StackRadar

CVE-2025-6176

High

Advisory

Published 31 Oct 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
255
of 17,781 indexed, latest versions
Container images
287
deployed by those charts
Fix available
2 of 2
affected packages

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Carried by container images the latest versions of 255 of 17,781 indexed charts deploy, on 287 images.

Affected packageAffected versionsFixed inImages
brotlirpm1.0.6-1.el8, 1.0.6-2.el8, 1.0.6-3.el8, 1.0.9-6.el9+2 more0:1.0.6-4.el8_10, 0:1.0.9-9.el9_7, 0:1.1.0-7.el10_1238
brotlipypi1.0.9, 1.1.01.2.049
OSV records
GHSA-2qfp-q593-8484RHSA-2026:0845RHSA-2026:2042RHSA-2026:2389RLSA-2026:2042
Also known as
PYSEC-2026-1906, PYSEC-2026-2401, RHSA-2026:2227, RHSA-2026:2228, RHSA-2026:2229, RHSA-2026:2399, RHSA-2026:2400, RHSA-2026:2401, RHSA-2026:2455

Charts affected

255 by stars
ChartLatestAffected imagesRadar Score
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,138
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

14,983
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

3,697

Container images carrying it

287 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gurolakman/smsf-momt:1.0.4ce23b20a8a17
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
gurolakman/ussigw-core:1.0.48739565c3ea2
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
hansehe/locust:1.1.0bc8e45262bc4
brotli@1.1.0
1.2.0
1
hayk96/alerta-web:9.0.486377705e9e3
brotli@1.1.0
1.2.0
1
hazelcast/management-center:5.3.2f9d34300d330
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
brotli@1.1.0
1.2.0
1
homeassistant/home-assistant:2023.12.48d000332b09b
brotli@1.1.0
1.2.0
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
inventree/inventree:1.5.4a946ec09da3e
brotli@1.1.0
1.2.0
1
kubeflow/model-registry:v0.2.95783f6db428f
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
kuberay/operator:v1.0.04e6ac8a3a2c4
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
langgenius/dify-api:1.0.0066035f93856
brotli@1.1.0
1.2.0
1
langgenius/dify-api:0.6.11fca918260dd6
brotli@1.1.0
1.2.0
1
linuxserver/calibre-web:0.6.24241009026e6f
brotli@1.1.0
1.2.0
1
locustio/locust:2.24.151d866285170
brotli@1.1.0
1.2.0
1
minio/kes:v0.22.255f3aef5803e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
minio/operator:v5.0.9170b154d2c61
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
minio/operator:v4.1.02adc5be088f5
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
brotli@1.1.0
1.2.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
brotli@1.1.0
1.2.0
1
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
razzy10/product-service:latest702e411956db
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
1
rm3l/dev-feed-api:latest9a7f732245a3
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
rm3l/mac-oui:1.8.03a5e1f95c132
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
sarwansharma/minio:v359d1da9385d1
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
brotli@1.0.9
1.2.0
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
semaphoreui/semaphore:v2.9.645b50bc11833f
brotli@1.0.9
1.2.0
1
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
sonatype/nexus3:3.58.1586060431b64
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
splunk/splunk-operator:2.0.0c4e0d3146226
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
stakater/workshop-operator:v0.0.3897bf456cc97c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
trinodb/trino:4796af989b0846d
brotli@1.1.0-6.el10
0:1.1.0-7.el10_1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.