CVE-2025-6965
CriticalAdvisory
Published 15 Jul 2025In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.725
- 99th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,281
- of 17,787 indexed, latest versions
- Container images
- 1,286
- deployed by those charts
- Fix available
- 7 of 8
- affected packages
SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite
Carried by container images the latest versions of 1,281 of 17,787 indexed charts deploy, on 1,286 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| SQLitePCLRaw.lib.e_sqlite3nuget | 2.0.4, 2.0.6, 2.1.0, 2.1.6+1 more | no fix listed | 16 |
| sqlite3deb | 3.8.2-1ubuntu2, 3.8.2-1ubuntu2.1, 3.8.2-1ubuntu2.2, 3.11.0-1ubuntu1+27 more | 3.8.2-1ubuntu2.2+esm5, 3.11.0-1ubuntu1.5+esm3, 3.22.0-1ubuntu0.7+esm2, 3.31.1-4ubuntu0.7+esm1+3 more | 798 |
| sqliterpm | 3.7.17-8.el7, 3.7.17-8.el7_7.1, 3.26.0-3.el8, 3.26.0-4.el8_1+13 more | 0:3.7.17-9.el7_9.1, 0:3.26.0-20.el8_10, 0:3.34.1-8.el9_6, 0:3.34.1-9.el9_7 | 294 |
| sqliteapk | 3.41.2-r2, 3.41.2-r3, 3.44.2-r0, 3.44.2-r1+7 more | 3.41.2-r4, 3.44.2-r2, 3.45.3-r3, 3.48.0-r3+1 more | 176 |
| nodejsrpm | 1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd42762, 1:18.18.2-1.module+el8.8.0+20407+c11d40bd+5 more | 1:22.16.0-2.module+el8.10.0+23338+c5a38893, 1:22.16.0-2.module+el9.6.0+23339+d3c8acfa, 1:22.16.0-2.module+el9.6.0+32322+a8b1fd01 | 14 |
| nodejs-packagingrpm | 23-3.module+el8.3.0+6519+9f98ed83 | 0:2021.06-4.module+el8.10.0+23140+4056b950 | 6 |
| nodejs-nodemonrpm | 1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca87034, 3.0.1-1.module+el9.6.0+23146+be9976bd | 0:3.0.1-1.module+el8.10.0+23140+4056b950, 0:3.0.1-1.module+el9.6.0+23339+d3c8acfa | 4 |
| sqlite3rpm | 3.28.0-lp151.2.3.1 | 3.50.3-1.1 | 2 |
- OSV records
- GHSA-2m69-gcr7-jv3qALPINE-CVE-2025-6965DEBIAN-CVE-2025-6965RHSA-2025:11802RHSA-2025:11803RHSA-2025:11992RHSA-2025:12010RHSA-2025:12349RHSA-2025:20936RLSA-2025:11802RLSA-2025:11992RLSA-2025:12010RLSA-2025:20936UBUNTU-CVE-2025-6965openSUSE-SU-2025:15368-1
- Also known as
- BIT-sqlite-2025-6965, RHSA-2025:12036, RHSA-2025:12521, RHSA-2025:12749, RHSA-2025:12901, RHSA-2025:12904, RHSA-2025:12905, USN-7676-1, USN-7679-1
Charts affected
1,281 by stars
Container images carrying it
1,286 by charts deploying them
A fixed version is listed for 7 of the 8 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | d7c43c3135c6 | sqlite3 | 3.31.1-4ubuntu0.7+esm1 | 1 |
| ghcr.io/ | 063eb446e298 | sqlite | 3.44.2-r2 | 1 |
| ghcr.io/ | 8bf880fe8c73 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| ghcr.io/ | b354978c440d | sqlite3 | 3.37.2-2ubuntu0.5 | 1 |
| ghcr.io/ | 50ea1cf0086f | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| ghcr.io/ | a56dfe91f5b1 | sqlite3 | 3.37.2-2ubuntu0.5 | 1 |
| ghcr.io/ | 916746209ac5 | sqlite3 | 3.37.2-2ubuntu0.5 | 1 |
| ghcr.io/ | 63873f3f698e | sqlite3 | 3.37.2-2ubuntu0.5 | 1 |
| ghcr.io/ | 563ce7794a71 | sqlite | 3.44.2-r2 | 1 |
