StackRadar

CVE-2025-8194

High

Advisory

Published 28 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
589
of 17,787 indexed, latest versions
Container images
597
deployed by those charts
Fix available
25 of 25
affected packages

Tarfile infinite loop during parsing with negative member offset

Carried by container images the latest versions of 589 of 17,787 indexed charts deploy, on 597 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.2-6, 3.11.2-6+deb12u2, 3.11.2-6+deb12u3+3 more3.11.0~rc1-1~22.04.1~esm5, 3.11.2-6+deb12u7144
python3rpm3.6.8-15.1.el8, 3.6.8-23.el8, 3.6.8-24.el8_2, 3.6.8-24.el8_2.2+24 more0:3.6.8-71.el8_10, 0:3.6.8-71.el8_10.rocky.0129
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm2100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+12 more3.10.12-1~22.04.1158
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more2.7.6-8ubuntu0.6+esm26, 2.7.12-1ubuntu0~16.04.18+esm17, 2.7.17-1~18.04ubuntu1.13+esm12, 2.7.18-1~20.04.7+esm8+1 more54
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm644
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm1925
python3.9rpm3.9.16-1.el9, 3.9.16-1.el9_2.1, 3.9.16-1.el9_2.2, 3.9.18-1.el9_3.1+8 more0:3.9.21-2.el9_6.223
python3.13deb3.13.5-2, 3.13.5-2+e303.13.5-2+deb13u1, 3.13.5-2+e3622
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3+3 more3.12.3-1ubuntu0.820
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf124920
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf124920
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf124920
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf124920
python-urllib3rpm1.24.2-5.el8, 1.24.2-5.el8_6.10:1.25.10-3.module+el8.4.0+9822+20bf1249, 0:1.25.10-4.module+el8.5.0+11712+ea2d2be120
python3x-setuptoolsrpm41.6.0-4.module+el8.4.0+8888+89bc7e79, 41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-3.module+el8.4.0+9822+20bf1249, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-3.module+el8.4.0+23445+8885b4ac.3, 0:50.3.2-7.module+el8.8.0+23471+79c1a0709
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm167
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12497
python39rpm3.9.2-1.module+el8.4.0+10237+bdc77aac, 3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.2-2.module+el8.4.0+23492+77169564.5, 0:3.9.16-1.module+el8.8.0+23491+7a06a3e6.56
python3x-piprpm19.3.1-1.module+el8.4.0+8888+89bc7e79, 19.3.1-6.module+el8.7.0+15823+8950cfa7, 20.2.4-3.module+el8.4.0+9822+20bf12490:20.2.4-3.module+el8.4.0+15042+dc5a279b.1, 0:20.2.4-7.module+el8.6.0+13003+6bb2c4884
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.9.243
python3.11rpm3.11.7-1.el9, 3.11.7-1.el9_4.50:3.11.11-2.el9_6.22
python-3.12apk3.12.0-r1, 3.12.9-r13.12.11-r62
python3.12rpm3.12.5-2.el9_5.20:3.12.9-1.el9_6.21
python-wheelrpm0.33.6-5.module+el8.4.0+8888+89bc7e791:0.35.1-3.module+el8.4.0+15042+dc5a279b.11
OSV records
BIT-python-2025-8194CGA-gpx3-xp28-32xwDEBIAN-CVE-2025-8194RHSA-2025:14560RHSA-2025:15007RHSA-2025:15010RHSA-2025:15019RHSA-2025:16062RHSA-2025:16078RHSA-2025:16118RLSA-2025:14560RLSA-2025:15019UBUNTU-CVE-2025-8194ECHO-053d-4507-0279USN-7710-2
Also known as
BIT-libpython-2025-8194, BIT-python-min-2025-8194, CGA-h5mr-vfp3-hqw6, PSF-2025-11, RHSA-2025:15800, RHSA-2025:15968, RHSA-2025:16016, RHSA-2025:16151, RHSA-2025:16152, RHSA-2025:16153, RHSA-2025:16262, USN-7710-1

