StackRadar

CVE-2025-6176

High

Advisory

Published 31 Oct 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
255
of 17,781 indexed, latest versions
Container images
287
deployed by those charts
Fix available
2 of 2
affected packages

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Carried by container images the latest versions of 255 of 17,781 indexed charts deploy, on 287 images.

Affected packageAffected versionsFixed inImages
brotlirpm1.0.6-1.el8, 1.0.6-2.el8, 1.0.6-3.el8, 1.0.9-6.el9+2 more0:1.0.6-4.el8_10, 0:1.0.9-9.el9_7, 0:1.1.0-7.el10_1238
brotlipypi1.0.9, 1.1.01.2.049
OSV records
GHSA-2qfp-q593-8484RHSA-2026:0845RHSA-2026:2042RHSA-2026:2389RLSA-2026:2042
Also known as
PYSEC-2026-1906, PYSEC-2026-2401, RHSA-2026:2227, RHSA-2026:2228, RHSA-2026:2229, RHSA-2026:2399, RHSA-2026:2400, RHSA-2026:2401, RHSA-2026:2455

Charts affected

255 by stars
ChartLatestAffected imagesRadar Score
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

7,486
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,237
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
brotli@1.1.0
1.2.0

Open the chart page →

19,224
dnation-kubernetes-monitoring-stackdnationcloud4.0.22 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

2 of the 17 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

21,641
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7

Open the chart page →

3,167
drogue-cloud-coredrogue-iotVerified publisher0.7.112 of 22See more

drogue-cloud-core drogue-iot 0.7.11

2 of the 22 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/keycloak/keycloak:20.0054ef67eb7da
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

55,666
drogue-cloud-examplesdrogue-iotVerified publisher0.7.113 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

3 of the 6 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ghcr.io/ctron/kubectl:1.25e37d61b5277c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

30,699
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,915
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

11,482
orion-ldeclipse-aeriosVerified publisher1.0.01 of 2See more

orion-ld eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
fiware/orion-ld:1.10.03c490a746f65
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

9,764
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

4,033
eoloPlanteolo-plannerVerified publisher0.1.02 of 7See more

eoloPlant eolo-planner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
mastercloudapps/weatherservice:v1.23de859d29c116
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

27,537
eoloplannereoloplannerVerified publisher0.1.02 of 7See more

eoloplanner eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
codeurjc/weatherservice:v1.0b9e2f7234349
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

32,205
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.02 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
mastercloudapps/weatherservice:v1.23de859d29c116
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

27,537
eoloplannereoloplanner-molynx-gat0.1.02 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
codeurjc/weatherservice:v1.0b9e2f7234349
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

28,482
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
codeurjc/weatherservice:v1.0b9e2f7234349
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

27,096
eoloplanteoloplant1.0.02 of 7See more

eoloplant eoloplant 1.0.0

2 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
mastercloudapps/weatherservice:v1.23de859d29c116
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

27,537
eoloplantseoloplants-urjcVerified publisher0.1.02 of 7See more

eoloplants eoloplants-urjc 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
codeurjc/weatherservice:v1.0b9e2f7234349
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

27,721
servereoloserverVerified publisher0.1.02 of 7See more

server eoloserver 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
codeurjc/weatherservice:v1.0b9e2f7234349
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

32,205
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
brotli@1.1.0
1.2.0

Open the chart page →

12,454
apollofiware0.1.41 of 1See more

apollo fiware 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/fiware/apollo:0.0.1055330b1b60c1
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,936
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

8,528
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

2,475
contract-managementfiware3.5.361 of 1See more

contract-management fiware 3.5.36

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/fiware/contract-management:3.3.122bcfcf874451
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

2,411
credentials-config-servicefiware2.6.41 of 1See more

credentials-config-service fiware 2.6.4

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

2,293
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

4,536
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

11,835
mintakafiware0.4.71 of 1See more

mintaka fiware 0.4.7

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
fiware/mintaka:latestefc6793388cc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

