StackRadar

CVE-2025-7709

Medium

Advisory

Published 8 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
608
of 17,787 indexed, latest versions
Container images
601
deployed by those charts
Fix available
2 of 2
affected packages

lemon-3.51.2-1.1 on GA media

Carried by container images the latest versions of 608 of 17,787 indexed charts deploy, on 601 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.40.1-2, 3.40.1-2+deb12u1, 3.40.1-2+deb12u2, 3.45.1-1ubuntu2+4 more3.45.1-1ubuntu2.5, 3.46.1-7+deb13u1596
sqlite3rpm3.28.0-lp151.2.3.1, 3.50.2-150000.3.33.13.51.2-1.1, 3.51.2-150000.3.36.15
OSV records
DEBIAN-CVE-2025-7709UBUNTU-CVE-2025-7709openSUSE-SU-2026:10171-1SUSE-SU-2026:0432-1
Also known as
USN-7751-1

Charts affected

608 by stars
ChartLatestAffected imagesRadar Score
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-7709.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
sqlite3@3.40.1-2
no fix listed

Open the chart page →

8,858
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-7709.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
sqlite3@3.40.1-2
no fix listed

Open the chart page →

2,538
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2025-7709.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

8,842
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-7709.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

8,824
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-7709.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

7,643
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-7709.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
sqlite3@3.40.1-2
no fix listed

Open the chart page →

5,548
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-7709.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

11,592
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-7709.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
sqlite3@3.40.1-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
sqlite3@3.40.1-2
no fix listed
murtazashah46/helmfile:latest4d11726cf803
sqlite3@3.40.1-2
no fix listed

Open the chart page →

13,197

Container images carrying it

601 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
sqlite3@3.40.1-2+deb12u1
no fix listed
1
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
sqlite3@3.40.1-2+deb12u1
no fix listed
1
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
sqlite3@3.40.1-2
no fix listed
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
sqlite3@3.40.1-2
no fix listed
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
sqlite3@3.40.1-2
no fix listed
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
sqlite3@3.40.1-2
no fix listed
1
stalwartlabs/stalwart:v0.15.5dcf575db2d53
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
stashapp/stash-box:latesta534c8afdf39
sqlite3@3.45.1-1ubuntu2.3
3.45.1-1ubuntu2.5
1
structurizr/onpremises:2025.11.094b5ffb5119c8
sqlite3@3.45.1-1ubuntu2.3
3.45.1-1ubuntu2.5
1
substratusai/verba:v0.4.0-baseURL261695be635eb
sqlite3@3.40.1-2
no fix listed
1
supabase/logflare:latest49bfe526f1b4
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
supabase/realtime:v2.102.3aa1c92c0cf32
sqlite3@3.40.1-2+deb12u2
no fix listed
1
supabase/studio:20241021-9f9b08326d8070c55e9
sqlite3@3.40.1-2
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
sqlite3@3.40.1-2+deb12u2
no fix listed
1
supabase/studio:latest94a2a9d2906e
sqlite3@3.40.1-2+deb12u2
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
sqlite3@3.40.1-2
no fix listed
1
swimmwatch/cloakbrowser-mcp:1.13.0d48c705a58c8
sqlite3@3.40.1-2+deb12u2
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
sqlite3@3.40.1-2+deb12u1
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
sqlite3@3.40.1-2+deb12u1
no fix listed
1
sysnet4admin/colosseum-rwd:log74ded2d92f07
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
teknas09/bird-pod:latest12a1fa85c4aa
sqlite3@3.40.1-2
no fix listed
1
tensorzero/ui:2026.6.0f2563d54724e
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
theradius/loggia:0.463ba348546ec
sqlite3@3.40.1-2
no fix listed
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
thingsboard/tb-postgres:latest2d17e4e36edc
sqlite3@3.40.1-2+deb12u2
no fix listed
1
thongngo3301/stakefish:latesta341af5976e3
sqlite3@3.40.1-2
no fix listed
1
tiago2/cap:2.159f5ae4e261e
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
sqlite3@3.40.1-2+deb12u1
no fix listed
1
tussanakorndev/kube-pod-alerts:1.0.5216fdadadf9a
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
sqlite3@3.40.1-2+deb12u1
no fix listed
1
vaultwarden/server:1.35.443498a94b22f
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1
vcnngr/telegram-login:latest1a849a997b6d
sqlite3@3.40.1-2+deb12u1
no fix listed
1
vcnngr/telegram-rebot:latest30f1f05e57a6
sqlite3@3.40.1-2+deb12u1
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
sqlite3@3.40.1-2
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
sqlite3@3.40.1-2
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
sqlite3@3.40.1-2
no fix listed
1
wiktorn/overpass-api:latest9bb5f4a9b54c
sqlite3@3.40.1-2+deb12u2
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
sqlite3@3.40.1-2
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
sqlite3@3.40.1-2
no fix listed
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
sqlite3@3.45.1-1ubuntu2
3.45.1-1ubuntu2.5
1
zenmldocker/zenml-server:0.96.409027a6312ee
sqlite3@3.40.1-2+deb12u2
no fix listed
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
sqlite3@3.40.1-2+deb12u1
no fix listed
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
sqlite3@3.40.1-2
no fix listed
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
sqlite3@3.40.1-2+deb12u1
no fix listed
1
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
sqlite3@3.40.1-2+deb12u2
no fix listed
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
sqlite3@3.40.1-2+deb12u2
no fix listed
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
sqlite3@3.40.1-2
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
sqlite3@3.46.1-7
3.46.1-7+deb13u1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.