StackRadar

CVE-2025-67221

High

Advisory

Published 22 Jan 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
65
of 17,781 indexed, latest versions
Container images
77
deployed by those charts
Fix available
1 of 1
affected package

orjson does not limit recursion for deeply nested JSON documents

Carried by container images the latest versions of 65 of 17,781 indexed charts deploy, on 77 images.

Affected packageAffected versionsFixed inImages
orjsonpypi2.6.1, 2.6.8, 3.3.1, 3.5.2+18 more3.11.677
OSV records
GHSA-hx9q-6w63-j58v
Also known as
PYSEC-2026-107

Charts affected

65 by stars
ChartLatestAffected imagesRadar Score
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
orjson@3.10.7
3.11.6
opea/embedding-tei:1.05c9639de61c1
orjson@3.10.7
3.11.6
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6
opea/reranking-tei:1.0e48613afb191
orjson@3.10.7
3.11.6
opea/retriever-redis:1.0eb746b263705
orjson@3.10.7
3.11.6

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
orjson@3.10.7
3.11.6
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
orjson@3.10.7
3.11.6
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
orjson@3.10.7
3.11.6
opea/llm-docsum-tgi:1.002f9e8fa5d71
orjson@3.10.7
3.11.6

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
orjson@3.10.7
3.11.6

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
orjson@3.10.7
3.11.6

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
orjson@3.10.7
3.11.6

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
orjson@3.10.7
3.11.6

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
orjson@3.10.7
3.11.6

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
orjson@3.10.7
3.11.6

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
orjson@3.10.7
3.11.6

Open the chart page →

5,350
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
orjson@3.10.3
3.11.6

Open the chart page →

1,515
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
orjson@3.3.1
3.11.6

Open the chart page →

4,086
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2025-67221.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
orjson@3.10.3
3.11.6

Open the chart page →

10,843

Container images carrying it

77 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
orjson@3.10.7
3.11.6
4
datawire/aes:1.14.48588eafe6862
orjson@3.3.1
3.11.6
2
opea/embedding-tei:1.05c9639de61c1
orjson@3.10.7
3.11.6
2
opea/reranking-tei:1.0e48613afb191
orjson@3.10.7
3.11.6
2
opea/retriever-redis:1.0eb746b263705
orjson@3.10.7
3.11.6
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
orjson@3.10.15
3.11.6
2
airbyte/manifest-server:7.23.73b3a670af168
orjson@3.10.15
3.11.6
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
orjson@3.8.10
3.11.6
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
orjson@3.10.16
3.11.6
1
baserow/backend:1.31.1e0b3c8130b91
orjson@3.10.3
3.11.6
1
baserow/baserow:1.30.1df0c42eb67e8
orjson@3.10.3
3.11.6
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
orjson@3.11.4
3.11.6
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
orjson@3.10.6
3.11.6
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
orjson@3.10.6
3.11.6
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
orjson@3.10.6
3.11.6
1
datadog/agent:7.22.08f20e56b5311
orjson@2.6.1
3.11.6
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
orjson@3.3.1
3.11.6
1
datawire/aes:1.13.62beb65062c8b
orjson@3.3.1
3.11.6
1
datawire/aes:3.11.195ec30b3c732
orjson@3.10.3
3.11.6
1
datawire/emissary:3.12.21f67a1292d2a
orjson@3.10.3
3.11.6
1
datawire/emissary:2.0.2-ea9716efbdd24b
orjson@3.3.1
3.11.6
1
evk02/mlflow:2.2.1ef6ff257ef35
orjson@3.8.7
3.11.6
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
orjson@3.8.3
3.11.6
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
orjson@3.9.7
3.11.6
1
homeassistant/home-assistant:2023.12.48d000332b09b
orjson@3.9.9
3.11.6
1
ilum/streamlit-example:1.0.0ce5dcdeb22ba
orjson@3.11.4
3.11.6
1
langgenius/dify-api:1.0.0066035f93856
orjson@3.10.15
3.11.6
1
langgenius/dify-api:0.6.11fca918260dd6
orjson@3.10.5
3.11.6
1
lsstsqre/kafkaaggregator:masterbe1b21060854
orjson@2.6.8
3.11.6
1
makersquad/harp-proxy:0.8.1a40dd258c527
orjson@3.10.16
3.11.6
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
orjson@3.8.0
3.11.6
1
opea/asr:1.025dd26d9cd09
orjson@3.10.7
3.11.6
1
opea/chatqna:1.038c51b791efa
orjson@3.10.7
3.11.6
1
opea/codegen:1.058f91683892d
orjson@3.10.7
3.11.6
1
opea/codetrans:1.0e2436483b73d
orjson@3.10.7
3.11.6
1
opea/docsum:1.03eaa91849512
orjson@3.10.7
3.11.6
1
opea/guardrails-tgi:1.0262c6048aab8
orjson@3.10.7
3.11.6
1
opea/guardrails-tgi:latestf68bec6a1271
orjson@3.10.13
3.11.6
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
orjson@3.10.7
3.11.6
1
opea/speecht5:1.0249afad3d268
orjson@3.10.7
3.11.6
1
opea/tts:1.0257ae94709e9
orjson@3.10.7
3.11.6
1
opea/web-retriever-chroma:1.0fe08165d7770
orjson@3.10.7
3.11.6
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
orjson@3.10.15
3.11.6
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
orjson@3.11.5
3.11.6
1
opendatacube/explorer:latest120457ffcd69
orjson@3.11.4
3.11.6
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
orjson@3.10.7
3.11.6
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
orjson@3.10.6
3.11.6
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
orjson@3.10.12
3.11.6
1
stackstorm/st2actionrunner:3.888235ba70cad
orjson@3.5.2
3.11.6
1
stackstorm/st2api:3.86f56d239d280
orjson@3.5.2
3.11.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.