Charts affected

589 by stars
ChartLatestAffected imagesRadar Score
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u7
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u7

Open the chart page →

25,681
p4p40.1.02 of 7See more

p4 p4 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11
mastercloudapps/server:v2.23f3d24dfe2686
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10

Open the chart page →

27,667
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-39.el8_4.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-39.el8_4.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10

Open the chart page →

15,466
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
python3.10@3.10.12-1~22.04.4
3.10.12-1~22.04.11

Open the chart page →

3,277
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7

Open the chart page →

5,731
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7

Open the chart page →

8,215
phronetisphronetis0.1.272 of 2See more

phronetis phronetis 0.1.27

2 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
knspar/phronetis:0.1.4609499d2dc91a
python3.12@3.12.3-1ubuntu0.5
3.12.3-1ubuntu0.8
knspar/phronetis-operator:0.1.60c4f0543ee58
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

15,077
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

22,146
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.8

Open the chart page →

7,149
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u7

Open the chart page →

11,373
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

6,695
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

6,641
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.8

Open the chart page →

4,938
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u7

Open the chart page →

11,017
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
library/node:208f693eaa7e0a
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7

Open the chart page →

25,626
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
python3@3.6.8-15.1.el8
0:3.6.8-71.el8_10

Open the chart page →

11,153
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-3.el8_8
python-urllib3@1.24.2-5.el8
python3@3.6.8-51.el8_8.1
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
0:3.6.8-71.el8_10
0:3.9.16-1.module+el8.8.0+23491+7a06a3e6.5
0:50.3.2-7.module+el8.8.0+23471+79c1a070

Open the chart page →

12,754
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

11,680
Practica_4_helmpr04helm0.1.02 of 7See more

Practica_4_helm pr04helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11

Open the chart page →

27,649
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

6,932
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

12,652
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

11,400
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

11,400
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7

Open the chart page →

7,691
rada-platformrada-platform0.1.03 of 7See more

rada-platform rada-platform 0.1.0

3 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u7
trinodb/trino:45038c6f24ab1a4
python3.9@3.9.18-3.el9
0:3.9.21-2.el9_6.2
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
python3.9@3.9.18-3.el9_4.1
0:3.9.21-2.el9_6.2

Open the chart page →

20,812
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
python3.9@3.9.21-1.el9_5
0:3.9.21-2.el9_6.2

Open the chart page →

9,389
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
python3@3.6.8-56.el8_9.3
0:3.6.8-71.el8_10

Open the chart page →

5,269
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
python3.9@3.9.21-1.el9_5
0:3.9.21-2.el9_6.2

Open the chart page →

4,236
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
python3.9@3.9.21-1.el9_5
0:3.9.21-2.el9_6.2

Open the chart page →

1,968
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

15,583
ibm-mongodb-enterprise-helmredhat0.3.01 of 1See more

ibm-mongodb-enterprise-helm redhat 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
python3@3.6.8-31.el8
0:3.6.8-71.el8_10

Open the chart page →

12,248
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-39.el8_4.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10

Open the chart page →

15,290
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-39.el8_4.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10

Open the chart page →

15,290
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
python3@3.6.8-24.el8_2
0:3.6.8-71.el8_10

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-3.el8_6
python-urllib3@1.24.2-5.el8_6.1
python3@3.6.8-47.el8_6.4
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
0:3.6.8-71.el8_10

Open the chart page →

16,060
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-37.el8
python39@3.9.2-1.module+el8.4.0+10237+bdc77aac
python3x-pip@20.2.4-3.module+el8.4.0+9822+20bf1249
python3x-setuptools@50.3.2-3.module+el8.4.0+9822+20bf1249
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10
0:3.9.2-2.module+el8.4.0+23492+77169564.5
0:20.2.4-3.module+el8.4.0+15042+dc5a279b.1
0:50.3.2-3.module+el8.4.0+23445+8885b4ac.3

