StackRadar

CVE-2025-69873

High

Advisory

Published 11 Feb 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
476
of 17,787 indexed, latest versions
Container images
508
deployed by those charts
Fix available
1 of 2
affected packages

ajv has ReDoS when using `$data` option

Carried by container images the latest versions of 476 of 17,787 indexed charts deploy, on 508 images.

Affected packageAffected versionsFixed inImages
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4, 8.12.0~ds+~2.1.1-5no fix listed4
ajvnpm4.11.8, 5.2.3, 5.5.2, 6.4.0+26 more6.14.0, 8.18.0508
OSV records
UBUNTU-CVE-2025-69873GHSA-2g4f-4pwh-qvx6DEBIAN-CVE-2025-69873

Charts affected

476 by stars
ChartLatestAffected imagesRadar Score
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
ajv@5.5.2
6.14.0

Open the chart page →

9,384
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
ajv@6.12.6
6.14.0

Open the chart page →

1,927
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
ajv@6.12.6
6.14.0

Open the chart page →

2,008
multitenantkvalitetsitVerified publisher2.2.181 of 1See more

multitenant kvalitetsit 2.2.18

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
ajv@6.12.6
6.14.0

Open the chart page →

1,614
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
ajv@6.12.6
6.14.0

Open the chart page →

2,685
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
ajv@6.12.6
6.14.0

Open the chart page →

3,556
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
stremio/server:latest3dc145603def
ajv@6.12.6
6.14.0

Open the chart page →

2,601
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ajv@8.17.1
8.18.0

Open the chart page →

1,392
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
devspacecloud/ui:0.3.3deef55ff29a7
ajv@5.5.2
6.14.0

Open the chart page →

9,880
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-ajv@6.10.2-1
ajv@6.10.2
no fix listed
6.14.0

Open the chart page →

17,836
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
ajv@6.10.2
6.14.0

Open the chart page →

7,931
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
ajv@6.12.6
6.14.0

Open the chart page →

2,248
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
ajv@6.12.2
6.14.0

Open the chart page →

3,651
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
ajv@6.12.6
6.14.0

Open the chart page →

9,786
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
ajv@8.17.1
8.18.0

Open the chart page →

10,908
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
ajv@8.12.0
8.18.0

Open the chart page →

6,722
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
ajv@6.12.6
6.14.0

Open the chart page →

5,288
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
ajv@8.17.1
8.18.0

Open the chart page →

8,351
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ajv@6.12.6
6.14.0

Open the chart page →

5,941
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
ajv@6.12.6
6.14.0

Open the chart page →

9,707
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ajv@6.12.6
6.14.0

Open the chart page →

68,330
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ajv@6.12.6
6.14.0

Open the chart page →

7,027
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
ajv@6.12.6
6.14.0

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
ajv@6.12.6
6.14.0

Open the chart page →

8,361
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
ajv@5.5.2
6.14.0

Open the chart page →

12,862
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
ajv@8.17.1
8.18.0

Open the chart page →

42,983
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ajv@6.12.4
6.14.0

Open the chart page →

10,639
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ajv@6.12.4
6.14.0

Open the chart page →

10,515
iotmmontesVerified publisher0.3.24 of 7See more

iot mmontes 0.3.2

4 of the 7 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
ajv@6.12.6
6.14.0
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
ajv@6.12.6
6.14.0
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
ajv@6.12.6
6.14.0
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
ajv@6.12.6
6.14.0

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ajv@8.6.3
8.18.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.14.0

Open the chart page →

11,734
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ajv@8.6.3
8.18.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.14.0

Open the chart page →

11,734
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ajv@5.5.2
6.14.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.14.0

Open the chart page →

12,147
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ajv@6.12.6
6.14.0

Open the chart page →

2,458
finance-portalmojaloop5.1.44 of 11See more

finance-portal mojaloop 5.1.4

4 of the 11 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
ajv@6.12.6
6.14.0
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ajv@6.12.6
6.14.0
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ajv@6.12.6
6.14.0
mojaloop/role-assignment-service:v2.1.0def4bf273721
ajv@8.12.0
8.18.0

Open the chart page →

14,811
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.14.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ajv@5.5.2
6.14.0

Open the chart page →

11,518
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ajv@8.6.3
8.18.0
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ajv@5.5.2
6.14.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.14.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ajv@5.5.2
6.14.0

Open the chart page →

19,265
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ajv@6.12.6
6.14.0

Open the chart page →

2,632
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ajv@6.12.6
6.14.0

Open the chart page →

2,318
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
ajv@6.12.6
6.14.0

Open the chart page →

1,949
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
ajv@8.12.0
8.18.0

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ajv@6.12.6
6.14.0

Open the chart page →

2,458
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ajv@6.12.6
6.14.0

Open the chart page →

6,438
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
ajv@4.11.8
6.14.0
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
ajv@4.11.8
6.14.0

Open the chart page →

7,048
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
ajv@6.12.6
6.14.0

Open the chart page →

8,556
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
ajv@6.10.2
6.14.0

Open the chart page →

6,684
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
ajv@6.12.6
6.14.0

Open the chart page →

4,908
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
ajv@8.12.0
8.18.0

Open the chart page →

6,646
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
ajv@6.12.6
6.14.0

Open the chart page →

3,128
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
ajv@6.12.6
6.14.0

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
ajv@6.12.6
6.14.0

Open the chart page →

12,861

Container images carrying it

508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.