CVE-2025-7709
MediumAdvisory
Published 8 Sept 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.9
- base score, highest
- EPSS
- 0.003
- 28th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 608
- of 17,787 indexed, latest versions
- Container images
- 601
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
lemon-3.51.2-1.1 on GA media
Carried by container images the latest versions of 608 of 17,787 indexed charts deploy, on 601 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| sqlite3deb | 3.40.1-2, 3.40.1-2+deb12u1, 3.40.1-2+deb12u2, 3.45.1-1ubuntu2+4 more | 3.45.1-1ubuntu2.5, 3.46.1-7+deb13u1 | 596 |
| sqlite3rpm | 3.28.0-lp151.2.3.1, 3.50.2-150000.3.33.1 | 3.51.2-1.1, 3.51.2-150000.3.36.1 | 5 |
- OSV records
- DEBIAN-CVE-2025-7709UBUNTU-CVE-2025-7709openSUSE-SU-2026:10171-1SUSE-SU-2026:0432-1
- Also known as
- USN-7751-1
Charts affected
608 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| web-dvwaweb-dvwa | 1.16.0 | 1 of 2See more | 8,858 |
| welcome-elos-webappwelcome-elos-webappVerified publisher | 2.0.0 | 1 of 1See more | 2,538 |
| giteawenerme | 12.7.0 | 1 of 4See more | 8,842 |
| juicefs-csi-driverwenerme | 0.32.5 | 1 of 5See more | 8,824 |
| keycloakwiremindVerified publisher | 25.3.1 | 1 of 2See more | 7,643 |
| marge-botwiremindVerified publisher | 1.4.4 | 1 of 1See more | 5,548 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,592 |
| xkopsxkops | 0.1.0 | 3 of 5See more | 13,197 |
Container images carrying it
601 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.k8s.io/ | ce5b5ccd5eb0 | sqlite3 | no fix listed | 1 |