StackRadar

CVE-2025-69646

Medium

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
263
of 17,781 indexed, latest versions
Container images
266
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 263 of 17,781 indexed charts deploy, on 266 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.40-2, 2.42-4ubuntu2, 2.42-4ubuntu2.3, 2.42-4ubuntu2.5+6 moreno fix listed266
OSV records
DEBIAN-CVE-2025-69646UBUNTU-CVE-2025-69646

Charts affected

263 by stars
ChartLatestAffected imagesRadar Score
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
binutils@2.40-2
no fix listed

Open the chart page →

40,238
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
binutils@2.40-2
no fix listed
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
binutils@2.40-2
no fix listed
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
binutils@2.40-2
no fix listed

Open the chart page →

45,363
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
binutils@2.40-2
no fix listed

Open the chart page →

32,501
bamboo-agentatlassian-data-centerVerified publisher2.0.151 of 1See more

bamboo-agent atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

1,581
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
binutils@2.40-2
no fix listed

Open the chart page →

10,145
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
binutils@2.40-2
no fix listed
sysnet4admin/colosseum-prm:log5802bfcd7fed
binutils@2.40-2
no fix listed

Open the chart page →

26,996
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
binutils@2.42-4ubuntu2.5
no fix listed

Open the chart page →

14,352
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
binutils@2.40-2
no fix listed

Open the chart page →

10,776
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
binutils@2.40-2
no fix listed

Open the chart page →

5,778
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
binutils@2.40-2
no fix listed

Open the chart page →

5,904
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
binutils@2.40-2
no fix listed

Open the chart page →

11,995
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
binutils@2.40-2
no fix listed

Open the chart page →

8,009
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
binutils@2.40-2
no fix listed

Open the chart page →

9,128
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
binutils@2.42-4ubuntu2.3
no fix listed

Open the chart page →

4,578
cohdicohdi0.2.21 of 3See more

cohdi cohdi 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
binutils@2.44-3
no fix listed

Open the chart page →

3,694
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
binutils@2.40-2
no fix listed

Open the chart page →

14,559
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
cspconsole/csp-control-center:1.0.1046dda4a31bd6
binutils@2.40-2
no fix listed

Open the chart page →

12,274
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
binutils@2.40-2
no fix listed

Open the chart page →

16,604
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
binutils@2.40-2
no fix listed

Open the chart page →

5,062
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
binutils@2.40-2
no fix listed

Open the chart page →

10,090
devtron-enterprisedevtron48.0.02 of 28See more

devtron-enterprise devtron 48.0.0

2 of the 28 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed

Open the chart page →

68,240
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed

Open the chart page →

32,902
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

19,224
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
binutils@2.40-2
no fix listed

Open the chart page →

7,141
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
binutils@2.42-4ubuntu2
no fix listed

Open the chart page →

16,954
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
binutils@2.40-2
no fix listed

Open the chart page →

14,627
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
binutils@2.44-3
no fix listed

Open the chart page →

13,391
esphomeegebackVerified publisher2.0.251 of 1See more

esphome egeback 2.0.25

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
esphome/esphome:2026.7.44866347cb5b4
binutils@2.44-3
no fix listed

Open the chart page →

3,121
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
binutils@2.44-3
no fix listed

Open the chart page →

7,233
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
binutils@2.40-2
no fix listed

Open the chart page →

5,290
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
binutils@2.44-3
no fix listed

Open the chart page →

6,431
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

7,368
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

7,368
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/node:latestf5d1cc40abc1
binutils@2.44-3
no fix listed

Open the chart page →

6,851
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
binutils@2.40-2
no fix listed

Open the chart page →

10,741
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed

Open the chart page →

4,829
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,704
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
binutils@2.40-2
no fix listed

Open the chart page →

64,489
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,704
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
binutils@2.40-2
no fix listed

Open the chart page →

3,463
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
binutils@2.44-3
no fix listed

Open the chart page →

3,112
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
binutils@2.40-2
no fix listed

Open the chart page →

9,077
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
binutils@2.40-2
no fix listed

Open the chart page →

12,958
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
binutils@2.44-3
no fix listed

Open the chart page →

8,923
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
binutils@2.40-2
no fix listed

Open the chart page →

12,170
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
binutils@2.40-2
no fix listed

Open the chart page →

49,025
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
binutils@2.40-2
no fix listed

Open the chart page →

24,995

Container images carrying it

266 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
binutils@2.44-3
no fix listed
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
binutils@2.44-3
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
binutils@2.40-2
no fix listed
1
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
binutils@2.40-2
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
binutils@2.40-2
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
binutils@2.40-2
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
binutils@2.40-2
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
binutils@2.40-2
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
binutils@2.42-4ubuntu2.3
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
binutils@2.40-2
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
binutils@2.44-3
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
binutils@2.42-4ubuntu2.5
no fix listed
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
binutils@2.44-3
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
binutils@2.44-3
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
binutils@2.40-2
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
binutils@2.44-3
no fix listed
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
binutils@2.42-4ubuntu2.10
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
binutils@2.40-2
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
binutils@2.40-2
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
binutils@2.40-2
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
binutils@2.40-2
no fix listed
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
binutils@2.44-3
no fix listed
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
binutils@2.40-2
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
binutils@2.40-2
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
binutils@2.40-2
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
binutils@2.40-2
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
binutils@2.44-3
no fix listed
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
binutils@2.44-3
no fix listed
1
esphome/esphome:2026.7.44866347cb5b4
binutils@2.44-3
no fix listed
1
esphome/esphome:2026.8.285abea33854b
binutils@2.44-3
no fix listed
1
espocrm/espocrm:9.3.101b5a24504ed9
binutils@2.44-3
no fix listed
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
binutils@2.40-2
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
binutils@2.40-2
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
binutils@2.44-3
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
binutils@2.40-2
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
binutils@2.40-2
no fix listed
1
glpi/glpi:latest4b681082a79e
binutils@2.44-3
no fix listed
1
gulacedia/web-dvwa-new:v367b467d961ca
binutils@2.40-2
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
binutils@2.40-2
no fix listed
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
binutils@2.40-2
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
binutils@2.44-3
no fix listed
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
binutils@2.44-3
no fix listed
1
instill/model-backend:611f0f2e980125e5ba5
binutils@2.44-3
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
binutils@2.40-2
no fix listed
1
jaedb/iris:latest048cfbf58d57
binutils@2.40-2
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
binutils@2.40-2
no fix listed
1
kimai/kimai2:2.65.06dfc63199654
binutils@2.40-2
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
binutils@2.44-3
no fix listed
1
kixote/typemill4e9dff179519
binutils@2.44-3
no fix listed
1
kixote/typemill628f79a08cc7
binutils@2.44-3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.