CVE-2025-66382
MediumAdvisory
Published 28 Nov 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.002
- 10th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,407
- of 17,797 indexed, latest versions
- Container images
- 1,242
- deployed by those charts
- Fix available
- None
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 1,407 of 17,797 indexed charts deploy, on 1,242 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| expatdeb | 2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+36 more | no fix listed | 1,242 |
Charts affected
1,407 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,714 |
| xkopsxkops | 0.1.0 | 1 of 5See more | 13,813 |
| nginx-chartxxoznge-nginx | 0.1.0 | 1 of 1See more | 1,861 |
| my-nginx-appyasser-nginx-app | 0.1.0 | 1 of 1See more | 1,861 |
| changedetection-iozekker6Verified publisher | 1.101.0 | 1See more | — |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,861 |
| zoo-project-druzoo-projectOfficialVerified publisher | 0.10.4 | 1 of 6See more | 7,936 |
Container images carrying it
1,242 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.