StackRadar

CVE-2025-69421

High

Advisory

Published 27 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,262
of 17,813 indexed, latest versions
Container images
2,524
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2025-69421 affecting package openssl for versions less than 3.3.5-3

Carried by container images the latest versions of 2,262 of 17,813 indexed charts deploy, on 2,524 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+93 more1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.1.1-1ubuntu2.1~18.04.23+esm7, 1.1.1f-1ubuntu2.24+esm2+5 more1,575
opensslapk3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+34 more3.0.19-r0, 3.3.6-r0, 3.5.5-r0, 3.6.1-r0948
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm320
opensslrpm3.3.5-1.azl33.3.5-31
OSV records
ALPINE-CVE-2025-69421CGA-f52p-r4fw-2gg9DEBIAN-CVE-2025-69421UBUNTU-CVE-2025-69421AZL-75287
Also known as
CGA-ggqp-v682-3mmx, USN-7980-1, USN-7980-2

Charts affected

2,262 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
openssl@3.3.4-r0
3.3.6-r0

Open the chart page →

1,197
dingtalk-botxxl-job-adminVerified publisher0.1.21 of 2See more

dingtalk-bot xxl-job-admin 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2

Open the chart page →

3,185
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
openssl@3.0.16-1~deb12u1
3.0.18-1~deb12u2

Open the chart page →

9,738
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
openssl@3.0.13-1~deb12u1
3.0.18-1~deb12u2

Open the chart page →

3,196
yearningxxl-job-adminVerified publisher0.2.31 of 1See more

yearning xxl-job-admin 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
yeelabs/yearning:v3.1.81576c002d1df
openssl@3.0.8-r3
3.0.19-r0

Open the chart page →

641
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

9,526
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
3.0.18-1~deb12u2

Open the chart page →

2,718
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
openssl@3.0.9-r1
3.0.19-r0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
openssl@3.0.9-r1
3.0.19-r0

Open the chart page →

5,077
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm7

Open the chart page →

2,485
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
openssl@3.0.7-r2
3.0.19-r0
zahoriaut/zahori-server:0.1.17b2de13916f3e
openssl@3.0.8-r3
3.0.19-r0

Open the chart page →

5,846
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm7
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm2

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-69421.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

7,966

Container images carrying it

2,524 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
zahoriaut/zahori-server:0.1.17b2de13916f3e
openssl@3.0.8-r3
3.0.19-r0
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
openssl@3.5.1-r0
3.5.5-r0
1
zedeus/nitter:bc219aa792cc0e4117888b2036a969559f4f26893dd3d5ea33be
openssl@3.0.8-r0
3.0.19-r0
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
openssl@3.0.16-1~deb12u1
3.0.18-1~deb12u2
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
no fix listed
1
zurdi15/romm:2.3.12db88fe44c89
openssl@3.0.12-r1
3.0.19-r0
1
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.21
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.7
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
openssl@1.1.1-1ubuntu2.1~18.04.5
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm7
1.0.2n-1ubuntu5.13+esm3
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
openssl@1.0.2g-1ubuntu4.8
1.0.2g-1ubuntu4.20+esm14
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
openssl@1.0.2g-1ubuntu4.8
1.0.2g-1ubuntu4.20+esm14
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm14
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm2
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm14
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm2
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.7
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.21
1
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
openssl@3.4.1-r2
3.6.1-r0
1
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
openssl@3.4.1-r0
3.6.1-r0
1
gcr.io/kubecost1/kubecost-network-costs:v0.17.6ab6a54c53fd8
openssl@3.3.2-r0
3.6.1-r0
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
openssl@3.0.14-1~deb12u2
3.0.18-1~deb12u2
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm14
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm2
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
openssl@3.0.14-1~deb12u2
3.0.18-1~deb12u2
1
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
openssl@3.3.1-r3
3.3.6-r0
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
openssl@3.0.15-1~deb12u1
3.0.18-1~deb12u2
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
openssl@3.0.15-1~deb12u1
3.0.18-1~deb12u2
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm7
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
openssl@3.3.3-r0
3.3.6-r0
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.7
1
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.7
1
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
openssl@3.0.2-0ubuntu1.25
no fix listed
1
ghcr.io/alekc/samba-docker:v1.1.0cc9a028d9c43
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.7
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
openssl@3.0.18-1~deb12u1
3.0.18-1~deb12u2
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
openssl@3.3.3-r0
3.3.6-r0
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
openssl@3.0.14-1~deb12u2
3.0.18-1~deb12u2
1
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
openssl@3.3.2-r0
3.3.6-r0
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.7
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.21
1
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
openssl@3.3.2-r4
3.3.6-r0
1
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
openssl@3.3.2-r1
3.3.6-r0
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
openssl@3.3.1-r1
3.3.6-r0
1
ghcr.io/appscode/falco-ui-server:v0.0.66ec488d89b56
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
openssl@3.3.3-r0
3.3.6-r0
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.