| ghcr.io/ | 6df27f944fe8 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| ghcr.io/ | dbaa8527bf4c | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| ghcr.io/ | d19d886d5090 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| ghcr.io/ | 8e6a9516eac0 | sqlite3 | 3.22.0-1ubuntu0.7+esm2 | 1 |
| ghcr.io/ | 5a6fe78d4d15 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| ghcr.io/ | bf5983d754d7 | sqlite | 3.45.3-r3 | 1 |
| ghcr.io/ | 34c7b540a095 | sqlite | 3.45.3-r3 | 1 |
| ghcr.io/ | fbba58ddb1a6 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| ghcr.io/ | 7dc0ee57b628 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| mcr.microsoft.com/ | 13221ac5f673 | sqlite3 | 3.22.0-1ubuntu0.7+esm2 | 1 |
| mcr.microsoft.com/ | 49a57dc220b1 | sqlite3 | 3.31.1-4ubuntu0.7+esm1 | 1 |
| mcr.microsoft.com/ | fbf79e0fea59 | sqlite3 | 3.22.0-1ubuntu0.7+esm2 | 1 |
| public.ecr.aws/ | 9026dbbf280d | sqlite | 0:3.34.1-9.el9_7 | 1 |
| public.ecr.aws/ | b1493760c716 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| public.ecr.aws/ | 5cd62142d6ed | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| public.ecr.aws/ | 36d051110158 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| public.ecr.aws/ | 9e14a72b066d | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| public.ecr.aws/ | f7567ce3419d | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| public.ecr.aws/ | 849e235e2d3e | sqlite | 0:3.26.0-20.el8_10 | 1 |
| public.ecr.aws/ | 9083e60c38bc | sqlite | 0:3.34.1-8.el9_6 | 1 |
| public.ecr.aws/ | d7c3def9252b | sqlite | 0:3.34.1-8.el9_6 | 1 |
| public.ecr.aws/ | efcecf98b912 | sqlite3 | 3.22.0-1ubuntu0.7+esm2 | 1 |
| public.ecr.aws/ | 573779e57fae | sqlite3 | 3.31.1-4ubuntu0.7+esm1 | 1 |
| public.ecr.aws/ | f74851ce31f5 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| public.ecr.aws/ | 794b3bff9510 | sqlite | 0:3.34.1-8.el9_6 | 1 |
| public.ecr.aws/ | c265156b00d1 | sqlite | 0:3.34.1-8.el9_6 | 1 |
| quay.io/ | 70d138997acd | nodejs sqlite | 1:22.16.0-2.module+el9.6.0+23339+d3c8acfa 0:3.34.1-8.el9_6 | 1 |
| quay.io/ | 7302e0c8e5a7 | sqlite | 0:3.26.0-20.el8_10 | 1 |
| quay.io/ | 3b036692d546 | sqlite | 0:3.26.0-20.el8_10 | 1 |
| quay.io/ | 5b6701d8fb31 | sqlite3 | 3.37.2-2ubuntu0.5 | 1 |
| quay.io/ | 95b5cf7ba6fe | sqlite3 | 3.45.1-1ubuntu2.4 | 1 |
| quay.io/ | acaf37352569 | sqlite3 | 3.37.2-2ubuntu0.5 | 1 |
| quay.io/ | cdefc81c6b2e | sqlite | 0:3.26.0-20.el8_10 | 1 |
| quay.io/ | 13aaae779248 | sqlite | 0:3.26.0-20.el8_10 | 1 |
| quay.io/ | a9f835d1b241 | sqlite3 | 3.40.1-2+deb12u2 | 1 |
| quay.io/ | 10df27bc5560 | nodejs nodejs-packaging sqlite | 1:22.16.0-2.module+el8.10.0+23338+c5a38893 0:2021.06-4.module+el8.10.0+23140+4056b950 0:3.26.0-20.el8_10 | 1 |
| quay.io/ | d752a1c2a7b7 | sqlite | 0:3.26.0-20.el8_10 | 1 |
| quay.io/ | a3b9a07648b6 | sqlite | 0:3.26.0-20.el8_10 | 1 |
| quay.io/ | 14ff275b2e61 | sqlite | 0:3.34.1-8.el9_6 | 1 |
| quay.io/ | a2d3a4c67b0f | sqlite3 | 3.22.0-1ubuntu0.7+esm2 | 1 |