StackRadar

CVE-2025-66293

High

Advisory

Published 3 Dec 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
629
of 17,787 indexed, latest versions
Container images
568
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 629 of 17,787 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+4 more1.6.34-1ubuntu0.18.04.2+esm2, 1.6.37-2ubuntu0.1~esm2, 1.6.37-3ubuntu0.3, 1.6.39-2+deb12u1+3 more463
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r01.6.53-r0105
OSV records
ALPINE-CVE-2025-66293DEBIAN-CVE-2025-66293UBUNTU-CVE-2025-66293
Also known as
USN-7963-1, USN-8035-1

Charts affected

629 by stars
ChartLatestAffected imagesRadar Score
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm2

Open the chart page →

20,190
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm2

Open the chart page →

20,190
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
erenozcan17/react_frontend:v4.56e1b14973f9b
libpng@1.6.47-r0
1.6.53-r0

Open the chart page →

6,973
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
libpng@1.6.47-r0
1.6.53-r0

Open the chart page →

3,221
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
libpng@1.6.47-r0
1.6.53-r0

Open the chart page →

1,109
orchestra-login-portaltremolo2.3.981See more

orchestra-login-portal tremolo 2.3.98

1 container image this version deploys carries CVE-2025-66293.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3

Open the chart page →

tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libpng1.6@1.6.39-2
1.6.39-2+deb12u1

Open the chart page →

17,323
deep-learning-toolsuninettsigma29.1.21 of 3See more

deep-learning-tools uninettsigma2 9.1.2

1 of the 3 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
library/nginx:1.29.3-alpineb3c656d55d7a
libpng@1.6.47-r0
1.6.53-r0

Open the chart page →

1,567
opencloudunxwaresVerified publisher0.2.38 of 13See more

opencloud unxwares 0.2.3

8 of the 13 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
libpng@1.6.44-r0
1.6.53-r0
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libpng1.6@1.6.39-2
1.6.39-2+deb12u1

Open the chart page →

45,239
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libpng1.6@1.6.39-2
1.6.39-2+deb12u1

Open the chart page →

14,358
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
evoapicloud/evolution-manager:latestcbfeb314afb9
libpng@1.6.47-r0
1.6.53-r0

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
libpng@1.6.47-r0
1.6.53-r0

Open the chart page →

4,768
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
libpng@1.6.43-r0
1.6.53-r0

Open the chart page →

4,303
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
libpng1.6@1.6.39-2
1.6.39-2+deb12u1

Open the chart page →

10,795
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
libpng@1.6.47-r0
1.6.53-r0

Open the chart page →

2,076
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
libpng@1.6.47-r0
1.6.53-r0

Open the chart page →

pagesvictor-pages1.0.02 of 3See more

pages victor-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm2

Open the chart page →

20,190
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3

Open the chart page →

7,628
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2

Open the chart page →

11,405
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm2

Open the chart page →

20,190
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u1

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2

Open the chart page →

28,605
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3

Open the chart page →

9,248
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3

Open the chart page →

14,100
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u1

Open the chart page →

7,673
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-66293.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.53-r0

Open the chart page →

13,677

Container images carrying it

568 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
opendatacube/ows:latest668cbb41473c
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
vdiogov/glpi-conteiner:latest6945f84f0058
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
2
1dev/server:11.9.0cd5b12fe5471
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
1
5200710/hadoop:3.2.3-java8092d3088a5fb
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
1
akaunting/akaunting:3.0.1552811b36ec3a
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
libpng@1.6.47-r0
1.6.53-r0
1
allegroai/clearml:2.0.0-613713ae38f7daf
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
anguda/ant-media:2.5c435285fc241
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
1
anujdatar/cups:25.07.01685df04a643b
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
1
apache/activemq-artemis:2.44.00305c26f19ed
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
1
apache/activemq-artemis:2.37.0bae523439ee3
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
1
apache/druid:29.0.10cef139b6bf1
libpng1.6@1.6.39-2
1.6.39-2+deb12u1
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
apache/iotdb:0.13.3-nodeafa47bf1692a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
1
apache/kafka:4.1.0bff074a5d005
libpng@1.6.47-r0
1.6.53-r0
1
apache/kafka:3.9.0fbc7d7c428e3
libpng@1.6.44-r0
1.6.53-r0
1
apache/nifi-registry:1.27.063b8e3e40742
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
1
apachepulsar/pulsar:3.0.79c9947de139d
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
apachepulsar/pulsar:2.9.0d056c89b7131
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
1
apachepulsar/pulsar:2.8.2d538416d5afe
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
1
apache/ranger:2.7.076c176e8a0e4
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
apache/rocketmq:5.3.0434d8398f996
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.3
1
apache/rocketmq-exporter:0.0.2c8fb51195444
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
apache/skywalking-oap-server:9.2.0133d35d2c263
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.3
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.