StackRadar

CVE-2025-64118

Medium

Advisory

Published 30 Oct 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 2
affected packages

node-tar has a race condition leading to uninitialized memory exposure

Carried by container images the latest versions of 22 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
tarnpm7.5.17.5.213
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3no fix listed6
OSV records
GHSA-29xp-372q-xqphUBUNTU-CVE-2025-64118

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
tar@7.5.1
7.5.2

Open the chart page →

15,712
kube-ingress-dash-chartkube-ingress-dashVerified publisher0.3.11 of 1See more

kube-ingress-dash-chart kube-ingress-dash 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
tar@7.5.1
7.5.2

Open the chart page →

1,505
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
prowlercloud/prowler-ui:5.31.179ee83c8e702
tar@7.5.1
7.5.2

Open the chart page →

8,158
bluerange-mosquittobluerangeOfficialVerified publisher1.0.41 of 1See more

bluerange-mosquitto bluerange 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:25f1bfbba84832
tar@7.5.1
7.5.2

Open the chart page →

1,168
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
node-tar@2.2.1-1
no fix listed

Open the chart page →

12,779
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
node-tar@1.0.3-2
no fix listed

Open the chart page →

27,417
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-tar@6.1.13+~cs7.0.5-3
no fix listed

Open the chart page →

13,220
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.2

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.2

Open the chart page →

68,240
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
ilum/marquez-web:0.53.2716437a51a6c
tar@7.5.1
7.5.2

Open the chart page →

6,254
github-exporterjkroepkeVerified publisher1.4.01 of 1See more

github-exporter jkroepke 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
jkroepke/github_exporter:1.8.03d850992786d
tar@7.5.1
7.5.2

Open the chart page →

1,031
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
tar@7.5.1
7.5.2

Open the chart page →

2,437
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
tar@7.5.1
7.5.2

Open the chart page →

3,441
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-tar@4.4.10+ds1-2ubuntu1
no fix listed

Open the chart page →

17,779
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
tar@7.5.1
7.5.2

Open the chart page →

2,457
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
tar@7.5.1
7.5.2

Open the chart page →

2,457
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
node-tar@2.2.1-1
no fix listed

Open the chart page →

36,215
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
tar@7.5.1
7.5.2

Open the chart page →

1,858
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.2

Open the chart page →

68,240
counter-dhlsikademo0.3.01 of 3See more

counter-dhl sikademo 0.3.0

1 of the 3 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
tar@7.5.1
7.5.2

Open the chart page →

4,820
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-tar@4.4.10+ds1-2ubuntu1
no fix listed

Open the chart page →

10,902
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2025-64118.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
tar@7.5.1
7.5.2

Open the chart page →

3,972

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.2
3
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
tar@7.5.1
7.5.2
2
bluerange/bluerange-mosquitto:25f1bfbba84832
tar@7.5.1
7.5.2
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
node-tar@1.0.3-2
no fix listed
1
fosrl/pangolin:1.13.0c32ad797ab96
tar@7.5.1
7.5.2
1
ilum/marquez-web:0.53.2716437a51a6c
tar@7.5.1
7.5.2
1
jkroepke/github_exporter:1.8.03d850992786d
tar@7.5.1
7.5.2
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-tar@6.1.13+~cs7.0.5-3
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-tar@4.4.10+ds1-2ubuntu1
no fix listed
1
openthread/otbr:latestf307f59f6432
node-tar@2.2.1-1
no fix listed
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
node-tar@2.2.1-1
no fix listed
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
tar@7.5.1
7.5.2
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
tar@7.5.1
7.5.2
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-tar@4.4.10+ds1-2ubuntu1
no fix listed
1
tensorzero/ui:2026.6.0f2563d54724e
tar@7.5.1
7.5.2
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
tar@7.5.1
7.5.2
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
tar@7.5.1
7.5.2
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
tar@7.5.1
7.5.2
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
tar@7.5.1
7.5.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.