StackRadar

CVE-2025-69725

Medium

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 17,781 indexed, latest versions
Container images
109
deployed by those charts
Fix available
1 of 2
affected packages

chi has an open redirect vulnerability in the RedirectSlashes middleware

Carried by container images the latest versions of 113 of 17,781 indexed charts deploy, on 109 images.

Affected packageAffected versionsFixed inImages
github.com/go-chi/chi/v5golangv5.2.2, v5.2.35.2.432
github.com/go-chi/chigolangv1.5.4, v1.5.5, v3.3.3+incompatible, v3.3.4+incompatible+5 moreno fix listed80
OSV records
GHSA-mqqf-5wvp-8fh8GO-2026-4316

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
rookout-hybridrookout0.3.12 of 2See more

rookout-hybrid rookout 0.3.1

2 of the 2 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
rookout/data-on-prem:latest51c0fce64467
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed

Open the chart page →

3,901
cloudflare-tunnelrubxkubeVerified publisher0.3.31 of 1See more

cloudflare-tunnel rubxkube 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.6.16d91c121b803
github.com/go-chi/chi/v5@v5.2.2
5.2.4

Open the chart page →

595
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
github.com/go-chi/chi/v5@v5.2.2
5.2.4

Open the chart page →

30,219
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed

Open the chart page →

2,960
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed

Open the chart page →

12,668
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
github.com/go-chi/chi@v3.3.4+incompatible
no fix listed

Open the chart page →

3,286
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed

Open the chart page →

1,494
webhook-receiversoftonic2.1.11 of 1See more

webhook-receiver softonic 2.1.1

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
almir/webhook:2.8.01698346f6077
github.com/go-chi/chi@v4.0.2+incompatible
no fix listed

Open the chart page →

1,927
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed

Open the chart page →

4,303
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
github.com/go-chi/chi/v5@v5.2.2
5.2.4

Open the chart page →

2,396
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed

Open the chart page →

2,015
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed

Open the chart page →

4,382
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
github.com/go-chi/chi@v4.0.2+incompatible
no fix listed

Open the chart page →

2,030

Container images carrying it

109 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
github.com/go-chi/chi/v5@v5.2.2
5.2.4
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
quay.io/cortexproject/cortex:v1.21.18577eb292a01
github.com/go-chi/chi/v5@v5.2.2
5.2.4
1
quay.io/gogatekeeper/gatekeeper:4.9.0dcf583aba224
github.com/go-chi/chi/v5@v5.2.3
5.2.4
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
github.com/go-chi/chi@v4.0.0+incompatible
no fix listed
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.