StackRadar

CVE-2025-66199

Medium

Advisory

Published 27 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
759
of 17,781 indexed, latest versions
Container images
802
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2025-66199 affecting package openssl for versions less than 3.3.5-3

Carried by container images the latest versions of 759 of 17,781 indexed charts deploy, on 802 images.

Affected packageAffected versionsFixed inImages
opensslapk3.2.0-r0, 3.3.0-r2, 3.3.1-r0, 3.3.1-r1+18 more3.3.6-r0, 3.5.5-r0, 3.6.1-r0722
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.3-1ubuntu2, 3.5.4-1~deb13u13.5.3-1ubuntu3, 3.5.4-1~deb13u263
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
opensslrpm3.3.5-1.azl33.3.5-31
OSV records
ALPINE-CVE-2025-66199CGA-8724-74qp-7vp4DEBIAN-CVE-2025-66199UBUNTU-CVE-2025-66199AZL-75284
Also known as
CGA-r9pq-2w3x-64gx, USN-7980-1

Charts affected

759 by stars
ChartLatestAffected imagesRadar Score
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
openssl@3.3.1-r3
3.3.6-r0

Open the chart page →

2,634
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
openssl@3.5.0-r0
3.5.5-r0
temporalio/server:1.29.1c1e3326b2ce1
openssl@3.5.0-r0
3.5.5-r0
temporalio/ui:2.44.00b36e00aad30
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

14,983
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
openssl@3.3.1-r3
3.3.6-r0

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
openssl@3.3.2-r4
3.3.6-r0

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

789
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,100
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-66199.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

9,381

Container images carrying it

802 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
openssl@3.3.3-r0
3.3.6-r0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
openssl@3.5.1-r0
3.5.5-r0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
openssl@3.3.3-r0
3.3.6-r0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
openssl@3.5.4-r0
3.5.5-r0
2
natsio/nats-server-config-reloader:0.21.110ff229eaf52
openssl@3.5.4-r0
3.5.5-r0
2
natsio/prometheus-nats-exporter:0.17.326c826662ac8
openssl@3.3.3-r0
3.3.6-r0
2
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
openssl@3.3.3-r0
3.3.6-r0
2
opea/chatqna-conversation-ui:1.002d5674ca863
openssl@3.3.2-r0
3.3.6-r0
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
openssl@3.3.3-r0
3.3.6-r0
2
oryd/kratos:v1.3.1fe2428f103a6
openssl@3.3.2-r1
3.3.6-r0
2
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.6-r0
2
rancher/local-path-provisioner:v0.0.299bebefa0b908
openssl@3.3.1-r3
3.3.6-r0
2
rclone/rclone:1.6874c51b8817e5
openssl@3.3.2-r0
3.3.6-r0
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
openssl@3.3.3-r0
3.3.6-r0
2
timberio/vector:0.51.1-alpine2d16ae87ec39
openssl@3.5.4-r0
3.5.5-r0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
nodejs@16.14.2-deb-1nodesource1
no fix listed
2
uselagoon/docker-host:v3.6.12c89ed939b8b
openssl@3.3.3-r0
3.3.6-r0
2
valkey/valkey:9.0.1546304417fea
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2
2
valkey/valkey:8.1.481db6d39e1bb
openssl@3.5.1-1+deb13u1
3.5.4-1~deb13u2
2
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
openssl@3.5.4-r0
3.5.5-r0
2
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.5-r0
2
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
openssl@3.3.1-r3
3.3.6-r0
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
no fix listed
2
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
openssl@3.5.0-r0
3.5.5-r0
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
openssl@3.5.1-r0
3.5.5-r0
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
openssl@3.5.1-r0
3.5.5-r0
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
openssl@3.5.0-r0
3.5.5-r0
2
ghcr.io/kiwigrid/k8s-sidecar:1.29.142002d66ddb3
openssl@3.3.2-r4
3.3.6-r0
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
openssl@3.5.0-r0
3.5.5-r0
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.5-r0
2
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
3.5.4-1~deb13u2
2
quay.io/curl/curl:8.16.0b17b13321678
openssl@3.5.2-r0
3.5.5-r0
2
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
openssl@3.5.4-r0
3.5.5-r0
2
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
openssl@3.3.0-r2
3.3.6-r0
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
openssl@3.5.4-r0
3.5.5-r0
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
openssl@3.5.0-r0
3.5.5-r0
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
openssl@3.3.3-r0
3.3.6-r0
2
2martens/configserver:latestbf1cdb80239d
openssl@3.3.1-r3
3.3.6-r0
1
2martens/timetable:latestbd1ba6ab84c9
openssl@3.5.1-r0
3.5.5-r0
1
2martens/wahlrecht:latestba2c3040dab0
openssl@3.5.1-r0
3.5.5-r0
1
abdullahkhawer/simple-elasticsearch-cleaner:2.1.028a6c3f7e0a9
openssl@3.3.2-r4
3.3.6-r0
1
abhinavsingh/proxy.py:latest51adc989fd03
openssl@3.3.3-r0
3.3.6-r0
1
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
openssl@3.3.4-r0
3.3.6-r0
1
adguard/adguardhome:v0.107.65d765078d2140
openssl@3.3.4-r0
3.3.6-r0
1
airbyte/db:2.2.03b6985a0ce75
openssl@3.5.4-r0
3.5.5-r0
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
openssl@3.5.1-r0
3.5.5-r0
1
alakaganaguathoork/local-business:latest7eb27b0f4a5a
openssl@3.5.4-r0
3.5.5-r0
1
alpine/curl:8.12.08943e8c7e8e4
openssl@3.3.2-r4
3.3.6-r0
1
alpine/git:v2.49.1c0280cf95723
openssl@3.5.4-r0
3.5.5-r0
1
alpine/helm105741fa6621
openssl@3.3.1-r3
3.3.6-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.