StackRadar

CVE-2025-7458

Critical

Advisory

Published 29 Jul 2025In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
463
of 17,781 indexed, latest versions
Container images
457
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 463 of 17,781 indexed charts deploy, on 457 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.40.1-2, 3.40.1-2+deb12u1, 3.40.1-2+deb12u2no fix listed457
OSV records
DEBIAN-CVE-2025-7458

Charts affected

463 by stars
ChartLatestAffected imagesRadar Score
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

5,228
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
sqlite3@3.40.1-2
no fix listed

Open the chart page →

14,358
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
sqlite3@3.40.1-2+deb12u1
no fix listed
vcnngr/telegram-rebot:latest30f1f05e57a6
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

5,026
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

10,795
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlite3@3.40.1-2
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
sqlite3@3.40.1-2
no fix listed

Open the chart page →

10,001
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
sqlite3@3.40.1-2
no fix listed

Open the chart page →

2,678
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

8,811
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

9,117
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

7,624
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
sqlite3@3.40.1-2
no fix listed

Open the chart page →

5,542
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

11,577
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
sqlite3@3.40.1-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
sqlite3@3.40.1-2
no fix listed
murtazashah46/helmfile:latest4d11726cf803
sqlite3@3.40.1-2
no fix listed

Open the chart page →

13,677

Container images carrying it

457 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
sqlite3@3.40.1-2+deb12u1
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
sqlite3@3.40.1-2+deb12u1
no fix listed
1
boky/postfix:4.4.0f3f247fd4252
sqlite3@3.40.1-2+deb12u1
no fix listed
1
budibase/database:2.1.0d90f656261c9
sqlite3@3.40.1-2+deb12u2
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
sqlite3@3.40.1-2+deb12u1
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
sqlite3@3.40.1-2
no fix listed
1
cccs/assemblyline-core:4.7.4.stable177c3c25d4d6e0
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cccs/assemblyline-rust:4.7.4.stable17468326853ec5
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cccs/assemblyline-socketio:4.7.4.stable1724646dbfd944
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cccs/assemblyline-ui:4.7.4.stable171a7a103668f5
sqlite3@3.40.1-2+deb12u2
no fix listed
1
ckan/ckan-base:2.12.087ecf3f27ad6
sqlite3@3.40.1-2+deb12u2
no fix listed
1
ckulka/baikal:0.10.1-nginx434bdd162247
sqlite3@3.40.1-2+deb12u1
no fix listed
1
cloudtooling/moodle:5.2.3f4f04e0fc401
sqlite3@3.40.1-2+deb12u2
no fix listed
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
sqlite3@3.40.1-2+deb12u2
no fix listed
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
sqlite3@3.40.1-2+deb12u2
no fix listed
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
sqlite3@3.40.1-2+deb12u2
no fix listed
1
codedesignplus/ms-emails-grpc:lateste336012bc781
sqlite3@3.40.1-2+deb12u2
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
sqlite3@3.40.1-2+deb12u2
no fix listed
1
collabora/code:24.04.13.2.101dc4ab83977
sqlite3@3.40.1-2+deb12u1
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
sqlite3@3.40.1-2
no fix listed
1
cspconsole/config-provider:1.0.365524a26a6c23
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
sqlite3@3.40.1-2+deb12u2
no fix listed
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
sqlite3@3.40.1-2+deb12u2
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlite3@3.40.1-2
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
sqlite3@3.40.1-2
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlite3@3.40.1-2
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
sqlite3@3.40.1-2
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
sqlite3@3.40.1-2+deb12u1
no fix listed
1
devopsgoofy/k8s-platform:latestad865312099f
sqlite3@3.40.1-2+deb12u1
no fix listed
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
sqlite3@3.40.1-2+deb12u1
no fix listed
1
djjudas21/alertify:0.1.0ba22be670c37
sqlite3@3.40.1-2+deb12u1
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
sqlite3@3.40.1-2
no fix listed
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
sqlite3@3.40.1-2+deb12u2
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
sqlite3@3.40.1-2+deb12u2
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
sqlite3@3.40.1-2
no fix listed
1
dragonflyoss/client:v1.5.4a1b52779c4dd
sqlite3@3.40.1-2+deb12u2
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
sqlite3@3.40.1-2
no fix listed
1
drumsergio/genieacs:1.2.16.028244054e1bf
sqlite3@3.40.1-2+deb12u2
no fix listed
1
dserio83/velero-api:0.3.16b3d9115fee2
sqlite3@3.40.1-2+deb12u1
no fix listed
1
dserio83/velero-watchdog:0.1.8d5deae589229
sqlite3@3.40.1-2+deb12u1
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
sqlite3@3.40.1-2
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
sqlite3@3.40.1-2+deb12u1
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
sqlite3@3.40.1-2+deb12u1
no fix listed
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
sqlite3@3.40.1-2+deb12u2
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
sqlite3@3.40.1-2+deb12u1
no fix listed
1
firefart/requesttracker:5.0.40d6249906d8c
sqlite3@3.40.1-2
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
sqlite3@3.40.1-2+deb12u1
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
sqlite3@3.40.1-2+deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.