StackRadar

CVE-2025-64718

Medium

Advisory

Published 13 Nov 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
395
of 17,781 indexed, latest versions
Container images
394
deployed by those charts
Fix available
1 of 2
affected packages

js-yaml has prototype pollution in merge (<<)

Carried by container images the latest versions of 395 of 17,781 indexed charts deploy, on 394 images.

Affected packageAffected versionsFixed inImages
js-yamlnpm1.0.3, 3.5.5, 3.6.1, 3.7.0+9 more3.14.2, 4.1.1394
node-js-yamldeb4.1.0+dfsg+~4.0.5-7no fix listed1
OSV records
GHSA-mh29-5h37-fv8mUBUNTU-CVE-2025-64718

Charts affected

395 by stars
ChartLatestAffected imagesRadar Score
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
js-yaml@3.13.1
3.14.2

Open the chart page →

2,851
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
js-yaml@3.14.0
3.14.2

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
js-yaml@3.14.0
3.14.2

Open the chart page →

10,730
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
js-yaml@3.14.1
3.14.2

Open the chart page →

1,843
skoonerchristianhuthVerified publisher0.4.01 of 1See more

skooner christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
js-yaml@4.1.0
4.1.1

Open the chart page →

1,341
data-fairdata354-helmVerified publisher1.1.26 of 12See more

data-fair data354-helm 1.1.2

6 of the 12 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
js-yaml@3.13.1
3.14.2
ghcr.io/data-fair/data-fair:3cc9498b64b5b
js-yaml@3.14.1
3.14.2
ghcr.io/data-fair/metrics:0a8d40779eeae
js-yaml@3.14.1
3.14.2
ghcr.io/data-fair/notify:3c739b74dabb0
js-yaml@3.14.1
3.14.2
ghcr.io/data-fair/processings:15a9216989707
js-yaml@3.14.1
3.14.2
ghcr.io/data-fair/simple-directory:438a4f32fad82
js-yaml@3.14.1
3.14.2

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
js-yaml@3.14.1
3.14.2

Open the chart page →

5,056
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
js-yaml@3.14.1
3.14.2

Open the chart page →

3,925
elchi-stackelchi1.13.01 of 10See more

elchi-stack elchi 1.13.0

1 of the 10 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/mongo:6.0.12646902910d6a
js-yaml@3.13.1
3.14.2

Open the chart page →

15,383
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
js-yaml@4.1.0
4.1.1

Open the chart page →

31,510
fastapi-microservice-appfast-api-microservice-app1.3.01 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

1 of the 4 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/mongo:7.0b6421fd6d1c5
js-yaml@3.13.1
3.14.2

Open the chart page →

9,562
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
js-yaml@3.14.1
3.14.2

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
js-yaml@1.0.3
3.14.2

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
js-yaml@4.1.0
4.1.1

Open the chart page →

15,653
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
js-yaml@3.14.1
3.14.2

Open the chart page →

4,405
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
js-yaml@4.0.0
4.1.1

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
js-yaml@3.14.1
3.14.2

Open the chart page →

7,801
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
js-yaml@3.14.1
3.14.2

Open the chart page →

2,173
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
js-yaml@3.13.1
3.14.2

Open the chart page →

4,711
pdc-portali4trustVerified publisher2.3.21 of 1See more

pdc-portal i4trust 2.3.2

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
i4trust/pdc-portal:2.0.03e77858e1219
js-yaml@4.0.0
4.1.1

Open the chart page →

2,723
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
js-yaml@4.1.0
4.1.1

Open the chart page →

15,712
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
js-yaml@3.14.1
3.14.2

Open the chart page →

17,284
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
js-yaml@3.14.1
3.14.2

Open the chart page →

3,369
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
js-yaml@4.1.0
4.1.1

Open the chart page →

5,228
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
js-yaml@3.14.1
3.14.2

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
langgenius/dify-web:0.6.11a2a294743634
js-yaml@4.1.0
4.1.1

