StackRadar

CVE-2025-6176

High

Advisory

Published 31 Oct 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
255
of 17,781 indexed, latest versions
Container images
287
deployed by those charts
Fix available
2 of 2
affected packages

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Carried by container images the latest versions of 255 of 17,781 indexed charts deploy, on 287 images.

Affected packageAffected versionsFixed inImages
brotlirpm1.0.6-1.el8, 1.0.6-2.el8, 1.0.6-3.el8, 1.0.9-6.el9+2 more0:1.0.6-4.el8_10, 0:1.0.9-9.el9_7, 0:1.1.0-7.el10_1238
brotlipypi1.0.9, 1.1.01.2.049
OSV records
GHSA-2qfp-q593-8484RHSA-2026:0845RHSA-2026:2042RHSA-2026:2389RLSA-2026:2042
Also known as
PYSEC-2026-1906, PYSEC-2026-2401, RHSA-2026:2227, RHSA-2026:2228, RHSA-2026:2229, RHSA-2026:2399, RHSA-2026:2400, RHSA-2026:2401, RHSA-2026:2455

Charts affected

255 by stars
ChartLatestAffected imagesRadar Score
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,138
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

14,983
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-6176.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10

Open the chart page →

3,697

Container images carrying it

287 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
codeurjc/weatherservice:v1.0b9e2f7234349
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
10
codeurjc/server:v1.0310bea5b1ee7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
8
mastercloudapps/server:v2.23f3d24dfe2686
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
4
mastercloudapps/weatherservice:v1.23de859d29c116
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
4
quay.io/strimzi/operator:0.37.052f376e64b9b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
4
cloudve/cloudlaunch-server:latest4a3d7fae90bb
brotli@1.0.9
1.2.0
3
dpage/pgadmin4:6.12781369df9994
brotli@1.0.9
1.2.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
brotli@1.0.6-2.el8
0:1.0.6-4.el8_10
3
quay.io/devtron/clair:4.3.675fb847ac045
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
3
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
confluentinc/cp-zookeeper:latest7610a50b13e7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
locustio/locust:2.32.2a0d4b88e42c1
brotli@1.1.0
1.2.0
2
minio/operator:v4.3.754393e03f3b2
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
2
akeyless/base-rhel:0.0.14ba8900a0061
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
alerta/alerta-web:8.5.04786b9eaa606
brotli@1.0.9
1.2.0
1
allegroai/clearml:2.0.0-613713ae38f7daf
brotli@1.1.0
1.2.0
1
alquimiaai/studio:certification38a1f0341982
brotli@1.0.9-7.el9_5
0:1.0.9-9.el9_7
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
altinity/metrics-exporter:0.20.01a46d104406d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
anchore/anchore-engine:v0.10.0bde9eedf639d
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
brotli@1.0.6-1.el8
0:1.0.6-4.el8_10
1
andrianrf/backoffice:latest047a7837651e
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
andrianrf/backoffice-be:latest6036614803d4
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
andrianrf/iso-server:latest7da47f525c7d
brotli@1.0.9-6.el9
0:1.0.9-9.el9_7
1
apache/camel-k:1.10.43bb13d14f64a
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
brotli@1.0.9
1.2.0
1
apache/superset:4.0.1ab9467fd712c
brotli@1.0.9
1.2.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
brotli@1.1.0
1.2.0
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
brotli@1.0.6-3.el8
0:1.0.6-4.el8_10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.