7,019
orionfiware1.6.112 of 2See more

orion fiware 1.6.11

2 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

10,637
tm-forum-apifiware0.17.1519 of 19See more

tm-forum-api fiware 0.17.15

19 of the 19 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/fiware/tmforum-account:1.18.06b25aac03414
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

35,112
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

7,087
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

11,961
searxgeek-cookbookVerified publisher5.6.21 of 4See more

searx geek-cookbook 5.6.2

1 of the 4 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
searx/searx:1.0.0-211-968b28993dbb3a6d9419
brotli@1.0.9
1.2.0

Open the chart page →

7,470
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
brotli@1.1.0
1.2.0

Open the chart page →

49,025
mimir-openshift-experimentalgrafana2.1.02 of 4See more

mimir-openshift-experimental grafana 2.1.0

2 of the 4 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10

Open the chart page →

17,759
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7

Open the chart page →

8,188
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
brotli@1.1.0
1.2.0

Open the chart page →

4,647
ditto-operatorhelm-chartsVerified publisher0.3.01 of 1See more

ditto-operator helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

2,674
hawkbit-operatorhelm-chartsVerified publisher0.1.41 of 1See more

hawkbit-operator helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ctron/hawkbit-operator:0.1.48fdea8f76499
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10

Open the chart page →

5,792
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

24,161
streamsheetshelm-chartsVerified publisher0.2.35 of 8See more

streamsheets helm-charts 0.2.3

5 of the 8 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

89,959
locusthelm-charts-nr0.32.41 of 1See more

locust helm-charts-nr 0.32.4

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
brotli@1.1.0
1.2.0

Open the chart page →

2,800
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
brotli@1.1.0
1.2.0

Open the chart page →

16,384
eoloplanthttpd-eoloplant0.1.02 of 7See more

eoloplant httpd-eoloplant 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
codeurjc/weatherservice:v1.0b9e2f7234349
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

32,205
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10

Open the chart page →

12,461
ibm-ucv-prodibm-helm5.2.61 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

1 of the 16 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10

Open the chart page →

12,105

Container images carrying it

287 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
codeurjc/weatherservice:v1.0b9e2f7234349
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
10
codeurjc/server:v1.0310bea5b1ee7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
8
mastercloudapps/server:v2.23f3d24dfe2686
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
4
mastercloudapps/weatherservice:v1.23de859d29c116
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
4
quay.io/strimzi/operator:0.37.052f376e64b9b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
4
cloudve/cloudlaunch-server:latest4a3d7fae90bb
brotli@1.0.9
1.2.0
3
dpage/pgadmin4:6.12781369df9994
brotli@1.0.9
1.2.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
3
quay.io/devtron/clair:4.3.675fb847ac045
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
3
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
confluentinc/cp-zookeeper:latest7610a50b13e7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
locustio/locust:2.32.2a0d4b88e42c1
brotli@1.1.0
1.2.0
2
minio/operator:v4.3.754393e03f3b2
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
akeyless/base-rhel:0.0.14ba8900a0061
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
alerta/alerta-web:8.5.04786b9eaa606
brotli@1.0.9
1.2.0
1
allegroai/clearml:2.0.0-613713ae38f7daf
brotli@1.1.0
1.2.0
1
alquimiaai/studio:certification38a1f0341982
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
altinity/metrics-exporter:0.20.01a46d104406d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
anchore/anchore-engine:v0.10.0bde9eedf639d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
andrianrf/backoffice:latest047a7837651e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
andrianrf/backoffice-be:latest6036614803d4
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
andrianrf/iso-server:latest7da47f525c7d
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
apache/camel-k:1.10.43bb13d14f64a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
brotli@1.0.9
1.2.0
1
apache/superset:4.0.1ab9467fd712c
brotli@1.0.9
1.2.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
brotli@1.1.0
1.2.0
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.