StackRadar

CVE-2025-7458

Critical

Advisory

Published 29 Jul 2025In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
463
of 17,781 indexed, latest versions
Container images
457
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 463 of 17,781 indexed charts deploy, on 457 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.40.1-2, 3.40.1-2+deb12u1, 3.40.1-2+deb12u2no fix listed457
OSV records
DEBIAN-CVE-2025-7458

Charts affected

463 by stars
ChartLatestAffected imagesRadar Score
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

5,228
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
sqlite3@3.40.1-2
no fix listed

Open the chart page →

14,358
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
sqlite3@3.40.1-2+deb12u1
no fix listed
vcnngr/telegram-rebot:latest30f1f05e57a6
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

5,026
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

10,795
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlite3@3.40.1-2
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
sqlite3@3.40.1-2
no fix listed

Open the chart page →

10,001
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
sqlite3@3.40.1-2
no fix listed

Open the chart page →

2,678
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

8,811
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

9,117
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

7,624
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
sqlite3@3.40.1-2
no fix listed

Open the chart page →

5,542
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

11,577
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
sqlite3@3.40.1-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
sqlite3@3.40.1-2
no fix listed
murtazashah46/helmfile:latest4d11726cf803
sqlite3@3.40.1-2
no fix listed

Open the chart page →

13,677

Container images carrying it

457 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/couchdb:3.4.22817ad50b5c5
sqlite3@3.40.1-2+deb12u1
no fix listed
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
sqlite3@3.40.1-2+deb12u2
no fix listed
1
library/influxdb:2.8571eb4514977
sqlite3@3.40.1-2+deb12u2
no fix listed
1
library/influxdb:1.12.3-meta8812029260b5
sqlite3@3.40.1-2+deb12u2
no fix listed
1
library/influxdb:1.12.3-datab0f9fc41ed79
sqlite3@3.40.1-2+deb12u2
no fix listed
1
library/influxdb:latestf75e48af0598
sqlite3@3.40.1-2+deb12u2
no fix listed
1
library/matomo:5.1.2-apache2415789e1602
sqlite3@3.40.1-2+deb12u1
no fix listed
1
library/mysql:8.0-debian9382e4f6f7f0
sqlite3@3.40.1-2+deb12u2
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
sqlite3@3.40.1-2+deb12u1
no fix listed
1
library/node:208f693eaa7e0a
sqlite3@3.40.1-2+deb12u2
no fix listed
1
library/postgres:17.4304ab8135187
sqlite3@3.40.1-2+deb12u1
no fix listed
1
library/postgres:16.6557fea37a744
sqlite3@3.40.1-2+deb12u1
no fix listed
1
library/postgres:15.38775adb39f0d
sqlite3@3.40.1-2
no fix listed
1
library/postgres:13.12ced3ba927f4c
sqlite3@3.40.1-2
no fix listed
1
library/postgres:15.18-bookworme8db9bd3e9e1
sqlite3@3.40.1-2+deb12u2
no fix listed
1
library/postgres:17.5-bookwormfbcea1bd13b6
sqlite3@3.40.1-2+deb12u1
no fix listed
1
library/python:3.8d41127070014
sqlite3@3.40.1-2
no fix listed
1
library/telegraf:1.27507a3eecf809
sqlite3@3.40.1-2
no fix listed
1
library/varnish:7.5.04d0bb287d87b
sqlite3@3.40.1-2+deb12u1
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
sqlite3@3.40.1-2
no fix listed
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
sqlite3@3.40.1-2+deb12u2
no fix listed
1
localstack/localstack:3.19d278167f2b7
sqlite3@3.40.1-2
no fix listed
1
locustio/locust:2.24.151d866285170
sqlite3@3.40.1-2
no fix listed
1
logiqai/flash:v3.10.265b996bc7bdc
sqlite3@3.40.1-2
no fix listed
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
sqlite3@3.40.1-2+deb12u2
no fix listed
1
louislam/uptime-kuma:2.5.33e24e96c89ef
sqlite3@3.40.1-2+deb12u2
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
sqlite3@3.40.1-2+deb12u2
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
sqlite3@3.40.1-2+deb12u2
no fix listed
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
sqlite3@3.40.1-2+deb12u2
no fix listed
1
makersquad/harp-proxy:0.8.1a40dd258c527
sqlite3@3.40.1-2+deb12u1
no fix listed
1
martinhelmich/typo3:12.4c83a4f3fd7ae
sqlite3@3.40.1-2+deb12u2
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
sqlite3@3.40.1-2+deb12u2
no fix listed
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
sqlite3@3.40.1-2+deb12u1
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
sqlite3@3.40.1-2+deb12u2
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
sqlite3@3.40.1-2+deb12u1
no fix listed
1
middlewareeng/middleware:0.3.1747d880812f1
sqlite3@3.40.1-2+deb12u1
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
sqlite3@3.40.1-2+deb12u1
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
sqlite3@3.40.1-2+deb12u2
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
sqlite3@3.40.1-2+deb12u1
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
sqlite3@3.40.1-2+deb12u1
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
sqlite3@3.40.1-2+deb12u2
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
sqlite3@3.40.1-2
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
sqlite3@3.40.1-2
no fix listed
1
murtazashah46/helmfile:latest4d11726cf803
sqlite3@3.40.1-2
no fix listed
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
sqlite3@3.40.1-2+deb12u2
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
sqlite3@3.40.1-2
no fix listed
1
oled01/automx2:2025.1.105d3e398e675
sqlite3@3.40.1-2+deb12u1
no fix listed
1
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
sqlite3@3.40.1-2+deb12u1
no fix listed
1
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
sqlite3@3.40.1-2+deb12u1
no fix listed
1
omkara25/simple-microservice-app-user-service:v2d62cba548580
sqlite3@3.40.1-2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.