StackRadar

CVE-2025-69873

High

Advisory

Published 11 Feb 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
475
of 17,781 indexed, latest versions
Container images
507
deployed by those charts
Fix available
1 of 2
affected packages

ajv has ReDoS when using `$data` option

Carried by container images the latest versions of 475 of 17,781 indexed charts deploy, on 507 images.

Affected packageAffected versionsFixed inImages
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
ajvnpm4.11.8, 5.2.3, 5.5.2, 6.4.0+25 more6.14.0, 8.18.0507
OSV records
UBUNTU-CVE-2025-69873GHSA-2g4f-4pwh-qvx6

Charts affected

475 by stars
ChartLatestAffected imagesRadar Score
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
ajv@8.17.1
8.18.0
sysnet4admin/colosseum-prm:log5802bfcd7fed
ajv@8.17.1
8.18.0

Open the chart page →

26,996
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
ajv@6.12.6
6.14.0

Open the chart page →

3,071
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
ajv@4.11.8
6.14.0

Open the chart page →

4,069
rtorrent-floodbryanalves0.5.01 of 1See more

rtorrent-flood bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
jesec/flood:4.7.03d1d0bec117a
ajv@6.12.6
6.14.0

Open the chart page →

1,477
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
ajv@6.12.6
6.14.0

Open the chart page →

951
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ajv@8.17.1
8.18.0

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
ajv@6.12.6
6.14.0

Open the chart page →

4,083
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
ajv@6.12.6
6.14.0

Open the chart page →

1,977
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
ajv@6.12.6
6.14.0
countly/frontend:25.05.42acbc11499b6
ajv@6.12.6
6.14.0

Open the chart page →

7,295
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
ajv@8.17.1
8.18.0

Open the chart page →

2,759
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
ajv@5.2.3
6.14.0

Open the chart page →

29,901
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
ajv@5.2.3
6.14.0

Open the chart page →

27,417
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
ajv@5.2.3
6.14.0

Open the chart page →

33,963
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
ajv@5.5.2
6.14.0

Open the chart page →

2,580
kube-slackcloudnativeapp1.0.01 of 1See more

kube-slack cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
willwill/kube-slack:v4.1.1d443017aae98
ajv@5.5.2
6.14.0

Open the chart page →

1,937
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
ajv@6.9.2
6.14.0

Open the chart page →

4,790
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
ajv@6.5.5
6.14.0

Open the chart page →

25,456
robot-shopcloud-native-toolkit1.1.13 of 12See more

robot-shop cloud-native-toolkit 1.1.1

3 of the 12 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
robotshop/rs-cart:latest388349d5cb3c
ajv@6.12.6
6.14.0
robotshop/rs-catalogue:latestd545747c1b97
ajv@6.12.6
6.14.0
robotshop/rs-user:latestea509182c180
ajv@6.12.6
6.14.0

Open the chart page →

29,555
setup-jobcloud-native-toolkit0.3.01 of 2See more

setup-job cloud-native-toolkit 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
ajv@5.5.2
6.14.0

Open the chart page →

2,792
slack-notificationscloud-native-toolkit0.1.71 of 1See more

slack-notifications cloud-native-toolkit 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
ajv@6.12.6
6.14.0

Open the chart page →

1,545
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ajv@6.12.6
6.14.0
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ajv@6.12.6
6.14.0
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ajv@6.12.6
6.14.0

Open the chart page →

18,293
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
ajv@4.11.8
6.14.0

Open the chart page →

70,895
maildevcnieg1.1.11 of 1See more

maildev cnieg 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
cnieg/maildev:v1.1.998ee05668915
ajv@5.5.2
6.14.0

Open the chart page →

2,449
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-ajv@8.12.0~ds+~2.1.1-4
ajv@8.12.0
no fix listed
8.18.0

Open the chart page →

13,220
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
ajv@6.12.6
6.14.0

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
ajv@6.12.6
6.14.0

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
ajv@6.12.6
6.14.0

Open the chart page →

5,141
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
ajv@7.1.1
8.18.0

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.02 of 7See more

containers-security-charts containers-security 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
ajv@6.12.6
6.14.0
coldatom/containers-security-front:latest7c2fbbb41bcf
ajv@8.12.0
8.18.0

Open the chart page →

9,146
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
ajv@6.12.6
6.14.0

Open the chart page →

8,368
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
ajv@6.12.6
6.14.0

Open the chart page →

5,488
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ajv@5.5.2
6.14.0

Open the chart page →

5,209
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
ajv@8.17.1
8.18.0

Open the chart page →

3,769
swagger-combine-uicryptexlabsVerified publisher0.2.41 of 1See more

swagger-combine-ui cryptexlabs 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
ajv@6.12.6
6.14.0

Open the chart page →

1,378
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
ajv@6.12.6
6.14.0

Open the chart page →

13,852
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
ajv@6.12.6
6.14.0

Open the chart page →

22,193
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
ajv@6.12.6
6.14.0

Open the chart page →

3,042
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
ajv@6.12.6
6.14.0

Open the chart page →

2,529
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
ajv@6.12.6
6.14.0

Open the chart page →

11,909
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
ajv@6.12.6
6.14.0

Open the chart page →

11,909
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
ajv@6.12.6
6.14.0
oscarsotosanchez/weatherservice:v1.0911ec961d10b
ajv@6.12.6
6.14.0

Open the chart page →

27,550
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
ajv@6.12.5
6.14.0
langgenius/dify-web:1.0.0d64914ff0d6d
ajv@6.12.6
6.14.0

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
ajv@6.12.6
6.14.0

Open the chart page →

4,551
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
ajv@6.12.6
6.14.0

Open the chart page →

2,862
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
ajv@5.5.2
6.14.0

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
ajv@6.12.6
6.14.0
oscarsotosanchez/weatherservice:v1.0911ec961d10b
ajv@6.12.6
6.14.0

Open the chart page →

24,656
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2025-69873.