Open the chart page →

20,403
chibisafel4gVerified publisher0.1.12 of 3See more

chibisafe l4g 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
chibisafe/chibisafe:latest836467a50792
js-yaml@4.1.0
4.1.1
chibisafe/chibisafe-server:latest3da4fcbc1a18
js-yaml@4.1.0
4.1.1

Open the chart page →

5,654
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
js-yaml@3.13.1
3.14.2

Open the chart page →

7,874
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
js-yaml@3.14.1
3.14.2

Open the chart page →

5,940
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
js-yaml@4.1.0
4.1.1

Open the chart page →

13,738
open-api-discoveryopen-api-discoveryVerified publisher0.1.11 of 1See more

open-api-discovery open-api-discovery 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
lukasreining/open-api-schema-collector:0.1.050e021c42e33
js-yaml@4.1.0
4.1.1

Open the chart page →

2,473
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
js-yaml@3.13.1
3.14.2

Open the chart page →

5,779
patchworkpatchworkVerified publisher0.8.61 of 2See more

patchwork patchwork 0.8.6

1 of the 2 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/patchwork:mainc01e018bced4
js-yaml@4.1.0
4.1.1

Open the chart page →

2,083
pdf-editor-helmpdf-editor-web1.0.01 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
js-yaml@3.14.1
3.14.2

Open the chart page →

4,206
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
js-yaml@4.1.0
4.1.1
treskon/portrait-ui:DEV-lateste7970783bc8d
js-yaml@4.1.0
4.1.1

Open the chart page →

31,844
psa-restricted-patcherpsa-restricted-patcherVerified publisher0.10.11 of 1See more

psa-restricted-patcher psa-restricted-patcher 0.10.1

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
js-yaml@4.1.0
4.1.1

Open the chart page →

1,401
pumejwebapppumejnodejswebapp0.1.01 of 1See more

pumejwebapp pumejnodejswebapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
pumejlab/nodejs-webapp:latestf563eabcb819
js-yaml@4.1.0
4.1.1

Open the chart page →

1,164
flamerlex0.3.01 of 1See more

flame rlex 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
pawelmalak/flame:2.1.193e7b0abb603
js-yaml@4.1.0
4.1.1

Open the chart page →

2,449
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
js-yaml@3.14.1
3.14.2

Open the chart page →

6,879
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
js-yaml@4.1.0
4.1.1

Open the chart page →

2,823
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
js-yaml@4.1.0
4.1.1

Open the chart page →

10,380
statsdstatsd-airflow-smd0.1.191 of 1See more

statsd statsd-airflow-smd 0.1.19

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
js-yaml@3.13.1
3.14.2

Open the chart page →

4,185
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
js-yaml@4.1.0
4.1.1

Open the chart page →

11,574
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
js-yaml@3.13.1
3.14.2

Open the chart page →

7,517
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
js-yaml@3.14.1
3.14.2

Open the chart page →

12,581
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
js-yaml@3.14.0
3.14.2

Open the chart page →

3,833
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
js-yaml@3.13.1
3.14.2

Open the chart page →

2,154
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
js-yaml@3.14.0
3.14.2

Open the chart page →

9,783
admin-portaladmin-web-portal1.2.11 of 2See more

admin-portal admin-web-portal 1.2.1

1 of the 2 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
soulou2019/node-server:latest5e6ecfcc109e
js-yaml@4.1.0
4.1.1

Open the chart page →

3,419
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2025-64718.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
js-yaml@4.1.0
4.1.1

