StackRadar

CVE-2025-66034

Medium

Advisory

Published 1 Dec 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
26
of 17,781 indexed, latest versions
Container images
26
deployed by those charts
Fix available
1 of 1
affected package

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

Carried by container images the latest versions of 26 of 17,781 indexed charts deploy, on 26 images.

Affected packageAffected versionsFixed inImages
fonttoolspypi4.33.3, 4.37.4, 4.38.0, 4.39.0+11 more4.60.226
OSV records
GHSA-768j-98cg-p3fv
Also known as
PYSEC-2026-1389

Charts affected

26 by stars
ChartLatestAffected imagesRadar Score
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
fonttools@4.33.3
4.60.2

Open the chart page →

7,705
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
fonttools@4.53.1
4.60.2

Open the chart page →

3,004
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
openmined/syft-backend:0.9.5b72f74a68b32
fonttools@4.56.0
4.60.2

Open the chart page →

17,245
mlflowgetindataVerified publisher0.1.21 of 1See more

mlflow getindata 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
fonttools@4.51.0
4.60.2

Open the chart page →

2,452
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
fonttools@4.60.1
4.60.2

Open the chart page →

107,811
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
fonttools@4.47.2
4.60.2

Open the chart page →

15,712
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
fonttools@4.53.0
4.60.2

Open the chart page →

20,403
mlflow-controllermlflow-deployment-controller0.1.81 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

1 of the 2 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
fonttools@4.38.0
4.60.2

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
fonttools@4.38.0
4.60.2

Open the chart page →

5,804
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
fonttools@4.55.3
4.60.2

Open the chart page →

2,928
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
fonttools@4.55.3
4.60.2

Open the chart page →

6,324
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
fonttools@4.49.0
4.60.2
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
fonttools@4.51.0
4.60.2
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
fonttools@4.38.0
4.60.2

Open the chart page →

45,363
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
fonttools@4.37.4
4.60.2

Open the chart page →

2,573
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
fonttools@4.59.0
4.60.2

Open the chart page →

11,335
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
fonttools@4.53.1
4.60.2

Open the chart page →

16,604
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
fonttools@4.55.3
4.60.2

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
fonttools@4.55.3
4.60.2

Open the chart page →

5,974
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
fonttools@4.38.0
4.60.2

Open the chart page →

4,085
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
fonttools@4.60.1
4.60.2

Open the chart page →

8,923
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
fonttools@4.47.2
4.60.2

Open the chart page →

2,159
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
fonttools@4.57.0
4.60.2

Open the chart page →

5,788
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
fonttools@4.37.4
4.60.2

Open the chart page →

2,370
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
fonttools@4.39.3
4.60.2

Open the chart page →

3,811
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
fonttools@4.39.0
4.60.2

Open the chart page →

5,456
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
fonttools@4.56.0
4.60.2

Open the chart page →

2,817
frigatesmarthallVerified publisher1.0.61 of 1See more

frigate smarthall 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-66034.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
fonttools@4.39.3
4.60.2

Open the chart page →

2,243

Container images carrying it

26 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
blakeblackshear/frigate:0.11.18330b0a265b8
fonttools@4.37.4
4.60.2
2
opendatacube/ows:latest668cbb41473c
fonttools@4.55.3
4.60.2
2
aristidetm/basic-notebook:3.6.5469dbc951224
fonttools@4.53.1
4.60.2
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
fonttools@4.49.0
4.60.2
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
fonttools@4.51.0
4.60.2
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
fonttools@4.38.0
4.60.2
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
fonttools@4.60.1
4.60.2
1
buntha/mlflow:2.1.1154542cc3083
fonttools@4.38.0
4.60.2
1
esphome/esphome:2024.12.2b2c6322700ac
fonttools@4.55.3
4.60.2
1
evk02/mlflow:2.2.1ef6ff257ef35
fonttools@4.39.0
4.60.2
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
fonttools@4.38.0
4.60.2
1
inventree/inventree:1.5.4a946ec09da3e
fonttools@4.57.0
4.60.2
1
langgenius/dify-api:0.6.11fca918260dd6
fonttools@4.53.0
4.60.2
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
fonttools@4.39.3
4.60.2
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
fonttools@4.59.0
4.60.2
1
openmined/syft-backend:0.9.5b72f74a68b32
fonttools@4.56.0
4.60.2
1
saidsef/scapy-containerised:v2025.02f17f7c435891
fonttools@4.56.0
4.60.2
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
fonttools@4.38.0
4.60.2
1
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
fonttools@4.51.0
4.60.2
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
fonttools@4.53.1
4.60.2
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
fonttools@4.47.2
4.60.2
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
fonttools@4.39.3
4.60.2
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
fonttools@4.55.3
4.60.2
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
fonttools@4.33.3
4.60.2
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
fonttools@4.47.2
4.60.2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
fonttools@4.60.1
4.60.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.