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
ajv@5.5.2
6.14.0

Open the chart page →

11,174
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
ajv@6.12.6
6.14.0

Open the chart page →

1,693
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-69873.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
ajv@6.12.6
6.14.0

Open the chart page →

3,744

Container images carrying it

507 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
koumoul/openapi-viewer:18eeca2e8285b
ajv@5.2.3
6.14.0
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
ajv@6.12.6
6.14.0
1
kubebb/component-store:latestfd8ecbd73213
ajv@6.12.6
6.14.0
1
kubebb/tamp-portal:v5.6.0fadac6d52470
ajv@6.12.6
6.14.0
1
kubebb/tdsf-portal:v5.7.0258458311bc9
ajv@6.12.6
6.14.0
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
ajv@6.9.2
6.14.0
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ajv@6.9.2
6.14.0
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
ajv@5.5.2
6.14.0
1
kubevious/backend:1.2.22d9ba6eb46b6
ajv@6.12.6
6.14.0
1
kubevious/collector:1.2.1f58226f9d84e
ajv@6.12.6
6.14.0
1
kubevious/guard:1.2.19bf567704de2
ajv@6.12.6
6.14.0
1
kubevious/parser:1.0.151acf1a1f0b47
ajv@6.12.6
6.14.0
1
kubevious/parser:1.2.299ae7a5168c2
ajv@6.12.6
6.14.0
1
kubevious/workload-operator:1.0.20b0f4c507eb6
ajv@6.12.6
6.14.0
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
ajv@6.12.6
6.14.0
1
kyleslugg/klusterview:latestba8c36dfdfbd
ajv@8.12.0
8.18.0
1
kyso/kyso-front:lateste52595c5c16f
ajv@6.12.6
6.14.0
1
langgenius/dify-api:1.0.0066035f93856
ajv@6.12.5
6.14.0
1
langgenius/dify-api:0.6.11fca918260dd6
ajv@6.12.5
6.14.0
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ajv@8.17.1
8.18.0
1
langgenius/dify-web:1.0.0d64914ff0d6d
ajv@6.12.6
6.14.0
1
lavandadelpatio/frontend:latest501c3f31e0bc
ajv@6.12.2
6.14.0
1
leeyoongti/first-app:1.0.021d66cb76352
ajv@6.12.6
6.14.0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ajv@8.17.1
8.18.0
1
library/ghost:6.25.12654b1e90413
ajv@6.12.6
6.14.0
1
library/ghost:4.37.0767230c0f263
ajv@6.12.6
6.14.0
1
library/ghost:5.79.083f7bf209844
ajv@6.12.6
6.14.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ajv@6.12.6
6.14.0
1
library/kibana:7.17.150172f1c538e7
ajv@6.12.6
6.14.0
1
library/kibana:8.18.004c0fc150f3a
ajv@8.17.1
8.18.0
1
library/kibana:7.17.8c5781ba340ef
ajv@6.12.6
6.14.0
1
library/kibana:7.17.3e2e2031c15be
ajv@6.12.6
6.14.0
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
ajv@6.12.6
6.14.0
1
linuxserver/cloud9:latest45c5fe102ff3
ajv@4.11.8
6.14.0
1
linuxserver/codimd:latestb801bbcf6386
ajv@6.12.6
6.14.0
1
linuxserver/grocy:version-v3.1.3291296e66c2a
ajv@6.12.6
6.14.0
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
ajv@6.12.6
6.14.0
1
linuxserver/overseerr:1.35.06108ed066d4a
ajv@6.12.6
6.14.0
1
lissy93/dashy:2.0.51991f7be5ed0
ajv@6.12.6
6.14.0
1
loftsh/jspolicy:0.2.225deb9bd2683
ajv@6.12.6
6.14.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
ajv@6.12.6
6.14.0
1
louislam/uptime-kuma:1.18.5a84767d7934f
ajv@6.12.6
6.14.0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-ajv@6.10.2-1
ajv@6.10.2
no fix listed
6.14.0
1
lsstsqre/squareone:0.4.09ded78e7fe03
ajv@6.12.6
6.14.0
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
ajv@8.6.0
8.18.0
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
ajv@8.11.2
8.18.0
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
ajv@8.12.0
8.18.0
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
ajv@5.5.2
6.14.0
1
mautic/mautic:7-apacheeb8cc73d97e1
ajv@8.17.1
8.18.0
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
ajv@5.5.2
6.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.