CVE-2025-67499
MediumAdvisory
Published 9 Dec 2025In the index since 8 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.6
- base score, highest
- EPSS
- 0.001
- 4th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
CNA Plugins Portmap nftables backend can intercept non-local traffic
Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v1.6.2, v1.7.1 | 1.9.0 | 6 |
- OSV records
- GHSA-jv3w-x3r3-g6rm
- Also known as
- GO-2025-4222
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| lagoon-remotelagoon-chartsVerified publisher | 0.106.0 | 1 of 1See more | 2,113 |
| dockerdkarljorgensen | 0.1.0 | 1 of 1See more | 2,034 |
| spiderpoolkubeblocksVerified publisher | 1.2.0 | 1 of 4See more | 8,378 |
| kube-ovnkube-ovn-test | 1.14.0 | 1 of 1See more | 4,940 |
| lagoon-docker-hostlagoon-chartsVerified publisher | 0.7.0 | 1 of 1See more | 2,113 |
| istio-helm-cnimesosphere | 1.25.1 | 1 of 1See more | 2,533 |
| ciliumnicklasfrahm-ciliumVerified publisher | 0.7.4 | 1 of 6See more | 7,092 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| uselagoon/ | 2c89ed939b8b | github.com/ | 1.9.0 | 2 |
| istio/ | ce27c9ce43c8 | github.com/ | 1.9.0 | 1 |
| kubeovn/ | 6722b54eb5c0 | github.com/ | 1.9.0 | 1 |
| library/ | 2a232a42256f | github.com/ | 1.9.0 | 1 |
| ghcr.io/ | 8edc39be1e22 | github.com/ | 1.9.0 | 1 |
| quay.io/ | 858f807ea4e2 | github.com/ | 1.9.0 | 1 |