Open the chart page →

6,486

Container images carrying it

394 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kobotoolbox/kpi:2.022.24dbcacc01bccd4
js-yaml@3.13.1
3.14.2
1
konradkleine/docker-registry-frontend:v2181aad54ee64
js-yaml@3.6.1
3.14.2
1
ktitilayo2/nodejswebapp:latest8bac28058688
js-yaml@4.1.0
4.1.1
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
js-yaml@4.1.0
4.1.1
1
kubebb/component-store:latestfd8ecbd73213
js-yaml@4.1.0
4.1.1
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
js-yaml@3.13.1
3.14.2
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
js-yaml@4.1.0
4.1.1
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
js-yaml@3.13.1
3.14.2
1
kubevious/backend:1.2.22d9ba6eb46b6
js-yaml@4.1.0
4.1.1
1
kubevious/collector:1.2.1f58226f9d84e
js-yaml@4.1.0
4.1.1
1
kubevious/guard:1.2.19bf567704de2
js-yaml@3.14.1
3.14.2
1
kubevious/parser:1.0.151acf1a1f0b47
js-yaml@4.0.0
4.1.1
1
kubevious/parser:1.2.299ae7a5168c2
js-yaml@3.14.1
3.14.2
1
kubevious/workload-operator:1.0.20b0f4c507eb6
js-yaml@4.1.0
4.1.1
1
kyleslugg/klusterview:latestba8c36dfdfbd
js-yaml@3.14.1
3.14.2
1
kyso/kyso-front:lateste52595c5c16f
js-yaml@3.14.1
3.14.2
1
laly9999/node-app:1dd0e503913e1
js-yaml@3.14.1
3.14.2
1
laly9999/node-app-dockerized:latest75ae77a20c6c
js-yaml@4.1.0
4.1.1
1
langgenius/dify-web:0.6.11a2a294743634
js-yaml@4.1.0
4.1.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
js-yaml@4.1.0
4.1.1
1
lavandadelpatio/frontend:latest501c3f31e0bc
js-yaml@3.13.1
3.14.2
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
js-yaml@4.1.0
4.1.1
1
library/ghost:6.25.12654b1e90413
js-yaml@4.1.0
4.1.1
1
library/ghost:4.37.0767230c0f263
js-yaml@1.0.3
3.14.2
1
library/ghost:5.79.083f7bf209844
js-yaml@4.1.0
4.1.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
js-yaml@4.1.0
4.1.1
1
library/kibana:7.17.150172f1c538e7
js-yaml@3.14.1
3.14.2
1
library/kibana:8.18.004c0fc150f3a
js-yaml@4.1.0
4.1.1
1
library/kibana:7.17.8c5781ba340ef
js-yaml@3.14.1
3.14.2
1
library/kibana:7.17.3e2e2031c15be
js-yaml@3.14.1
3.14.2
1
library/mongo:7.0.140032d2ca20db
js-yaml@3.13.1
3.14.2
1
library/mongo:8.002a0cc7939f5
js-yaml@3.13.1
3.14.2
1
library/mongo:5.0.32-focal3b6c281e1c08
js-yaml@3.13.1
3.14.2
1
library/mongo:6.0.12646902910d6a
js-yaml@3.13.1
3.14.2
1
library/mongo:noble6ede2806c78e
js-yaml@3.13.1
3.14.2
1
library/mongo:7.0.28-jammy88785f6f665a
js-yaml@3.13.1
3.14.2
1
library/mongo:7.0.12ae1cf99fa7bf
js-yaml@3.13.1
3.14.2
1
library/mongo:8.0.11dca8d11fe467
js-yaml@3.13.1
3.14.2
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
js-yaml@3.14.1
3.14.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
js-yaml@4.1.0
4.1.1
1
linuxserver/code-server:4.10.1a5e43a05ae79
js-yaml@4.1.0
4.1.1
1
linuxserver/codimd:latestb801bbcf6386
js-yaml@3.14.0
3.14.2
1
linuxserver/overseerr:1.35.06108ed066d4a
js-yaml@4.1.0
4.1.1
1
lissy93/dashy:2.0.51991f7be5ed0
js-yaml@3.14.1
3.14.2
1
lsstsqre/squareone:0.4.09ded78e7fe03
js-yaml@3.14.1
3.14.2
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
js-yaml@4.0.0
4.1.1
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
js-yaml@4.1.0
4.1.1
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
js-yaml@4.1.0
4.1.1
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
js-yaml@3.13.1
3.14.2
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
js-yaml@4.1.0
4.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.