StackRadar

CVE-2025-66864

High

Advisory

Published 29 Dec 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
420
of 17,781 indexed, latest versions
Container images
404
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 420 of 17,781 indexed charts deploy, on 404 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.24-5ubuntu3.1, 2.24-5ubuntu14.2, 2.26.1-1ubuntu1~16.04.5, 2.26.1-1ubuntu1~16.04.6+41 moreno fix listed404
OSV records
DEBIAN-CVE-2025-66864UBUNTU-CVE-2025-66864

Charts affected

420 by stars
ChartLatestAffected imagesRadar Score
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
binutils@2.40-2
no fix listed

Open the chart page →

13,390
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
binutils@2.40-2
no fix listed

Open the chart page →

9,102
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
binutils@2.34-6ubuntu1.9
no fix listed

Open the chart page →

18,756
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
binutils@2.40-2
no fix listed

Open the chart page →

11,199
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
binutils@2.38-3ubuntu1
no fix listed

Open the chart page →

17,461
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
supabase/studio:latest94a2a9d2906e
binutils@2.40-2
no fix listed

Open the chart page →

9,556
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,704
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
binutils@2.40-2
no fix listed

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
binutils@2.40-2
no fix listed

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
binutils@2.40-2
no fix listed

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
binutils@2.40-2
no fix listed

Open the chart page →

28,858
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
binutils@2.40-2
no fix listed

Open the chart page →

10,086
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
binutils@2.40-2
no fix listed

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
binutils@2.40-2
no fix listed

Open the chart page →

14,358
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
binutils@2.38-4ubuntu2.6
no fix listed

Open the chart page →

9,347
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
binutils@2.44-3
no fix listed

Open the chart page →

3,911
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
binutils@2.40-2
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
binutils@2.40-2
no fix listed

Open the chart page →

10,001
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
binutils@2.44-3
no fix listed

Open the chart page →

5,560
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-66864.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
binutils@2.38-4ubuntu2.12
no fix listed

Open the chart page →

7,849

Container images carrying it

404 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jaedb/iris:latest048cfbf58d57
binutils@2.40-2
no fix listed
1
jakowenko/double-take:1.6.0b858bac9e32a
binutils@2.34-6ubuntu1.3
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
binutils@2.40-2
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
binutils@2.38-4ubuntu2.6
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
binutils@2.34-6ubuntu1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
binutils@2.34-6ubuntu1.3
no fix listed
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
binutils@2.38-4ubuntu2.6
no fix listed
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
binutils@2.38-4ubuntu2.6
no fix listed
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
binutils@2.38-4ubuntu2.6
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
binutils@2.30-21ubuntu1~18.04
no fix listed
1
kimai/kimai2:2.65.06dfc63199654
binutils@2.40-2
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
binutils@2.44-3
no fix listed
1
kixote/typemill4e9dff179519
binutils@2.44-3
no fix listed
1
kixote/typemill628f79a08cc7
binutils@2.44-3
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
binutils@2.40-2
no fix listed
1
kong/httpbin:latesta6ac46531193
binutils@2.38-4ubuntu2.6
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
binutils@2.38-4ubuntu2.6
no fix listed
1
laly9999/node-app:1dd0e503913e1
binutils@2.40-2
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
binutils@2.42-4ubuntu2.10
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
binutils@2.42-4ubuntu2.7
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
binutils@2.42-4ubuntu2.10
no fix listed
1
library/convertigo:8.4.3ae605bfcda05
binutils@2.42-4ubuntu2.10
no fix listed
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
binutils@2.40-2
no fix listed
1
library/eclipse-temurin:211f79c73404fb
binutils@2.46-3ubuntu2
no fix listed
1
library/eclipse-temurin:2185f00967bcc6
binutils@2.46-3ubuntu2
no fix listed
1
library/golang:latest512690a56605
binutils@2.44-3
no fix listed
1
library/matomo:5.1.2-apache2415789e1602
binutils@2.40-2
no fix listed
1
library/matomo:5.13.0-apache8e6bdd396496
binutils@2.44-3
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
binutils@2.40-2
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
binutils@2.44-3
no fix listed
1
library/node:208f693eaa7e0a
binutils@2.40-2
no fix listed
1
library/node:latestf5d1cc40abc1
binutils@2.44-3
no fix listed
1
library/php:8.4-fpm59fa733c9af6
binutils@2.44-3
no fix listed
1
library/python:3.1070c9cc675605
binutils@2.44-3
no fix listed
1
library/python:3.8d41127070014
binutils@2.40-2
no fix listed
1
library/python:3.9da5aee29682d
binutils@2.44-3
no fix listed
1
library/sonarqube:10.0.0-communityef9723cf4fe4
binutils@2.38-4ubuntu2.2
no fix listed
1
library/tomcat:11.0.25-jdk17-temurin-noble9e1d2afa6898
binutils@2.42-4ubuntu2.10
no fix listed
1
library/varnish:7.5.04d0bb287d87b
binutils@2.40-2
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
binutils@2.40-2
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
binutils@2.44-3
no fix listed
1
library/wordpress:php8.1-apachef73396626d2f
binutils@2.44-3
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
binutils@2.34-6ubuntu1.7
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
binutils@2.34-6ubuntu1.5
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
binutils@2.34-6ubuntu1.3
no fix listed
1
makersquad/harp-proxy:0.8.1a40dd258c527
binutils@2.40-2
no fix listed
1
mariusm/vingress:0.5.0b3db186c3d72
binutils@2.44-3
no fix listed
1
martinhelmich/typo3:12.4c83a4f3fd7ae
binutils@2.40-2
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
binutils@2.40-2
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
binutils@2.40-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.