StackRadar

CVE-2025-7458

Critical

Advisory

Published 29 Jul 2025In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
460
of 17,787 indexed, latest versions
Container images
452
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 460 of 17,787 indexed charts deploy, on 452 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.40.1-2, 3.40.1-2+deb12u1, 3.40.1-2+deb12u2no fix listed452
OSV records
DEBIAN-CVE-2025-7458

Charts affected

460 by stars
ChartLatestAffected imagesRadar Score
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

10,795
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlite3@3.40.1-2
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
sqlite3@3.40.1-2
no fix listed

Open the chart page →

10,001
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
sqlite3@3.40.1-2
no fix listed

Open the chart page →

2,678
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

8,811
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

9,117
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

7,624
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
sqlite3@3.40.1-2
no fix listed

Open the chart page →

5,542
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

11,577
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-7458.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
sqlite3@3.40.1-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
sqlite3@3.40.1-2
no fix listed
murtazashah46/helmfile:latest4d11726cf803
sqlite3@3.40.1-2
no fix listed

Open the chart page →

13,677

Container images carrying it

452 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opea/codetrans-ui:1.03ef121f34610
sqlite3@3.40.1-2
no fix listed
1
opea/docsum:1.03eaa91849512
sqlite3@3.40.1-2
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
sqlite3@3.40.1-2
no fix listed
1
opea/guardrails-tgi:1.0262c6048aab8
sqlite3@3.40.1-2
no fix listed
1
opea/guardrails-tgi:latestf68bec6a1271
sqlite3@3.40.1-2+deb12u1
no fix listed
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
sqlite3@3.40.1-2
no fix listed
1
opea/speecht5:1.0249afad3d268
sqlite3@3.40.1-2
no fix listed
1
opea/tts:1.0257ae94709e9
sqlite3@3.40.1-2
no fix listed
1
opea/web-retriever-chroma:1.0fe08165d7770
sqlite3@3.40.1-2
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
sqlite3@3.40.1-2+deb12u1
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
sqlite3@3.40.1-2+deb12u1
no fix listed
1
openproject/hocuspocus:release-338001b288dc1359dfb5
sqlite3@3.40.1-2+deb12u1
no fix listed
1
pgvector/pgvector:pg17cf134a767f47
sqlite3@3.40.1-2+deb12u2
no fix listed
1
phan2410/dummy-service:0.0.89c6ed6de26ca
sqlite3@3.40.1-2+deb12u1
no fix listed
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
sqlite3@3.40.1-2+deb12u1
no fix listed
1
pococze/python-hello-elos:2.0.07a1aab425e51
sqlite3@3.40.1-2
no fix listed
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
sqlite3@3.40.1-2
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
sqlite3@3.40.1-2+deb12u2
no fix listed
1
proxysql/proxysql:2.7.3a4d6c35c2949
sqlite3@3.40.1-2+deb12u1
no fix listed
1
redash/redash:25.8.000d813437db5
sqlite3@3.40.1-2+deb12u1
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
sqlite3@3.40.1-2+deb12u2
no fix listed
1
redimp/otterwiki:2778bf30da3da
sqlite3@3.40.1-2+deb12u2
no fix listed
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
sqlite3@3.40.1-2+deb12u2
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
sqlite3@3.40.1-2+deb12u2
no fix listed
1
rhasspy/wyoming-whisper:3.5.0308b7959a925
sqlite3@3.40.1-2+deb12u2
no fix listed
1
rocketadmin/rocketadmin:1.17.710955ef540b9
sqlite3@3.40.1-2+deb12u2
no fix listed
1
rocketchat/freeswitch:stablecfba5c20a5cc
sqlite3@3.40.1-2+deb12u1
no fix listed
1
ryshe/terraria:latestb1c89f7f359a
sqlite3@3.40.1-2+deb12u2
no fix listed
1
santisbon/evwatcher:latestc4e994ca4540
sqlite3@3.40.1-2
no fix listed
1
santisbon/evworker:lateste807283f8d69
sqlite3@3.40.1-2
no fix listed
1
santisbon/speedtest:latest8ee3a1697227
sqlite3@3.40.1-2
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
sqlite3@3.40.1-2
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
sqlite3@3.40.1-2
no fix listed
1
scsibug/nostr-rs-relay:0.9.003f54bfbffff
sqlite3@3.40.1-2
no fix listed
1
sharanalwar/redchef-backend:latest8d3cab80df49
sqlite3@3.40.1-2+deb12u1
no fix listed
1
signalen/backend:2.50.14760256000738
sqlite3@3.40.1-2+deb12u2
no fix listed
1
sigscale/cse:latest67d0c886516b
sqlite3@3.40.1-2+deb12u2
no fix listed
1
sigscale/ocs:latest3c1bdc9732e2
sqlite3@3.40.1-2+deb12u2
no fix listed
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
sqlite3@3.40.1-2
no fix listed
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
sqlite3@3.40.1-2
no fix listed
1
sirrend/helmup-notifications-service:0.1.3997866417011
sqlite3@3.40.1-2
no fix listed
1
sissbruecker/linkding:1.35.00c5dddf0b37c
sqlite3@3.40.1-2
no fix listed
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
sqlite3@3.40.1-2+deb12u1
no fix listed
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
sqlite3@3.40.1-2
no fix listed
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
sqlite3@3.40.1-2
no fix listed
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
sqlite3@3.40.1-2
no fix listed
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
sqlite3@3.40.1-2
no fix listed
1
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
sqlite3@3.40.1-2+deb12u2
no fix listed
1
speckle/speckle-monitor-deployment:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb2faf1508c1d3
sqlite3@3.40.1-2
no fix listed
1
speckle/speckle-monitor-deployment:2.20.2-branch.testing4.134160-9fad4b23c8fbe855665
sqlite3@3.40.1-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.