StackRadar

CVE-2025-6176

High

Advisory

Published 31 Oct 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
255
of 17,781 indexed, latest versions
Container images
287
deployed by those charts
Fix available
2 of 2
affected packages

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Carried by container images the latest versions of 255 of 17,781 indexed charts deploy, on 287 images.

Affected packageAffected versionsFixed inImages
brotlirpm1.0.6-1.el8, 1.0.6-2.el8, 1.0.6-3.el8, 1.0.9-6.el9+2 more0:1.0.6-4.el8_10, 0:1.0.9-9.el9_7, 0:1.1.0-7.el10_1238
brotlipypi1.0.9, 1.1.01.2.049
OSV records
GHSA-2qfp-q593-8484RHSA-2026:0845RHSA-2026:2042RHSA-2026:2389RLSA-2026:2042
Also known as
PYSEC-2026-1906, PYSEC-2026-2401, RHSA-2026:2227, RHSA-2026:2228, RHSA-2026:2229, RHSA-2026:2399, RHSA-2026:2400, RHSA-2026:2401, RHSA-2026:2455

Charts affected

255 by stars
ChartLatestAffected imagesRadar Score
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,138
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

14,983
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

3,697

Container images carrying it

287 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
assistiot/identity-manager_kc:latest0df4b4fa899a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
baserow/backend:1.31.1e0b3c8130b91
brotli@1.1.0
1.2.0
1
baserow/baserow:1.30.1df0c42eb67e8
brotli@1.1.0
1.2.0
1
beopenit/door-helm:v3.0.1b4d9f9bee224
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
bmeares/meerschaum:2.8.48e9c5bacaa82
brotli@1.1.0
1.2.0
1
bsgrigorov/helm-operator:latest45ab095f09c8
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
cleveritcz/opencve:1.5.0c75c1636e0b7
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
cockroachdb/cockroach:v22.2.91116820f4134
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
cockroachdb/cockroach-operator:v2.1.0983312754620
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
coderenvs/coder-service:1.44.61deffc4670e6
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
coderenvs/timescale:1.44.676fd37fe6830
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
codetogether/codetogether:latest4348c8a38752
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-kafka:7.5.1dc9b972db002
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
craftypath/sops-operator:v0.8.0402a0024c732
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
ctron/hawkbit-operator:0.1.48fdea8f76499
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
dpage/pgadmin4:8.418cd5711fc9a
brotli@1.1.0
1.2.0
1
dpage/pgadmin4:7.537946e4f3e7b
brotli@1.0.9
1.2.0
1
dpage/pgadmin4:9.252cb72a9e3da
brotli@1.1.0
1.2.0
1
dpage/pgadmin4:8.13561c1f8f99f2
brotli@1.1.0
1.2.0
1
evk02/mlflow:2.2.1ef6ff257ef35
brotli@1.0.9
1.2.0
1
fiware/mintaka:0.7.092a3c5cf43c0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
fiware/mintaka:latestefc6793388cc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
fiware/orion-ld:1.10.03c490a746f65
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
galaxy/cloudman-server:lateste5c265fe9fcd
brotli@1.0.9
1.2.0
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
1
gurolakman/oam:4.0.0ed8fd2062548
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.