StackRadar

CVE-2025-7424

High

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
226
of 17,781 indexed, latest versions
Container images
216
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 226 of 17,781 indexed charts deploy, on 216 images.

Affected packageAffected versionsFixed inImages
libxsltdeb1.1.28-2.1ubuntu0.3, 1.1.28-2ubuntu0.1, 1.1.29-5ubuntu0.2, 1.1.34-4+10 more1.1.28-2.1ubuntu0.3+esm4, 1.1.28-2ubuntu0.2+esm5, 1.1.29-5ubuntu0.3+esm3, 1.1.34-4ubuntu0.20.04.3+esm2+4 more216
OSV records
DEBIAN-CVE-2025-7424UBUNTU-CVE-2025-7424
Also known as
USN-7945-1

Charts affected

226 by stars
ChartLatestAffected imagesRadar Score
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxslt@1.1.35-1
1.1.35-1+deb12u2
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

14,838
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

5,779
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

31,844
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.5

Open the chart page →

7,432
atuinrm3lVerified publisher0.11.01 of 3See more

atuin rm3l 0.11.0

1 of the 3 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

6,521
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2

Open the chart page →

5,315
kyoorubxkubeVerified publisher0.1.102 of 9See more

kyoo rubxkube 0.1.10

2 of the 9 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libxslt@1.1.35-1
1.1.35-1+deb12u2
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

30,234
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

5,676
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.3+esm2

Open the chart page →

24,930
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

12,581
backendzymtraceOfficialVerified publisher26.9.11 of 6See more

backend zymtrace 26.9.1

1 of the 6 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
library/postgres:17.4304ab8135187
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2

Open the chart page →

10,323
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
libxslt@1.1.35-1
1.1.35-1+deb12u2
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

25,669
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2

Open the chart page →

40,238
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

13,352
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

45,363
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.5
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

32,501
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

6,297
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2
kuzwolka/aws9:news3e8880fbbb96
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2
kuzwolka/aws9:blog4a7707410bf1
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2
kuzwolka/aws9:shop84a9d9766345
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2

Open the chart page →

18,344
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

6,297
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
libxslt@1.1.29-5ubuntu0.2
1.1.29-5ubuntu0.3+esm3

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

10,145
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.3+esm2

Open the chart page →

15,253
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2
sysnet4admin/colosseum-prm:log5802bfcd7fed
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2

Open the chart page →

26,996
plexbryanalves0.5.01 of 1See more

plex bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.3+esm2

Open the chart page →

6,707
geoservercamptocamp20.0.31 of 12See more

geoserver camptocamp2 0.0.3

1 of the 12 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

88,335
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

5,039
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

10,776
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

15,371
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.5

Open the chart page →

20,900
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
galaxy/galaxy-stable:v18.018e577a626dfd
libxslt@1.1.28-2ubuntu0.1
1.1.28-2ubuntu0.2+esm5

Open the chart page →

70,895
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2

Open the chart page →

13,220
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2

Open the chart page →

14,559
postgresqlcowboysysopVerified publisher15.5.71 of 1See more

postgresql cowboysysop 15.5.7

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r14cc55da2fa366
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

4,770
cypikcypik-app0.1.01 of 2See more

cypik cypik-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

7,503
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.5

Open the chart page →

5,398
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

10,090
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.5

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.5

Open the chart page →

29,033
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

68,240
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

3,891
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

68,240
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

32,902
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

3,891
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
libxslt@1.1.35-1+deb12u1
1.1.35-1+deb12u2

Open the chart page →

4,046
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

14,627
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.5

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxslt@1.1.34-4build2
1.1.34-4ubuntu0.22.04.5

Open the chart page →

30,699
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

4,586
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
libxslt@1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.3+esm2

Open the chart page →

25,122
kube-ecp-stackemqx-operator2.5.11 of 16See more

kube-ecp-stack emqx-operator 2.5.1

1 of the 16 container images this version deploys carry CVE-2025-7424.

Container imageDigestPackageFixed in
emqx/ecp-ui:2.5.1e33e9816f147
libxslt@1.1.35-1
1.1.35-1+deb12u2

Open the chart page →

23,685

Container images carrying it

216 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
libxslt@1.1.34-4ubuntu0.22.04.4
1.1.34-4ubuntu0.22.04.5
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.3+esm2
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libxslt@1.1.35-1
1.1.35-1+deb12u2
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxslt@1.1.35-1
1.1.35-1+deb12u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.