StackRadar

CVE-2025-69277

Medium

Advisory

Published 31 Dec 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
322
of 17,781 indexed, latest versions
Container images
301
deployed by those charts
Fix available
4 of 4
affected packages

libsodium has Incomplete List of Disallowed Inputs

Carried by container images the latest versions of 322 of 17,781 indexed charts deploy, on 301 images.

Affected packageAffected versionsFixed inImages
libsodiumdeb1.0.8-5, 1.0.16-2, 1.0.18-1, 1.0.18-1+b2+2 more1.0.18-1+deb11u1, 1.0.18-1+deb12u1, 1.0.18-1+deb13u1, 1.0.18-1ubuntu0.22.04.1+2 more148
pynaclpypi1.2.1, 1.3.0, 1.4.0, 1.5.0+2 more1.6.2129
libsodiumapk1.0.19-r0, 1.0.20-r01.0.19-r1, 1.0.20-r123
paragonie/sodium_compatcomposerv1.16.1, v1.17.1, v1.19.0, v1.20.0+2 more1.24.011
OSV records
ALPINE-CVE-2025-69277DEBIAN-CVE-2025-69277GHSA-mrfv-m5wm-5w6wUBUNTU-CVE-2025-69277DLA-4435-1
Also known as
DSA-6094-1, PYSEC-2026-1448, PYSEC-2026-3002, USN-7949-1

Charts affected

322 by stars
ChartLatestAffected imagesRadar Score
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pynacl@1.4.0
1.6.2

Open the chart page →

5,841
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
libsodium@1.0.18-1
1.0.18-1+deb12u1

Open the chart page →

9,102
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libsodium@1.0.18-1build2
1.0.18-1ubuntu0.22.04.1

Open the chart page →

12,048
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
pynacl@1.3.0
1.6.2

Open the chart page →

18,756
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
pynacl@1.4.0
1.6.2

Open the chart page →

7,244
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
pynacl@1.4.0
1.6.2

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
pynacl@1.4.0
1.6.2

Open the chart page →

1,955
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pynacl@1.4.0
1.6.2

Open the chart page →

17,461
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
paragonie/sodium_compat@v1.23.0
1.24.0

Open the chart page →

5,704
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libsodium@1.0.18-1
1.0.18-1+deb12u1

Open the chart page →

9,616
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
pynacl@1.4.0
1.6.2

Open the chart page →

5,321
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
libsodium@1.0.18-1
1.0.18-1+deb12u1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
libsodium@1.0.18-1
no fix listed

Open the chart page →

10,006
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
pynacl@1.5.0
1.6.2

Open the chart page →

3,164
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pynacl@1.4.0
1.6.2

Open the chart page →

3,176
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pynacl@1.5.0
1.6.2

Open the chart page →

4,768
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
libsodium@1.0.18-1
1.0.18-1+deb11u1

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
libsodium@1.0.18-1
1.0.18-1+deb11u1

Open the chart page →

2,132
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pynacl@1.5.0
1.6.2

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libsodium@1.0.18-1
1.0.18-1+deb12u1

Open the chart page →

10,001
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
libsodium@1.0.18-1
1.0.18-1+deb11u1

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-69277.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsodium@1.0.18-1build2
1.0.18-1ubuntu0.22.04.1