Open the chart page →

29,226
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

6,562
httpbinrgnu1.0.01 of 1See more

httpbin rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
citizenstig/httpbin:latestb81c818ccb86
python3.5@3.5.2-2ubuntu0~16.04.1
3.5.2-2ubuntu0~16.04.13+esm19

Open the chart page →

11,437
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
python3.11@3.11.2-6+deb12u4
3.11.2-6+deb12u7

Open the chart page →

15,623
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
python3.10@3.10.6-1~22.04.2
3.10.12-1~22.04.11

Open the chart page →

12,999
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
python3.11@3.11.2-6
3.11.2-6+deb12u7
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7

Open the chart page →

66,542
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

31,447
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

11,957
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
python3.10@3.10.12-1~22.04.9
3.10.12-1~22.04.11

Open the chart page →

8,720
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
python3.13@3.13.5-2
3.13.5-2+deb13u1

Open the chart page →

9,421
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

17,736
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

14,792
evsantisbon0.2.02 of 5See more

ev santisbon 0.2.0

2 of the 5 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
santisbon/evwatcher:latestc4e994ca4540
python3.11@3.11.2-6
3.11.2-6+deb12u7
santisbon/evworker:lateste807283f8d69
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

12,090
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
santisbon/speedtest:latest8ee3a1697227
python3.11@3.11.2-6
3.11.2-6+deb12u7

Open the chart page →

11,314

Container images carrying it

597 by charts deploying them

A fixed version is listed for 25 of the 25 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u7
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python3.8@3.8.10-0ubuntu1~20.04.4
python2.7@2.7.18-1~20.04.1
3.8.10-0ubuntu1~20.04.18+esm2
2.7.18-1~20.04.7+esm8
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
python3.9@3.9.18-3.el9_4.1
0:3.9.21-2.el9_6.2
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.8
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.8
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.11
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
python3.11@3.11.2-6+deb12u4
3.11.2-6+deb12u7
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
python3.11@3.11.2-6+deb12u4
3.11.2-6+deb12u7
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
2.7.17-1~18.04ubuntu1.13+esm12
3.6.9-1~18.04ubuntu1.13+esm6
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm2
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
2.7.17-1~18.04ubuntu1.13+esm12
3.6.9-1~18.04ubuntu1.13+esm6
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
python3.13@3.13.5-2+e30
3.13.5-2+e36
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u7
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
python3.9@3.9.19-8.el9_5.1
0:3.9.21-2.el9_6.2
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
python3.9@3.9.19-8.el9_5.1
0:3.9.21-2.el9_6.2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm2
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
python3.9@3.9.18-3.el9_4.5
0:3.9.21-2.el9_6.2
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
python3.11@3.11.7-1.el9_4.5
python3.9@3.9.18-3.el9_4.5
0:3.11.11-2.el9_6.2
0:3.9.21-2.el9_6.2
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
python3@3.6.8-56.el8_9.3
0:3.6.8-71.el8_10
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
python3@3.6.8-56.el8_9
0:3.6.8-71.el8_10
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-51.el8_8.1
python3x-pip@19.3.1-6.module+el8.7.0+15823+8950cfa7
python3x-setuptools@41.6.0-5.module+el8.5.0+12205+a865257a
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
0:3.6.8-71.el8_10
0:20.2.4-7.module+el8.6.0+13003+6bb2c488
0:50.3.2-7.module+el8.8.0+23471+79c1a070
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-37.el8
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-37.el8
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
python3.9@3.9.21-1.el9_5
0:3.9.21-2.el9_6.2
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
python3.6@3.6.9-1~18.04ubuntu1.8
3.6.9-1~18.04ubuntu1.13+esm6
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
python3@3.6.8-45.el8
0:3.6.8-71.el8_10
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
python3@3.6.8-41.el8
0:3.6.8-71.el8_10
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
python3@3.6.8-45.el8
0:3.6.8-71.el8_10
1
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
python3@3.6.8-39.el8_4
0:3.6.8-71.el8_10
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.