CVE-2025-66418
HighAdvisory
Published 5 Dec 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.9
- base score, highest
- EPSS
- 0.007
- 51st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 801
- of 17,787 indexed, latest versions
- Container images
- 845
- deployed by those charts
- Fix available
- 4 of 4
- affected packages
urllib3 allows an unbounded number of links in the decompression chain
Carried by container images the latest versions of 801 of 17,787 indexed charts deploy, on 845 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| urllib3pypi | 1.24, 1.24.1, 1.24.2, 1.24.3+42 more | 2.6.0 | 818 |
| py3-pipapk | 25.0.1-r0, 25.2-r0, 26.0.1-r1 | 26.1.1-r0 | 3 |
| python-urllib3deb | 1.25.8-2ubuntu0.1, 1.25.8-2ubuntu0.2, 1.25.8-2ubuntu0.3, 1.25.8-2ubuntu0.4+6 more | 1.25.8-2ubuntu0.4+esm2, 1.26.5-1~exp1ubuntu0.4, 1.26.12-1+deb12u2, 2.0.7-1ubuntu0.3 | 46 |
| python-pipdeb | 22.0.2+dfsg-1, 22.0.2+dfsg-1ubuntu0.2, 22.0.2+dfsg-1ubuntu0.3, 22.0.2+dfsg-1ubuntu0.4+7 more | 22.0.2+dfsg-1ubuntu0.7+esm1, 24.0+dfsg-1ubuntu1.3+esm1 | 44 |
- OSV records
- CGA-7c7g-v8c7-cp3hCGA-9p8r-r9mh-6fj5DEBIAN-CVE-2025-66418GHSA-gm62-xv2j-4w53UBUNTU-CVE-2025-66418
- Also known as
- CGA-8232-8863-qprx, CGA-f9vm-whvp-q74g, PYSEC-2026-1998, USN-7927-1, USN-8344-1
Charts affected
801 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| zerossl-cert-managerzerossl-cert-manager | 0.1.0 | 1 of 2See more | 569 |
Container images carrying it
845 by charts deploying them
A fixed version is listed for 4 of the 4 affected packages.