Open the chart page →

14,100

Container images carrying it

301 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libsodium@1.0.18-1
no fix listed
1
camptocamp/ekorre:0.1.035c91d5fda04
pynacl@1.3.0
1.6.2
1
castopod/castopod:1.12.101fd37280cbb2
libsodium@1.0.18-1
1.0.18-1+deb12u1
1
cheyang/distributed-tf:1.6.046cc34755493
libsodium@1.0.8-5
no fix listed
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
libsodium@1.0.20-r0
1.0.20-r1
1
chorss/docker-pgadmin4:4.115c549cacb8ab
pynacl@1.3.0
1.6.2
1
ckulka/baikal:0.10.1-nginx434bdd162247
libsodium@1.0.18-1
1.0.18-1+deb12u1
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
pynacl@1.4.0
1.6.2
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
pynacl@1.4.0
1.6.2
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
pynacl@1.5.0
1.6.2
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
pynacl@1.5.0
1.6.2
1
confluentinc/cp-kafka:7.5.1dc9b972db002
pynacl@1.5.0
1.6.2
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
pynacl@1.4.0
1.6.2
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
pynacl@1.4.0
1.6.2
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
pynacl@1.5.0
1.6.2
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
pynacl@1.4.0
1.6.2
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
pynacl@1.4.0
1.6.2
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
pynacl@1.5.0
1.6.2
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
pynacl@1.4.0
1.6.2
1
copyparty/ac:1.19.200a0a8605062c
libsodium@1.0.20-r0
1.0.20-r1
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
libsodium@1.0.18-1+b2
1.0.18-1+deb13u1
1
dannielkil/book-db:latest433290c5c1db
pynacl@1.5.0
1.6.2
1
datadog/agent:7.22.08f20e56b5311
pynacl@1.4.0
1.6.2
1
datadog/agent:6aad9994de6a7
pynacl@1.4.0
1.6.2
1
datamate/seafile-professional:11.0.202dd66b722464
libsodium@1.0.18-1build2
1.0.18-1ubuntu0.22.04.1
1
deepflowce/mysql:8.0.313d7ae561cf60
pynacl@1.4.0
1.6.2
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
libsodium@1.0.18-1+b2
1.0.18-1+deb13u1
1
domainmod/domainmod:4.23.04017bfe4c597
libsodium@1.0.18-1
1.0.18-1+deb12u1
1
dpage/pgadmin4:8.418cd5711fc9a
pynacl@1.5.0
1.6.2
1
dpage/pgadmin4:7.537946e4f3e7b
pynacl@1.5.0
1.6.2
1
dpage/pgadmin4:9.11.050700ac17936
pynacl@1.6.1
1.6.2
1
dpage/pgadmin4:9.252cb72a9e3da
pynacl@1.5.0
1.6.2
1
dpage/pgadmin4:8.13561c1f8f99f2
pynacl@1.5.0
1.6.2
1
dpage/pgadmin4:4.5a5a656e1d5fd
pynacl@1.3.0
1.6.2
1
dpage/pgadmin4:4.22b1f00b8163cf
pynacl@1.3.0
1.6.2
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libsodium@1.0.18-1
1.0.18-1+deb12u1
1
dysnix/pritunl:v1.29-r819951e3e7a32
pynacl@1.3.0
1.6.2
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
pynacl@1.3.0
1.6.2
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libsodium@1.0.16-2
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libsodium@1.0.16-2
no fix listed
1
evk02/mlflow:2.2.1ef6ff257ef35
pynacl@1.5.0
1.6.2
1
extrim/perlite:1.5.99cb7eb5598b6
libsodium@1.0.20-r0
1.0.20-r1
1
felipecs8/app-db-connection-test:v129e06c9c6385
libsodium@1.0.18-1
1.0.18-1+deb12u1
1
filegator/filegator:latestce163db220d4
libsodium@1.0.18-1
1.0.18-1+deb11u1
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libsodium@1.0.18-1
pynacl@1.3.0
no fix listed
1.6.2
1
flanksource/batch-runner:v1.0.44689687a7cf95
pynacl@1.5.0
1.6.2
1
fluent/fluent-bit:4.0-debuge76397ef3983
libsodium@1.0.18-1
1.0.18-1+deb12u1
1
galaxy/cloudman-server:lateste5c265fe9fcd
pynacl@1.5.0
1.6.2
1
galaxy/galaxy-init:v18.010267bad550e6
pynacl@1.2.1
1.6.2
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pynacl@1.5.0
1.6.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.