StackRadar

CVE-2025-67221

High

Advisory

Published 22 Jan 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
65
of 17,781 indexed, latest versions
Container images
77
deployed by those charts
Fix available
1 of 1
affected package

orjson does not limit recursion for deeply nested JSON documents

Carried by container images the latest versions of 65 of 17,781 indexed charts deploy, on 77 images.

Affected packageAffected versionsFixed inImages
orjsonpypi2.6.1, 2.6.8, 3.3.1, 3.5.2+18 more3.11.677
OSV records
GHSA-hx9q-6w63-j58v
Also known as
PYSEC-2026-107

Charts affected

65 by stars
ChartLatestAffected imagesRadar Score
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
orjson@3.10.7
3.11.6
opea/embedding-tei:1.05c9639de61c1
orjson@3.10.7
3.11.6
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6
opea/reranking-tei:1.0e48613afb191
orjson@3.10.7
3.11.6
opea/retriever-redis:1.0eb746b263705
orjson@3.10.7
3.11.6

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
orjson@3.10.7
3.11.6
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
orjson@3.10.7
3.11.6
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
orjson@3.10.7
3.11.6
opea/llm-docsum-tgi:1.002f9e8fa5d71
orjson@3.10.7
3.11.6

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
orjson@3.10.7
3.11.6

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
orjson@3.10.7
3.11.6

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
orjson@3.10.7
3.11.6

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
orjson@3.10.7
3.11.6

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
orjson@3.10.7
3.11.6

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
orjson@3.10.7
3.11.6

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
orjson@3.10.7
3.11.6

Open the chart page →

5,350
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
orjson@3.10.3
3.11.6

Open the chart page →

1,515
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
orjson@3.3.1
3.11.6

Open the chart page →

4,086
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
orjson@3.10.3
3.11.6

Open the chart page →

10,843

Container images carrying it

77 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
stackstorm/st2auth:3.833ecfda16608
orjson@3.5.2
3.11.6
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
orjson@3.5.2
3.11.6
1
stackstorm/st2notifier:3.8f190a6212195
orjson@3.5.2
3.11.6
1
stackstorm/st2rulesengine:3.8259503496ff9
orjson@3.5.2
3.11.6
1
stackstorm/st2scheduler:3.8b1de2055c362
orjson@3.5.2
3.11.6
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
orjson@3.5.2
3.11.6
1
stackstorm/st2stream:3.81c8904a3bf67
orjson@3.5.2
3.11.6
1
stackstorm/st2timersengine:3.81bf35bfaf00c
orjson@3.5.2
3.11.6
1
stackstorm/st2workflowengine:3.819fdfffdbba8
orjson@3.5.2
3.11.6
1
thelande/kasa_exporter:v0.2.3a1fdb8baa152
orjson@3.10.3
3.11.6
1
witcherek7/pav:0.0.342a744f29ac0
orjson@3.8.3
3.11.6
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
orjson@3.10.12
3.11.6
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
orjson@3.11.5
3.11.6
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
orjson@3.10.6
3.11.6
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
orjson@3.10.12
3.11.6
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
orjson@3.11.3
3.11.6
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
orjson@3.9.9
3.11.6
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
orjson@3.11.5
3.11.6
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
orjson@3.11.3
3.11.6
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
orjson@3.11.3
3.11.6
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
orjson@3.10.0
3.11.6
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
orjson@3.11.5
3.11.6
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
orjson@3.11.5
3.11.6
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
orjson@3.10.16
3.11.6
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
orjson@3.11.3
3.11.6
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
orjson@3.10.3
3.11.6
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
orjson@3.11.4
3.11.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.