StackRadar

CVE-2025-6176

High

Advisory

Published 31 Oct 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
255
of 17,781 indexed, latest versions
Container images
287
deployed by those charts
Fix available
2 of 2
affected packages

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Carried by container images the latest versions of 255 of 17,781 indexed charts deploy, on 287 images.

Affected packageAffected versionsFixed inImages
brotlirpm1.0.6-1.el8, 1.0.6-2.el8, 1.0.6-3.el8, 1.0.9-6.el9+2 more0:1.0.6-4.el8_10, 0:1.0.9-9.el9_7, 0:1.1.0-7.el10_1238
brotlipypi1.0.9, 1.1.01.2.049
OSV records
GHSA-2qfp-q593-8484RHSA-2026:0845RHSA-2026:2042RHSA-2026:2389RLSA-2026:2042
Also known as
PYSEC-2026-1906, PYSEC-2026-2401, RHSA-2026:2227, RHSA-2026:2228, RHSA-2026:2229, RHSA-2026:2399, RHSA-2026:2400, RHSA-2026:2401, RHSA-2026:2455

Charts affected

255 by stars
ChartLatestAffected imagesRadar Score
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,138
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

14,983
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

3,697

Container images carrying it

287 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
1
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
1
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
quay.io/minio/directpv:v4.0.84560083eb77d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/openshift/origin-cli:4.66722d5041b47
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/projectquay/clair:4.9.023329c3368e4
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.