StackRadar

CVE-2025-66418

High

Advisory

Published 5 Dec 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
801
of 17,787 indexed, latest versions
Container images
845
deployed by those charts
Fix available
4 of 4
affected packages

urllib3 allows an unbounded number of links in the decompression chain

Carried by container images the latest versions of 801 of 17,787 indexed charts deploy, on 845 images.

Affected packageAffected versionsFixed inImages
urllib3pypi1.24, 1.24.1, 1.24.2, 1.24.3+42 more2.6.0818
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.1-r03
python-urllib3deb1.25.8-2ubuntu0.1, 1.25.8-2ubuntu0.2, 1.25.8-2ubuntu0.3, 1.25.8-2ubuntu0.4+6 more1.25.8-2ubuntu0.4+esm2, 1.26.5-1~exp1ubuntu0.4, 1.26.12-1+deb12u2, 2.0.7-1ubuntu0.346
python-pipdeb22.0.2+dfsg-1, 22.0.2+dfsg-1ubuntu0.2, 22.0.2+dfsg-1ubuntu0.3, 22.0.2+dfsg-1ubuntu0.4+7 more22.0.2+dfsg-1ubuntu0.7+esm1, 24.0+dfsg-1ubuntu1.3+esm144
OSV records
CGA-7c7g-v8c7-cp3hCGA-9p8r-r9mh-6fj5DEBIAN-CVE-2025-66418GHSA-gm62-xv2j-4w53UBUNTU-CVE-2025-66418
Also known as
CGA-8232-8863-qprx, CGA-f9vm-whvp-q74g, PYSEC-2026-1998, USN-7927-1, USN-8344-1

Charts affected

801 by stars
ChartLatestAffected imagesRadar Score
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-66418.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
urllib3@2.4.0
2.6.0

Open the chart page →

569

Container images carrying it

845 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
octoprint/octoprint:1.4.0106c26efcd8a
urllib3@1.26.2
2.6.0
1
octoprint/octoprint:1.6.1ea3bffae2470
urllib3@1.26.5
2.6.0
1
odaniait/aws-kubectl:latest3fff8a8570ec
urllib3@1.25.9
2.6.0
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
urllib3@2.2.3
2.6.0
1
opea/asr:1.025dd26d9cd09
urllib3@2.2.3
2.6.0
1
opea/chatqna:1.038c51b791efa
urllib3@2.2.3
2.6.0
1
opea/codegen:1.058f91683892d
urllib3@2.2.3
2.6.0
1
opea/codetrans:1.0e2436483b73d
urllib3@2.2.3
2.6.0
1
opea/docsum:1.03eaa91849512
urllib3@2.2.3
2.6.0
1
opea/guardrails-tgi:1.0262c6048aab8
urllib3@2.2.3
2.6.0
1
opea/guardrails-tgi:latestf68bec6a1271
urllib3@2.3.0
2.6.0
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
urllib3@2.2.3
2.6.0
1
opea/speecht5:1.0249afad3d268
urllib3@2.2.3
2.6.0
1
opea/tts:1.0257ae94709e9
urllib3@2.2.3
2.6.0
1
opea/web-retriever-chroma:1.0fe08165d7770
urllib3@2.2.3
2.6.0
1
openbas/caldera-server:5.1.0a277796d9724
urllib3@2.3.0
2.6.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
urllib3@2.5.0
2.6.0
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
urllib3@2.5.0
2.6.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
urllib3@2.5.0
2.6.0
1
opendatacube/explorer:latest120457ffcd69
urllib3@2.5.0
2.6.0
1
opendatacube/pipelines:wofs-1.225d810e8504b8
urllib3@1.24.2
2.6.0
1
opendatacube/restcube:latest91870111837c
urllib3@1.24.2
2.6.0
1
opendatacube/wms:latest1b90cdf68831
urllib3@1.24.2
2.6.0
1
opendatacube/wps:latest80df355a660b
urllib3@2.3.0
2.6.0
1
openemr/openemr:6.1.089eaa6d9a4e3
urllib3@1.26.7
2.6.0
1
openmined/syft-backend:0.9.5b72f74a68b32
py3-pip@25.0.1-r0
urllib3@2.3.0
26.1.1-r0
2.6.0
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
urllib3@1.26.12
2.6.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
urllib3@1.26.3
2.6.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
urllib3@1.26.3
2.6.0
1
openvpn/openvpn-as:latest2253c10ec652
urllib3@2.0.7
2.6.0
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
urllib3@1.25.11
2.6.0
1
openzaak/open-notificaties:1.3.02e65313b9b10
urllib3@1.26.9
2.6.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
urllib3@1.26.9
2.6.0
1
owanio1992/devpi:6.16.04ade8e1e4d7e
urllib3@2.5.0
2.6.0
1
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
urllib3@1.26.7
2.6.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
urllib3@2.1.0
2.6.0
1
pecan/monitor:1.7.273b2074f3fec
urllib3@1.24.3
2.6.0
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
urllib3@2.3.0
2.6.0
1
phntom/email-manager:0.1.22d8e2a9f2f085
urllib3@1.26.14
2.6.0
1
phntom/external-dns-host-network:0.0.123adadbac8443
urllib3@1.26.12
2.6.0
1
phntom/postgresql-backup-s3:1.0.2249b6488f618b
urllib3@1.26.13
2.6.0
1
phntom/stocks-nasdaq-crawler:0.0.28d2b844700b57
urllib3@1.25.10
2.6.0
1
phsmith/rundeck-exporter:2.6.10265a7616ae8
urllib3@2.0.2
2.6.0
1
platzio/backend:v0.6.5d5e5972f344b
urllib3@1.26.20
2.6.0
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
urllib3@1.25.8
2.6.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
urllib3@1.24.2
2.6.0
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
urllib3@2.2.2
2.6.0
1
prompve/prometheus-pve-exporter:3.4.2fcf041f0c24d
urllib3@2.1.0
2.6.0
1
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
urllib3@1.25.9
2.6.0
1
pryorda/vmware_exporter:v0.18.479925e63e59f
urllib3@1.26.12
2.6.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.