StackRadar

CVE-2025-7339

Low

Advisory

Published 17 Jul 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.4
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
213
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
1 of 1
affected package

on-headers is vulnerable to http response header manipulation

Carried by container images the latest versions of 213 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
on-headersnpm1.0.1, 1.0.21.1.0206
OSV records
GHSA-76c9-3jph-rj3q

Charts affected

213 by stars
ChartLatestAffected imagesRadar Score
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
on-headers@1.0.2
1.1.0

Open the chart page →

6,873
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
on-headers@1.0.2
1.1.0
treskon/portrait-ui:DEV-lateste7970783bc8d
on-headers@1.0.2
1.1.0

Open the chart page →

31,844
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
on-headers@1.0.2
1.1.0

Open the chart page →

2,823
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
speckle/speckle-server:2.26.379f14a2bf931
on-headers@1.0.2
1.1.0

Open the chart page →

10,380
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
on-headers@1.0.2
1.1.0

Open the chart page →

7,517
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
on-headers@1.0.2
1.1.0

Open the chart page →

12,581
prerenderutkuozdemirVerified publisher1.1.21 of 1See more

prerender utkuozdemir 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
tvanro/prerender-alpine:6.4.06909015f0328
on-headers@1.0.2
1.1.0

Open the chart page →

2,660
restreamerutkuozdemirVerified publisher1.1.01 of 1See more

restreamer utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
datarhei/restreamer:0.6.4655e12f9eeed
on-headers@1.0.2
1.1.0

Open the chart page →

2,598
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
on-headers@1.0.2
1.1.0

Open the chart page →

2,154
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
on-headers@1.0.2
1.1.0

Open the chart page →

9,783
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
on-headers@1.0.1
1.1.0

Open the chart page →

25,443
admin-portaladmin-web-portal1.2.11 of 2See more

admin-portal admin-web-portal 1.2.1

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
soulou2019/node-server:latest5e6ecfcc109e
on-headers@1.0.2
1.1.0

Open the chart page →

3,419
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
on-headers@1.0.2
1.1.0

Open the chart page →

3,437
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
on-headers@1.0.2
1.1.0

Open the chart page →

3,237
apimap-developerapimapOfficialVerified publisher1.4.11 of 1See more

apimap-developer apimap 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
apimap/developer:v1.3.1406d3858e20c
on-headers@1.0.2
1.1.0

Open the chart page →

2,353
apimap-portalapimapOfficialVerified publisher2.4.01 of 1See more

apimap-portal apimap 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
apimap/portal:v2.4.0041a4790c65c
on-headers@1.0.2
1.1.0

Open the chart page →

2,396
trifidappuio2.0.21 of 1See more

trifid appuio 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
zazuko/trifid:2.3.7054be137de70
on-headers@1.0.2
1.1.0

Open the chart page →

2,783
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
on-headers@1.0.2
1.1.0
pantsel/konga:latestc8172b75607d
on-headers@1.0.1
1.1.0

Open the chart page →

18,277
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
on-headers@1.0.2
1.1.0

Open the chart page →

1,722
http-debugbicarus-labs0.1.01 of 1See more

http-debug bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
bicarus/http-https-echo:2785dd6a7e805e
on-headers@1.0.2
1.1.0

Open the chart page →

867
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
on-headers@1.0.2
1.1.0

Open the chart page →

3,071
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
on-headers@1.0.1
1.1.0

Open the chart page →

4,069
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
on-headers@1.0.2
1.1.0

Open the chart page →

1,722
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
on-headers@1.0.2
1.1.0

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
on-headers@1.0.2
1.1.0
countly/frontend:25.05.42acbc11499b6
on-headers@1.0.2
1.1.0

Open the chart page →

7,295
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
on-headers@1.0.1
1.1.0

Open the chart page →

4,790
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
on-headers@1.0.2
1.1.0

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
on-headers@1.0.2
1.1.0

Open the chart page →

18,293
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
on-headers@1.0.2
1.1.0

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
on-headers@1.0.2
1.1.0

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
on-headers@1.0.2
1.1.0

Open the chart page →

5,141
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
on-headers@1.0.2
1.1.0

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
coldatom/containers-security-front:latest7c2fbbb41bcf
on-headers@1.0.2
1.1.0

Open the chart page →

9,146
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
on-headers@1.0.2
1.1.0

Open the chart page →

14,559
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
on-headers@1.0.1
1.1.0

Open the chart page →

5,209
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
on-headers@1.0.2
1.1.0

Open the chart page →

3,769
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
on-headers@1.0.2
1.1.0

Open the chart page →

4,217
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
on-headers@1.0.2
1.1.0

Open the chart page →

4,251
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
on-headers@1.0.2
1.1.0

Open the chart page →

3,744
smeejasfanzynoodle0.0.11 of 1See more

smeejas fanzynoodle 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
fanzynoodle/smeejas:0.0.15f9916c1a287
on-headers@1.0.2
1.1.0

Open the chart page →

4,127
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
on-headers@1.0.2
1.1.0

Open the chart page →

64,489
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
on-headers@1.0.2
1.1.0

Open the chart page →

3,159
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
on-headers@1.0.1
1.1.0

