity:0.1.45-microvm0e36d98402bc
stdlib@go1.19.8
1.24.11
1
hiversh/browser:0.1.45-microvmb5048c6342ce
stdlib@go1.19.8
1.24.11
1
hiversh/claude:0.1.45-microvm2fbf9f264498
stdlib@go1.19.8
1.24.11
1
hiversh/codex:0.1.45-microvm4f43130f51e5
stdlib@go1.19.8
1.24.11
1
hiversh/controller:0.1.45b0b85f8942c7
stdlib@go1.19.8
1.24.11
1
hiversh/copilot:0.1.45-microvm50c07b84f298
stdlib@go1.19.8
1.24.11
1
hiversh/node:0.1.45-alpine-microvm836a37641941
stdlib@go1.19.8
1.24.11
1
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
stdlib@go1.19.8
1.24.11
1
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
stdlib@go1.19.8
1.24.11
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
stdlib@go1.17.10
1.24.11
1
holiman/nodemonitor:latest5cd609761065
stdlib@go1.20.3
1.24.11
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.