StackRadar

CVE-2025-67721

High

Advisory

Published 12 Dec 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
59
of 17,781 indexed, latest versions
Container images
68
deployed by those charts
Fix available
2 of 2
affected packages

aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

Carried by container images the latest versions of 59 of 17,781 indexed charts deploy, on 68 images.

Affected packageAffected versionsFixed inImages
aircompressormaven0.3, 0.8, 0.9, 0.10+6 more2.0.368
aircompressor-v3maven3.23.42
OSV records
GHSA-vx9q-rhv9-3jvg

Charts affected

59 by stars
ChartLatestAffected imagesRadar Score
trinopresto-loadbalancer0.2.101 of 2See more

trino presto-loadbalancer 0.2.10

1 of the 2 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
trinodb/trino:4796af989b0846d
aircompressor@2.0.2
2.0.3

Open the chart page →

2,264
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
aircompressor@0.27
2.0.3

Open the chart page →

21,211
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
aircompressor@0.20
2.0.3

Open the chart page →

8,804
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
fthomas/scala-steward:latest367afe974b7a
aircompressor@0.27
2.0.3

Open the chart page →

589
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
aircompressor@2.0.2
2.0.3

Open the chart page →

1,702
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
aircompressor@0.21
2.0.3

Open the chart page →

13,767
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
aircompressor@0.27
2.0.3

Open the chart page →

1,827
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
aircompressor@0.10
2.0.3

Open the chart page →

9,397
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-67721.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
aircompressor@0.27
2.0.3

Open the chart page →

2,634

Container images carrying it

68 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
metabase/metabase:v0.53.4.17807bc5cad17
aircompressor@0.27
2.0.3
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
aircompressor@0.26
2.0.3
1
resurfaceio/resurface:3.7.84d5cda2f64109
aircompressor@2.0.2
aircompressor-v3@3.2
2.0.3
3.4
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
aircompressor@0.8
2.0.3
1
sslhep/hive-metastore:3.1.39e80af083079
aircompressor@0.10
2.0.3
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
aircompressor@0.27
2.0.3
1
trinodb/trino:45038c6f24ab1a4
aircompressor@0.27
2.0.3
1
trinodb/trino:4796af989b0846d
aircompressor@2.0.2
2.0.3
1
trinodb/trino:405ee80ab5eeab2
aircompressor@0.21
2.0.3
1
vespaengine/vespa:8.526.1569b160f58211
aircompressor@0.27
2.0.3
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
aircompressor@0.20
2.0.3
1
ghcr.io/joffreybvn/k8s-geyser:0.0.247f36880072e
aircompressor@0.27
2.0.3
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
aircompressor@0.27
2.0.3
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
aircompressor@0.8
2.0.3
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
aircompressor@0.20
2.0.3
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
aircompressor@0.20
2.0.3
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
aircompressor@0.10
2.0.3
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
aircompressor@2.0.2
aircompressor-v3@3.2
2.0.3
3.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.