StackRadar

CVE-2025-69646

Medium

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
263
of 17,781 indexed, latest versions
Container images
266
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 263 of 17,781 indexed charts deploy, on 266 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.40-2, 2.42-4ubuntu2, 2.42-4ubuntu2.3, 2.42-4ubuntu2.5+6 moreno fix listed266
OSV records
DEBIAN-CVE-2025-69646UBUNTU-CVE-2025-69646

Charts affected

263 by stars
ChartLatestAffected imagesRadar Score
nextcloudnextcloud9.2.61 of 1See more

nextcloud nextcloud 9.2.6

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3-apacheb97df9e0e1ee
binutils@2.44-3
no fix listed

Open the chart page →

4,507
falcofalcosecurity9.1.01 of 3See more

falco falcosecurity 9.1.0

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
binutils@2.40-2
no fix listed

Open the chart page →

5,227
jiraatlassian-data-centerVerified publisher2.0.151 of 2See more

jira atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
atlassian/jira-software:11.3.11e5548cd4eea8
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

1,490
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
binutils@2.40-2
no fix listed

Open the chart page →

10,622
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
binutils@2.42-4ubuntu2.7
no fix listed

Open the chart page →

19,391
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
binutils@2.42-4ubuntu2.5
no fix listed

Open the chart page →

3,606
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

22,002
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
binutils@2.42-4ubuntu2.8
no fix listed

Open the chart page →

1,869
yourlsyourlsOfficialVerified publisher8.9.111 of 2See more

yourls yourls 8.9.11

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.69b220ea83329
binutils@2.44-3
no fix listed

Open the chart page →

2,203
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
binutils@2.40-2
no fix listed

Open the chart page →

19,926
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
binutils@2.40-2
no fix listed

Open the chart page →

5,987
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/golang:latest512690a56605
binutils@2.44-3
no fix listed

Open the chart page →

8,390
localstacklocalstack0.7.01 of 1See more

localstack localstack 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
binutils@2.44-3
no fix listed

Open the chart page →

2,156
oneuptimeoneuptimeOfficialVerified publisher13.0.42 of 7See more

oneuptime oneuptime 13.0.4

2 of the 7 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
oneuptime/probe:release6b2d98713711
binutils@2.40-2
no fix listed
oneuptime/runner:release4accc516d800
binutils@2.44-3
no fix listed

Open the chart page →

11,192
prefect-serverprefectVerified publisher2026.9.32126051 of 2See more

prefect-server prefect 2026.9.3212605

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
prefecthq/prefect:3.8.5-python3.110018d02259bc
binutils@2.44-3
no fix listed

Open the chart page →

5,786
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

1,444
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
binutils@2.44-3
no fix listed

Open the chart page →

3,685
supabasetokens-studioVerified publisher1.0.01 of 14See more

supabase tokens-studio 1.0.0

1 of the 14 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
supabase/studio:20241021-9f9b08326d8070c55e9
binutils@2.40-2
no fix listed

Open the chart page →

23,123
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
binutils@2.40-2
no fix listed

Open the chart page →

8,493
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

1,710
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

4,556
devtron-operatordevtron0.23.31 of 11See more

devtron-operator devtron 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed

Open the chart page →

32,902
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
binutils@2.42-4ubuntu2.5
no fix listed

Open the chart page →

3,606
nextcloudgroundhog2k0.22.51 of 3See more

nextcloud groundhog2k 0.22.5

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
binutils@2.44-3
no fix listed

Open the chart page →

4,507
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
binutils@2.44-3
no fix listed

Open the chart page →

5,634
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

2,582
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

1,415
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
binutils@2.40-2
no fix listed

Open the chart page →

6,457
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
binutils@2.44-3
no fix listed

Open the chart page →

4,148
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
binutils@2.40-2
no fix listed

Open the chart page →

14,240
bambooatlassian-data-centerVerified publisher2.0.151 of 2See more

bamboo atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
atlassian/bamboo:12.1.114af4bb6c8d46
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

2,031
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
dolibarr/dolibarr:22.0.47ad88fc9b13c
binutils@2.40-2
no fix listed

Open the chart page →

9,106
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
binutils@2.44-3
no fix listed

Open the chart page →

2,814
glpiglpi-conteiner0.1.02 of 3See more

glpi glpi-conteiner 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
binutils@2.40-2
no fix listed

Open the chart page →

12,170
dolibarrhelmforgeVerified publisher1.2.181 of 3See more

dolibarr helmforge 1.2.18

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
dolibarr/dolibarr:24.0.069ec52e3b7ef
binutils@2.40-2
no fix listed

Open the chart page →

4,109
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
binutils@2.42-4ubuntu2.8
no fix listed
apache/hertzbeat-collector:1.8.0a2bab1be574c
binutils@2.42-4ubuntu2.8
no fix listed

Open the chart page →

14,000
kubeflowkubeflow1.6.21 of 45See more

kubeflow kubeflow 1.6.2

1 of the 45 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/python:3.7eedf63967cdb
binutils@2.40-2
no fix listed