Open the chart page →

5,941
galoy-paygaloymoney0.11.481 of 2See more

galoy-pay galoymoney 0.11.48

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
krtk6160/galoy-nostrdigest-pinnedcc82a694f818
on-headers@1.0.2
1.1.0

Open the chart page →

2,528
rtlgaloymoney0.4.31 of 2See more

rtl galoymoney 0.4.3

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.13.3e2195188a451
on-headers@1.0.2
1.1.0

Open the chart page →

2,090
galoy-paygaloymoney20.11.481 of 2See more

galoy-pay galoymoney2 0.11.48

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
krtk6160/galoy-nostrdigest-pinnedcc82a694f818
on-headers@1.0.2
1.1.0

Open the chart page →

2,528
rtlgaloymoney20.4.31 of 2See more

rtl galoymoney2 0.4.3

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.13.3e2195188a451
on-headers@1.0.2
1.1.0

Open the chart page →

2,090
littlelink-servergeek-cookbookVerified publisher1.4.21 of 1See more

littlelink-server geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
on-headers@1.0.2
1.1.0

Open the chart page →

819
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
on-headers@1.0.2
1.1.0

Open the chart page →

4,043
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
on-headers@1.0.2
1.1.0

Open the chart page →

2,102

Container images carrying it

206 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
on-headers@1.0.2
1.1.0
4
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
on-headers@1.0.2
1.1.0
3
pantsel/konga:latestc8172b75607d
on-headers@1.0.1
1.1.0
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
on-headers@1.0.2
1.1.0
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
on-headers@1.0.2
1.1.0
2
governify/registry:v3.4.0d3f37f4f8168
on-headers@1.0.2
1.1.0
2
governify/render:v2.2.0daeca1ce28e6
on-headers@1.0.2
1.1.0
2
governify/reporter:v2.2.038595913458f
on-headers@1.0.2
1.1.0
2
gradiant/open5gs-webui:2.7.5fbd10c017541
on-headers@1.0.2
1.1.0
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
on-headers@1.0.2
1.1.0
2
krtk6160/galoy-nostrcc82a694f818
on-headers@1.0.2
1.1.0
2
library/mongo-express:1.0.2:latest1b23d7976f02
on-headers@1.0.2
1.1.0
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
on-headers@1.0.2
1.1.0
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
on-headers@1.0.2
1.1.0
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
on-headers@1.0.2
1.1.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
on-headers@1.0.2
1.1.0
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
on-headers@1.0.2
1.1.0
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
on-headers@1.0.2
1.1.0
2
shahanafarooqui/rtl:0.13.3e2195188a451
on-headers@1.0.2
1.1.0
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
on-headers@1.0.2
1.1.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
on-headers@1.0.2
1.1.0
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
on-headers@1.0.2
1.1.0
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
on-headers@1.0.2
1.1.0
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
on-headers@1.0.2
1.1.0
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
on-headers@1.0.2
1.1.0
2
0hlov3/semaphore:v1.0.050f874ec096b
on-headers@1.0.2
1.1.0
1
actualbudget/actual-server:25.3.158fecd9088b7
on-headers@1.0.1
1.1.0
1
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
on-headers@1.0.2
1.1.0
1
apimap/developer:v1.3.1406d3858e20c
on-headers@1.0.2
1.1.0
1
apimap/portal:v2.4.0041a4790c65c
on-headers@1.0.2
1.1.0
1
arfath29/3-tier-app-frontend:latest384b3e377f47
on-headers@1.0.2
1.1.0
1
assistiot/open_api_frontend:1.0.1f11d82defc70
on-headers@1.0.2
1.1.0
1
automatischio/automatisch:0.15.03bace7a12d5f
on-headers@1.0.2
1.1.0
1
baserow/baserow:1.30.1df0c42eb67e8
on-headers@1.0.2
1.1.0
1
bicarus/http-https-echo:2785dd6a7e805e
on-headers@1.0.2
1.1.0
1
catalysm/csmm:latestf003b35f54d9
on-headers@1.0.2
1.1.0
1
ccjacobs14/amazon:59a9b14a6f09e
on-headers@1.0.2
1.1.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
on-headers@1.0.2
1.1.0
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
on-headers@1.0.2
1.1.0
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
on-headers@1.0.2
1.1.0
1
codercom/code-server:4.11.0-debian1e2cc688008e
on-headers@1.0.2
1.1.0
1
codercom/code-server:3.10.247605610ad8d
on-headers@1.0.2
1.1.0
1
codetogether/codetogether:latest4348c8a38752
on-headers@1.0.2
1.1.0
1
coldatom/containers-security-front:latest7c2fbbb41bcf
on-headers@1.0.2
1.1.0
1
conduction/conduction-ui-app:devd591f5e6f2a9
on-headers@1.0.2
1.1.0
1
countly/api:25.05.4f4cc7447c4f5
on-headers@1.0.2
1.1.0
1
countly/countly-server:25.05.4e3c238248f99
on-headers@1.0.2
1.1.0
1
countly/frontend:25.05.42acbc11499b6
on-headers@1.0.2
1.1.0
1
cryptexlabs/authf:0.12.11189c07411d7c
on-headers@1.0.2
1.1.0
1
dacinfomotion/h2p:latest68fa393b472c
on-headers@1.0.2
1.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.