StackRadar

CVE-2025-69725

Medium

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 17,781 indexed, latest versions
Container images
109
deployed by those charts
Fix available
1 of 2
affected packages

chi has an open redirect vulnerability in the RedirectSlashes middleware

Carried by container images the latest versions of 113 of 17,781 indexed charts deploy, on 109 images.

Affected packageAffected versionsFixed inImages
github.com/go-chi/chi/v5golangv5.2.2, v5.2.35.2.432
github.com/go-chi/chigolangv1.5.4, v1.5.5, v3.3.3+incompatible, v3.3.4+incompatible+5 moreno fix listed80
OSV records
GHSA-mqqf-5wvp-8fh8GO-2026-4316

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
rookout-hybridrookout0.3.12 of 2See more

rookout-hybrid rookout 0.3.1

2 of the 2 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
rookout/data-on-prem:latest51c0fce64467
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed

Open the chart page →

3,901
cloudflare-tunnelrubxkubeVerified publisher0.3.31 of 1See more

cloudflare-tunnel rubxkube 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.6.16d91c121b803
github.com/go-chi/chi/v5@v5.2.2
5.2.4

Open the chart page →

595
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
github.com/go-chi/chi/v5@v5.2.2
5.2.4

Open the chart page →

30,219
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed

Open the chart page →

2,960
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed

Open the chart page →

12,668
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
github.com/go-chi/chi@v3.3.4+incompatible
no fix listed

Open the chart page →

3,286
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed

Open the chart page →

1,494
webhook-receiversoftonic2.1.11 of 1See more

webhook-receiver softonic 2.1.1

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
almir/webhook:2.8.01698346f6077
github.com/go-chi/chi@v4.0.2+incompatible
no fix listed

Open the chart page →

1,927
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed

Open the chart page →

4,303
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
github.com/go-chi/chi/v5@v5.2.2
5.2.4

Open the chart page →

2,396
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed

Open the chart page →

2,015
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed

Open the chart page →

4,382
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-69725.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
github.com/go-chi/chi@v4.0.2+incompatible
no fix listed

Open the chart page →

2,030

Container images carrying it

109 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cloudflare/cloudflared:2026.3.06b599ca3e974
github.com/go-chi/chi/v5@v5.2.2
5.2.4
4
ghcr.io/hatchet-dev/hatchet/hatchet-frontend:v0.106.5847c7a9947fd
github.com/go-chi/chi@v1.5.5
no fix listed
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
github.com/go-chi/chi@v1.5.4
no fix listed
3
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
2
cloudflare/cloudflared:2026.6.16d91c121b803
github.com/go-chi/chi/v5@v5.2.2
5.2.4
2
library/influxdb:2.6.1-alpine44a366dd7724
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
2
library/influxdb:2.7b8d940ca9376
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
github.com/go-chi/chi/v5@v5.2.2
5.2.4
2
louislam/uptime-kuma:2.3.29aeb4e51d038
github.com/go-chi/chi/v5@v5.2.2
5.2.4
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
github.com/go-chi/chi/v5@v5.2.2
5.2.4
2
rookout/controller:latest4451a6f6b8ec
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
2
rookout/data-on-prem:latest51c0fce64467
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
2
tkpd/gripmock:1.10.174441dadcfbd
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
github.com/go-chi/chi@v4.0.2+incompatible
no fix listed
2
alcounit/browser-service:v0.0.94bd10defc324
github.com/go-chi/chi/v5@v5.2.3
5.2.4
1
alcounit/browser-ui:v0.0.96a977c92ef27
github.com/go-chi/chi/v5@v5.2.3
github.com/go-chi/chi@v1.5.5
5.2.4
no fix listed
1
alcounit/selenosis:v2.1.1d01a9dbbd943
github.com/go-chi/chi/v5@v5.2.3
5.2.4
1
almir/webhook:2.8.01698346f6077
github.com/go-chi/chi@v4.0.2+incompatible
no fix listed
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
cloudflare/cloudflared:2025.8.0eb5c9324efe3
github.com/go-chi/chi/v5@v5.2.2
5.2.4
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
github.com/go-chi/chi@v3.3.4+incompatible
no fix listed
1
cortezaproject/corteza:2024.9.08eb7a26605c9
github.com/go-chi/chi@v3.3.4+incompatible
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
github.com/go-chi/chi@v3.3.4+incompatible
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
github.com/go-chi/chi/v5@v5.2.3
5.2.4
1
devspacecloud/manager:0.3.349c397413f7b
github.com/go-chi/chi@v3.3.3+incompatible
no fix listed
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
drone/drone:2.28.255897c8fb22d
github.com/go-chi/chi@v3.3.3+incompatible
no fix listed
1
ethersphere/beekeeper:lateste4cda693ed63
github.com/go-chi/chi@v1.5.4
no fix listed
1
ethersphere/ethproxy:latest3a8a3926caa2
github.com/go-chi/chi@v1.5.4
no fix listed
1
factly/dega-api:0.15.166fafc7b0a17
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
factly/dega-server:0.15.194d21479382e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
factly/kavach-server:0.22.3be85ff1b9bd3
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
factly/mande-server:0.34.1384d384310ef
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
factly/vidcheck-server:0.12.087064eb0463c
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
gboxproxy/gbox:v1.0.63a9f4a711d5c
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
github.com/go-chi/chi@v4.0.2+incompatible
no fix listed
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
kubevious/ui:1.2.16233e84bdd59
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
library/caddy:2.660fb54d36b4b
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
library/caddy:2.2.0-alpine7367adca165f
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
library/caddy:2.4.5874405536b3e
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
github.com/go-chi/chi@v4.1.2+incompatible
no fix listed
1
library/influxdb:2.8571eb4514977
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
1
library/influxdb:1.12.3-meta8812029260b5
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
1
library/influxdb:2.7.4-alpinea10d46445d68
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
1
library/influxdb:1.12.3-datab0f9fc41ed79
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
1
library/influxdb:2.0.8ba10ac9ba17a
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
1
library/influxdb:latestf75e48af0598
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
1
library/kapacitor:1.6.37232f6388a4d
github.com/go-chi/chi@v4.1.0+incompatible
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.