StackRadar

CVE-2025-69421

High

Advisory

Published 27 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,262
of 17,813 indexed, latest versions
Container images
2,524
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2025-69421 affecting package openssl for versions less than 3.3.5-3

Carried by container images the latest versions of 2,262 of 17,813 indexed charts deploy, on 2,524 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+93 more1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.1.1-1ubuntu2.1~18.04.23+esm7, 1.1.1f-1ubuntu2.24+esm2+5 more1,575
opensslapk3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+34 more3.0.19-r0, 3.3.6-r0, 3.5.5-r0, 3.6.1-r0948
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm320
opensslrpm3.3.5-1.azl33.3.5-31
OSV records
ALPINE-CVE-2025-69421CGA-f52p-r4fw-2gg9DEBIAN-CVE-2025-69421UBUNTU-CVE-2025-69421AZL-75287
Also known as
CGA-ggqp-v682-3mmx, USN-7980-1, USN-7980-2

Charts affected

2,262 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
openssl@3.3.4-r0
3.3.6-r0

Open the chart page →

1,197
dingtalk-botxxl-job-adminVerified publisher0.1.21 of 2See more

dingtalk-bot xxl-job-admin 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2

Open the chart page →

3,185
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
openssl@3.0.16-1~deb12u1
3.0.18-1~deb12u2

Open the chart page →

9,738
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
openssl@3.0.13-1~deb12u1
3.0.18-1~deb12u2

Open the chart page →

3,196
yearningxxl-job-adminVerified publisher0.2.31 of 1See more

yearning xxl-job-admin 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
yeelabs/yearning:v3.1.81576c002d1df
openssl@3.0.8-r3
3.0.19-r0

Open the chart page →

641
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

9,526
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
3.0.18-1~deb12u2

Open the chart page →

2,718
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
openssl@3.0.9-r1
3.0.19-r0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
openssl@3.0.9-r1
3.0.19-r0

Open the chart page →

5,077
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm7

Open the chart page →

2,485
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
openssl@3.0.7-r2
3.0.19-r0
zahoriaut/zahori-server:0.1.17b2de13916f3e
openssl@3.0.8-r3
3.0.19-r0

Open the chart page →

5,846
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm7
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm2

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

7,966

Container images carrying it

2,524 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
temporalio/auto-setup:1.29.15b3502a3b685
openssl@3.5.0-r0
3.5.5-r0
1
temporalio/auto-setup:1.27.2b44cbfeb43db
openssl@3.3.3-r0
3.3.6-r0
1
temporalio/server:1.26.21e2626efcbc1
openssl@3.3.2-r0
3.3.6-r0
1
temporalio/server:1.29.1c1e3326b2ce1
openssl@3.5.0-r0
3.5.5-r0
1
temporalio/ui:2.44.00b36e00aad30
openssl@3.5.4-r0
3.5.5-r0
1
temporalio/ui:2.39.0b768f87f18b5
openssl@3.3.3-r0
3.3.6-r0
1
tensorflow/serving:latest8a208c232297
openssl@3.0.2-0ubuntu1.23
no fix listed
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
openssl@1.0.2g-1ubuntu4.10
1.0.2g-1ubuntu4.20+esm14
1
testinprod/op-erigon:latest0a125bd77a2d
openssl@3.0.17-1~deb12u3
3.0.18-1~deb12u2
1
thecloudspark/app-result:1.09a5302cb8312
openssl@3.3.0-r2
3.3.6-r0
1
thecloudspark/app-vote:1.0c7da7417a86a
openssl@3.3.0-r2
3.3.6-r0
1
thelande/kasa_exporter:v0.2.3a1fdb8baa152
openssl@3.3.0-r2
3.3.6-r0
1
thelande/openmeteo_exporter:v1.0.77e9072ace15f
openssl@3.5.1-r0
3.5.5-r0
1
theradius/loggia:0.463ba348546ec
openssl@3.0.11-1~deb12u2
3.0.18-1~deb12u2
1
thesisrobot/bitcoind:v23.016b368e4d52c
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.21
1
thingsboard/tb-postgres:latest2d17e4e36edc
openssl@3.0.17-1~deb12u3
3.0.18-1~deb12u2
1
thirtythreeforty/neolink:latestf564c4f538de
openssl@3.0.8-r3
3.0.19-r0
1
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
openssl@3.5.1-r0
3.5.5-r0
1
thmmniii/fbs-core:v1.27.15438517d9fc2
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.21
1
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
openssl@3.5.1-r0
3.5.5-r0
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
openssl@3.5.1-r0
3.5.5-r0
1
thongngo3301/stakefish:latesta341af5976e3
openssl@3.0.9-1
3.0.18-1~deb12u2
1
timberio/vector:0.42.0-alpine913878963fde
openssl@3.3.2-r0
3.3.6-r0
1
timescale/timescaledb-ha:pg164f288c0a5213
openssl@3.0.2-0ubuntu1.29
no fix listed
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.21
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.21
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.21
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.21
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
nodejs@7.10.1-2nodesource1~xenial1
openssl@1.0.2g-1ubuntu4.10
no fix listed
1.0.2g-1ubuntu4.20+esm14
1
tobiasehlert/teslamateapi:1.20.2cf09259ad0ea
openssl@3.3.3-r0
3.3.6-r0
1
tobirachel/node-project3:v17d9f37154994
openssl@3.0.9-r1
3.0.19-r0
1
tpdock/freeradius:2.2.93da600c95a49
openssl@1.0.2g-1ubuntu4.9
1.0.2g-1ubuntu4.20+esm14
1
traccar/traccar:6.7-alpine621c8d6d46fd
openssl@3.3.3-r0
3.3.6-r0
1
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
openssl@3.0.8-r0
3.0.19-r0
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
openssl@3.0.15-1~deb12u1
3.0.18-1~deb12u2
1
trinodb/trino:405ee80ab5eeab2
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.21
1
trueosiris/vrising:latest9356f98ad561
openssl@3.0.2-0ubuntu1.23
no fix listed
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
openssl@3.0.10-r0
3.0.19-r0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.21
1
typesense/typesense:0.25.1035ccfbc3fd8
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.21
1
typesense/typesense:0.23.03accb727cbe2
openssl@1.0.2g-1ubuntu4.19
1.0.2g-1ubuntu4.20+esm14
1
typesense/typesense:30.191604dc128e2
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.21
1
typesense/typesense:28.0.rc35dea1b62b7b6e
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.21
1
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm2
1
ubuntu/squid:5.2-22.04_beta723891b5bc74
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.21
1
udhos/apiping:1.5.041ab9bae6f3b
openssl@3.5.4-r0
3.5.5-r0
1
udhos/gateboard:1.12.53acc0e7599bf
openssl@3.5.4-r0
3.5.5-r0
1
udhos/gateboard-discovery:1.9.55567c9363c4c
openssl@3.5.4-r0
3.5.5-r0
1
udhos/lambdaping:1.0.46bd2cf2ac732
openssl@3.3.2-r1
3.3.6-r0
1
udhos/miniapi:1.3.28a7042db82ce
openssl@3.3.2-r1
3.3.6-r0
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.