StackRadar

CVE-2025-68156

High

Advisory

Published 16 Dec 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
64
of 17,781 indexed, latest versions
Container images
64
deployed by those charts
Fix available
1 of 1
affected package

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

Carried by container images the latest versions of 64 of 17,781 indexed charts deploy, on 64 images.

Affected packageAffected versionsFixed inImages
github.com/expr-lang/exprgolangv1.16.0, v1.16.1, v1.16.2, v1.16.5+6 more1.17.764
OSV records
GHSA-cfpf-hrx2-8rv6
Also known as
GO-2025-4245

Charts affected

64 by stars
ChartLatestAffected imagesRadar Score
onyx-stackonyx0.3.13 of 12See more

onyx-stack onyx 0.3.1

3 of the 12 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.17.272dc058e478d
github.com/expr-lang/expr@v1.17.2
1.17.7
ghcr.io/kedacore/keda-admission-webhooks:2.17.2c8227c6edb4d
github.com/expr-lang/expr@v1.17.2
1.17.7
ghcr.io/kedacore/keda-metrics-apiserver:2.17.2f312f50ddc57
github.com/expr-lang/expr@v1.17.2
1.17.7

Open the chart page →

6,338
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit:1.24.02434560e8f0e
github.com/expr-lang/expr@v1.17.6
1.17.7

Open the chart page →

5,017
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/expr-lang/expr@v1.17.6
1.17.7

Open the chart page →

2,525
adotowan-charts0.1.01 of 1See more

adot owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
github.com/expr-lang/expr@v1.17.0
1.17.7

Open the chart page →

1,016
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
github.com/expr-lang/expr@v1.16.5
1.17.7

Open the chart page →

1,980
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
github.com/expr-lang/expr@v1.17.6
1.17.7

Open the chart page →

4,749
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
github.com/expr-lang/expr@v1.17.0
1.17.7

Open the chart page →

25,934
jaegerromanow-helm-chartsVerified publisher1.7.31 of 1See more

jaeger romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.9.0e128b9adbb29
github.com/expr-lang/expr@v1.17.5
1.17.7

Open the chart page →

1,597
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/expr-lang/expr@v1.16.1
1.17.7

Open the chart page →

1,721
temposb-helm-charts0.4.01 of 1See more

tempo sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
grafana/tempo:2.9.065a578975943
github.com/expr-lang/expr@v1.17.5
1.17.7

Open the chart page →

923
service-exampleservice-example-jt0.1.11 of 9See more

service-example service-example-jt 0.1.1

1 of the 9 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
natsio/nats-box:0.19.28031d190c7ee
github.com/expr-lang/expr@v1.17.6
1.17.7

Open the chart page →

7,157
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
github.com/expr-lang/expr@v1.17.6
1.17.7

Open the chart page →

1,047
kedasoftonic2.17.03 of 3See more

keda softonic 2.17.0

3 of the 3 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.17.0112fc427d933
github.com/expr-lang/expr@v1.17.2
1.17.7
ghcr.io/kedacore/keda-admission-webhooks:2.17.0a87c42275757
github.com/expr-lang/expr@v1.17.2
1.17.7
ghcr.io/kedacore/keda-metrics-apiserver:2.17.0167fd532bd43
github.com/expr-lang/expr@v1.17.2
1.17.7

Open the chart page →

2,583
corednsvks-helm-chartsVerified publisher1.45.01 of 1See more

coredns vks-helm-charts 1.45.0

1 of the 1 container images this version deploys carry CVE-2025-68156.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
github.com/expr-lang/expr@v1.17.6
1.17.7

Open the chart page →

887

Container images carrying it

64 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/loft-sh/kubernetes:v1.35.090097a08b87c
github.com/expr-lang/expr@v1.17.6
1.17.7
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
github.com/expr-lang/expr@v1.16.9
1.17.7
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
github.com/expr-lang/expr@v1.17.6
1.17.7
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
github.com/expr-lang/expr@v1.16.9
1.17.7
1
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
github.com/expr-lang/expr@v1.17.3
1.17.7
1
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
github.com/expr-lang/expr@v1.17.0
1.17.7
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
github.com/expr-lang/expr@v1.16.9
1.17.7
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
github.com/expr-lang/expr@v1.17.5
1.17.7
1
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
github.com/expr-lang/expr@v1.17.5
1.17.7
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/expr-lang/expr@v1.16.0
1.17.7
1
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
github.com/expr-lang/expr@v1.17.5
1.17.7
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/expr-lang/expr@v1.16.0
1.17.7
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/expr-lang/expr@v1.17.6
1.17.7
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
github.com/expr-lang/expr@v1.17.6
1.17.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.