StackRadar

CVE-2025-7458

Critical

Advisory

Published 29 Jul 2025In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
463
of 17,781 indexed, latest versions
Container images
457
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 463 of 17,781 indexed charts deploy, on 457 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.40.1-2, 3.40.1-2+deb12u1, 3.40.1-2+deb12u2no fix listed457
OSV records
DEBIAN-CVE-2025-7458

Charts affected

463 by stars
ChartLatestAffected imagesRadar Score
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

5,228
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
sqlite3@3.40.1-2
no fix listed

Open the chart page →

14,358
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
sqlite3@3.40.1-2+deb12u1
no fix listed
vcnngr/telegram-rebot:latest30f1f05e57a6
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

5,026
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

10,795
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlite3@3.40.1-2
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
sqlite3@3.40.1-2
no fix listed

Open the chart page →

10,001
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
sqlite3@3.40.1-2
no fix listed

Open the chart page →

2,678
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

8,811
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

9,117
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

7,624
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
sqlite3@3.40.1-2
no fix listed

Open the chart page →

5,542
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

11,577
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
sqlite3@3.40.1-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
sqlite3@3.40.1-2
no fix listed
murtazashah46/helmfile:latest4d11726cf803
sqlite3@3.40.1-2
no fix listed

Open the chart page →

13,677

Container images carrying it

457 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
sqlite3@3.40.1-2+deb12u2
no fix listed
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
sqlite3@3.40.1-2+deb12u2
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
sqlite3@3.40.1-2
no fix listed
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
sqlite3@3.40.1-2+deb12u1
no fix listed
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
sqlite3@3.40.1-2+deb12u2
no fix listed
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
sqlite3@3.40.1-2+deb12u1
no fix listed
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
sqlite3@3.40.1-2+deb12u1
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
sqlite3@3.40.1-2+deb12u2
no fix listed
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
sqlite3@3.40.1-2+deb12u2
no fix listed
2
aboogie/login_test_backend:new9c41a4483ac8
sqlite3@3.40.1-2
no fix listed
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
sqlite3@3.40.1-2+deb12u2
no fix listed
1
aibrix/metadata-service:v0.7.063fb81a64377
sqlite3@3.40.1-2+deb12u1
no fix listed
1
airbyte/manifest-server:7.23.73b3a670af168
sqlite3@3.40.1-2+deb12u2
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
sqlite3@3.40.1-2
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
sqlite3@3.40.1-2+deb12u1
no fix listed
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
sqlite3@3.40.1-2
no fix listed
1
anujdatar/cups:25.07.01685df04a643b
sqlite3@3.40.1-2+deb12u1
no fix listed
1
apache/airflow:2.8.4-python3.964e58748b6b9
sqlite3@3.40.1-2
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
sqlite3@3.40.1-2
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
sqlite3@3.40.1-2
no fix listed
1
apache/superset:4.0.1ab9467fd712c
sqlite3@3.40.1-2
no fix listed
1
archivebox/archivebox:0.7.41a5a37331091
sqlite3@3.40.1-2+deb12u2
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
sqlite3@3.40.1-2
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
sqlite3@3.40.1-2
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
sqlite3@3.40.1-2
no fix listed
1
assistiot/identity-manager_db:latest0d3e6d35f168
sqlite3@3.40.1-2
no fix listed
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
sqlite3@3.40.1-2
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
sqlite3@3.40.1-2
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
sqlite3@3.40.1-2
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
sqlite3@3.40.1-2
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
sqlite3@3.40.1-2+deb12u1
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
sqlite3@3.40.1-2+deb12u1
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/openldap:2.6.8-debian-12-r16e412c178ef9
sqlite3@3.40.1-2
no fix listed
1
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
sqlite3@3.40.1-2
no fix listed
1
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
sqlite3@3.40.1-2
no fix listed
1
bitnamilegacy/postgresql:16.4.03ba6e6f11388
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
sqlite3@3.40.1-2
no fix listed
1
bitnamilegacy/postgresql:16.3.0-debian-12-r14cc55da2fa366
sqlite3@3.40.1-2
no fix listed
1
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/postgresql:17.0.0-debian-12-r9d885ac277163
sqlite3@3.40.1-2
no fix listed
1
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
sqlite3@3.40.1-2
no fix listed
1
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
sqlite3@3.40.1-2
no fix listed
1
blockstream/bitcoind:27.29472492530e3
sqlite3@3.40.1-2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.