StackRadar

CVE-2025-7339

Low

Advisory

Published 17 Jul 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.4
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
213
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
1 of 1
affected package

on-headers is vulnerable to http response header manipulation

Carried by container images the latest versions of 213 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
on-headersnpm1.0.1, 1.0.21.1.0206
OSV records
GHSA-76c9-3jph-rj3q

Charts affected

213 by stars
ChartLatestAffected imagesRadar Score
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
on-headers@1.0.2
1.1.0

Open the chart page →

3,881
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
on-headers@1.0.2
1.1.0

Open the chart page →

4,017
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
on-headers@1.0.2
1.1.0

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
on-headers@1.0.2
1.1.0

Open the chart page →

5,604
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
on-headers@1.0.2
1.1.0

Open the chart page →

20,270
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
on-headers@1.0.2
1.1.0

Open the chart page →

2,408
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
on-headers@1.0.2
1.1.0

Open the chart page →

3,576
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
thingsboard/tb-web-ui:3.4.157f98ed53b3d
on-headers@1.0.2
1.1.0

Open the chart page →

25,394
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
on-headers@1.0.2
1.1.0

Open the chart page →

2,806
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
on-headers@1.0.2
1.1.0

Open the chart page →

929
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
on-headers@1.0.2
1.1.0

Open the chart page →

3,129
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
on-headers@1.0.2
1.1.0

Open the chart page →

3,118
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2025-7339.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
on-headers@1.0.2
1.1.0

Open the chart page →

16,083

Container images carrying it

206 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
on-headers@1.0.2
1.1.0
4
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
on-headers@1.0.2
1.1.0
3
pantsel/konga:latestc8172b75607d
on-headers@1.0.1
1.1.0
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
on-headers@1.0.2
1.1.0
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
on-headers@1.0.2
1.1.0
2
governify/registry:v3.4.0d3f37f4f8168
on-headers@1.0.2
1.1.0
2
governify/render:v2.2.0daeca1ce28e6
on-headers@1.0.2
1.1.0
2
governify/reporter:v2.2.038595913458f
on-headers@1.0.2
1.1.0
2
gradiant/open5gs-webui:2.7.5fbd10c017541
on-headers@1.0.2
1.1.0
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
on-headers@1.0.2
1.1.0
2
krtk6160/galoy-nostrcc82a694f818
on-headers@1.0.2
1.1.0
2
library/mongo-express:1.0.2:latest1b23d7976f02
on-headers@1.0.2
1.1.0
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
on-headers@1.0.2
1.1.0
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
on-headers@1.0.2
1.1.0
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
on-headers@1.0.2
1.1.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
on-headers@1.0.2
1.1.0
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
on-headers@1.0.2
1.1.0
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
on-headers@1.0.2
1.1.0
2
shahanafarooqui/rtl:0.13.3e2195188a451
on-headers@1.0.2
1.1.0
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
on-headers@1.0.2
1.1.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
on-headers@1.0.2
1.1.0
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
on-headers@1.0.2
1.1.0
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
on-headers@1.0.2
1.1.0
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
on-headers@1.0.2
1.1.0
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
on-headers@1.0.2
1.1.0
2
0hlov3/semaphore:v1.0.050f874ec096b
on-headers@1.0.2
1.1.0
1
actualbudget/actual-server:25.3.158fecd9088b7
on-headers@1.0.1
1.1.0
1
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
on-headers@1.0.2
1.1.0
1
apimap/developer:v1.3.1406d3858e20c
on-headers@1.0.2
1.1.0
1
apimap/portal:v2.4.0041a4790c65c
on-headers@1.0.2
1.1.0
1
arfath29/3-tier-app-frontend:latest384b3e377f47
on-headers@1.0.2
1.1.0
1
assistiot/open_api_frontend:1.0.1f11d82defc70
on-headers@1.0.2
1.1.0
1
automatischio/automatisch:0.15.03bace7a12d5f
on-headers@1.0.2
1.1.0
1
baserow/baserow:1.30.1df0c42eb67e8
on-headers@1.0.2
1.1.0
1
bicarus/http-https-echo:2785dd6a7e805e
on-headers@1.0.2
1.1.0
1
catalysm/csmm:latestf003b35f54d9
on-headers@1.0.2
1.1.0
1
ccjacobs14/amazon:59a9b14a6f09e
on-headers@1.0.2
1.1.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
on-headers@1.0.2
1.1.0
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
on-headers@1.0.2
1.1.0
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
on-headers@1.0.2
1.1.0
1
codercom/code-server:4.11.0-debian1e2cc688008e
on-headers@1.0.2
1.1.0
1
codercom/code-server:3.10.247605610ad8d
on-headers@1.0.2
1.1.0
1
codetogether/codetogether:latest4348c8a38752
on-headers@1.0.2
1.1.0
1
coldatom/containers-security-front:latest7c2fbbb41bcf
on-headers@1.0.2
1.1.0
1
conduction/conduction-ui-app:devd591f5e6f2a9
on-headers@1.0.2
1.1.0
1
countly/api:25.05.4f4cc7447c4f5
on-headers@1.0.2
1.1.0
1
countly/countly-server:25.05.4e3c238248f99
on-headers@1.0.2
1.1.0
1
countly/frontend:25.05.42acbc11499b6
on-headers@1.0.2
1.1.0
1
cryptexlabs/authf:0.12.11189c07411d7c
on-headers@1.0.2
1.1.0
1
dacinfomotion/h2p:latest68fa393b472c
on-headers@1.0.2
1.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.