Open the chart page →

96,941
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
binutils@2.40-2
no fix listed

Open the chart page →

19,337
limesurveyarea-42Verified publisher0.3.931 of 2See more

limesurvey area-42 0.3.93

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
adamzammit/limesurvey:7.0.15e75e2f455c8d
binutils@2.44-3
no fix listed

Open the chart page →

4,668
convertigoconvertigoOfficialVerified publisher8.4.32 of 5See more

convertigo convertigo 8.4.3

2 of the 5 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
binutils@2.40-2
no fix listed
library/convertigo:8.4.3ae605bfcda05
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

17,404
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
binutils@2.40-2
no fix listed

Open the chart page →

28,839
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
binutils@2.44-3
no fix listed

Open the chart page →

9,316
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
binutils@2.40-2
no fix listed

Open the chart page →

4,641
terrariahalkeye0.4.21 of 2See more

terraria halkeye 0.4.2

1 of the 2 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
ryshe/terraria:latestb1c89f7f359a
binutils@2.40-2
no fix listed

Open the chart page →

4,127
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
binutils@2.44-3
no fix listed
instill/mgmt-backend:d0933d4ebe12f77a3f9
binutils@2.44-3
no fix listed
instill/model-backend:611f0f2e980125e5ba5
binutils@2.44-3
no fix listed

Open the chart page →

30,816
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

2,582
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
binutils@2.42-4ubuntu2.10
no fix listed

Open the chart page →

8,690
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
binutils@2.44-3
no fix listed

Open the chart page →

5,852
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
binutils@2.44-3
no fix listed

Open the chart page →

9,770
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-69646.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
binutils@2.44-3
no fix listed

Open the chart page →

5,880

Container images carrying it

266 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
photoprism/photoprism:251130db16ee6b1ba3
binutils@2.45-7ubuntu1
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
binutils@2.42-4ubuntu2
no fix listed
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
binutils@2.44-3
no fix listed
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
binutils@2.42-4ubuntu2.8
no fix listed
1
pockost/matomo:5.13.07f5d293cbe4e
binutils@2.44-3
no fix listed
1
polyaxon/polyaxon-api:2.16.42b55c3265a90
binutils@2.44-3
no fix listed
1
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
binutils@2.44-3
no fix listed
1
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
binutils@2.42-4ubuntu2.10
no fix listed
1
prefecthq/prefect:3.8.5-python3.110018d02259bc
binutils@2.44-3
no fix listed
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
binutils@2.40-2
no fix listed
1
pretix/standalone:2026.7.05df3b7aa852e
binutils@2.44-3
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
binutils@2.40-2
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
binutils@2.44-3
no fix listed
1
redash/redash:25.8.000d813437db5
binutils@2.40-2
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
binutils@2.40-2
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
binutils@2.40-2
no fix listed
1
rocketadmin/rocketadmin:1.17.710955ef540b9
binutils@2.40-2
no fix listed
1
rocketchat/freeswitch:stablecfba5c20a5cc
binutils@2.40-2
no fix listed
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
binutils@2.44-3
no fix listed
1
rspamd/rspamd:4.1.4e870599c970d
binutils@2.44-3
no fix listed
1
ryshe/terraria:latestb1c89f7f359a
binutils@2.40-2
no fix listed
1
santisbon/evwatcher:latestc4e994ca4540
binutils@2.40-2
no fix listed
1
santisbon/evworker:lateste807283f8d69
binutils@2.40-2
no fix listed
1
santisbon/speedtest:latest8ee3a1697227
binutils@2.40-2
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
binutils@2.40-2
no fix listed
1
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
binutils@2.44-3
no fix listed
1
signalen/backend:2.50.14760256000738
binutils@2.40-2
no fix listed
1
snipe/snipe-it:v8.3.1141ebf2386fe
binutils@2.42-4ubuntu2.5
no fix listed
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
binutils@2.40-2
no fix listed
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
binutils@2.40-2
no fix listed
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
binutils@2.40-2
no fix listed
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
binutils@2.40-2
no fix listed
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
binutils@2.44-3
no fix listed
1
sslhep/servicex_app:v1.8.51d12f943cec5
binutils@2.44-3
no fix listed
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
binutils@2.44-3
no fix listed
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
binutils@2.44-3
no fix listed
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
binutils@2.44-3
no fix listed
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
binutils@2.44-3
no fix listed
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
binutils@2.44-3
no fix listed
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
binutils@2.44-3
no fix listed
1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
binutils@2.44-3
no fix listed
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
binutils@2.44-3
no fix listed
1
substratusai/verba:v0.4.0-baseURL261695be635eb
binutils@2.40-2
no fix listed
1
supabase/studio:20241021-9f9b08326d8070c55e9
binutils@2.40-2
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
binutils@2.40-2
no fix listed
1
supabase/studio:latest94a2a9d2906e
binutils@2.40-2
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
binutils@2.40-2
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
binutils@2.40-2
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
binutils@2.40-2
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
binutils@2.40-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.