StackRadar

CVE-2025-8194

High

Advisory

Published 28 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
589
of 17,787 indexed, latest versions
Container images
597
deployed by those charts
Fix available
25 of 25
affected packages

Tarfile infinite loop during parsing with negative member offset

Carried by container images the latest versions of 589 of 17,787 indexed charts deploy, on 597 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.2-6, 3.11.2-6+deb12u2, 3.11.2-6+deb12u3+3 more3.11.0~rc1-1~22.04.1~esm5, 3.11.2-6+deb12u7144
python3rpm3.6.8-15.1.el8, 3.6.8-23.el8, 3.6.8-24.el8_2, 3.6.8-24.el8_2.2+24 more0:3.6.8-71.el8_10, 0:3.6.8-71.el8_10.rocky.0129
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm2100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+12 more3.10.12-1~22.04.1158
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more2.7.6-8ubuntu0.6+esm26, 2.7.12-1ubuntu0~16.04.18+esm17, 2.7.17-1~18.04ubuntu1.13+esm12, 2.7.18-1~20.04.7+esm8+1 more54
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm644
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm1925
python3.9rpm3.9.16-1.el9, 3.9.16-1.el9_2.1, 3.9.16-1.el9_2.2, 3.9.18-1.el9_3.1+8 more0:3.9.21-2.el9_6.223
python3.13deb3.13.5-2, 3.13.5-2+e303.13.5-2+deb13u1, 3.13.5-2+e3622
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3+3 more3.12.3-1ubuntu0.820
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf124920
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf124920
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf124920
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf124920
python-urllib3rpm1.24.2-5.el8, 1.24.2-5.el8_6.10:1.25.10-3.module+el8.4.0+9822+20bf1249, 0:1.25.10-4.module+el8.5.0+11712+ea2d2be120
python3x-setuptoolsrpm41.6.0-4.module+el8.4.0+8888+89bc7e79, 41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-3.module+el8.4.0+9822+20bf1249, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-3.module+el8.4.0+23445+8885b4ac.3, 0:50.3.2-7.module+el8.8.0+23471+79c1a0709
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm167
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12497
python39rpm3.9.2-1.module+el8.4.0+10237+bdc77aac, 3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.2-2.module+el8.4.0+23492+77169564.5, 0:3.9.16-1.module+el8.8.0+23491+7a06a3e6.56
python3x-piprpm19.3.1-1.module+el8.4.0+8888+89bc7e79, 19.3.1-6.module+el8.7.0+15823+8950cfa7, 20.2.4-3.module+el8.4.0+9822+20bf12490:20.2.4-3.module+el8.4.0+15042+dc5a279b.1, 0:20.2.4-7.module+el8.6.0+13003+6bb2c4884
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.9.243
python3.11rpm3.11.7-1.el9, 3.11.7-1.el9_4.50:3.11.11-2.el9_6.22
python-3.12apk3.12.0-r1, 3.12.9-r13.12.11-r62
python3.12rpm3.12.5-2.el9_5.20:3.12.9-1.el9_6.21
python-wheelrpm0.33.6-5.module+el8.4.0+8888+89bc7e791:0.35.1-3.module+el8.4.0+15042+dc5a279b.11
OSV records
BIT-python-2025-8194CGA-gpx3-xp28-32xwDEBIAN-CVE-2025-8194RHSA-2025:14560RHSA-2025:15007RHSA-2025:15010RHSA-2025:15019RHSA-2025:16062RHSA-2025:16078RHSA-2025:16118RLSA-2025:14560RLSA-2025:15019UBUNTU-CVE-2025-8194ECHO-053d-4507-0279USN-7710-2
Also known as
BIT-libpython-2025-8194, BIT-python-min-2025-8194, CGA-h5mr-vfp3-hqw6, PSF-2025-11, RHSA-2025:15800, RHSA-2025:15968, RHSA-2025:16016, RHSA-2025:16151, RHSA-2025:16152, RHSA-2025:16153, RHSA-2025:16262, USN-7710-1

Charts affected

589 by stars
ChartLatestAffected imagesRadar Score
eoloPlanteolo-plannerVerified publisher0.1.02 of 7See more

eoloPlant eolo-planner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11
mastercloudapps/server:v2.23f3d24dfe2686
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10

Open the chart page →

27,667
eoloplannereoloplannerVerified publisher0.1.02 of 7See more

eoloplanner eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11

Open the chart page →

32,336
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.02 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11
mastercloudapps/server:v2.23f3d24dfe2686
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10

Open the chart page →

27,667
eoloplannereoloplanner-molynx-gat0.1.02 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11

Open the chart page →

28,539
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11

Open the chart page →

27,188
eoloplanteoloplant1.0.02 of 7See more

eoloplant eoloplant 1.0.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11
mastercloudapps/server:v2.23f3d24dfe2686
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10

Open the chart page →

27,667
eoloplantseoloplants-urjcVerified publisher0.1.02 of 7See more

eoloplants eoloplants-urjc 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11

Open the chart page →

27,812
servereoloserverVerified publisher0.1.02 of 7See more

server eoloserver 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
python3@3.6.8-48.el8_7
0:3.6.8-71.el8_10
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11

Open the chart page →

32,336
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
python3.8@3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

9,383
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

20,987
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
python3.5@3.5.2-2ubuntu0~16.04.9
3.5.2-2ubuntu0~16.04.13+esm19

Open the chart page →

14,688
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u7

Open the chart page →

10,119
apollofiware0.1.41 of 1See more

apollo fiware 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/apollo:0.0.1055330b1b60c1
python3@3.6.8-45.el8
0:3.6.8-71.el8_10

Open the chart page →

6,935
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm2
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7

Open the chart page →

64,192
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
python3@3.6.8-41.el8
0:3.6.8-71.el8_10

Open the chart page →

8,528
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10

Open the chart page →

2,474
contract-managementfiware3.5.361 of 1See more

contract-management fiware 3.5.36

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/contract-management:3.3.122bcfcf874451
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10

Open the chart page →

2,411
credentials-config-servicefiware2.6.41 of 1See more

credentials-config-service fiware 2.6.4

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10

Open the chart page →

2,292
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
python3@3.6.8-48.el8_7.1
0:3.6.8-71.el8_10

Open the chart page →

4,536
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
python3@3.6.8-45.el8
0:3.6.8-71.el8_10

Open the chart page →

11,834
mintakafiware0.4.71 of 1See more

mintaka fiware 0.4.7

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
fiware/mintaka:latestefc6793388cc
python3@3.6.8-45.el8
0:3.6.8-71.el8_10

Open the chart page →

7,019
orionfiware1.6.111 of 2See more

orion fiware 1.6.11

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10

Open the chart page →

10,638
tm-forum-apifiware0.17.1519 of 19See more

tm-forum-api fiware 0.17.15

19 of the 19 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/tmforum-account:1.18.06b25aac03414
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10

Open the chart page →

35,112
trusted-issuers-listfiware0.18.71 of 1See more

trusted-issuers-list fiware 0.18.7

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
python3.9@3.9.21-2.el9_6.1
0:3.9.21-2.el9_6.2

Open the chart page →

1,718
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
python3@3.6.8-45.el8
0:3.6.8-71.el8_10

Open the chart page →

7,087
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7

Open the chart page →

8,831
maxscalefour-allportalVerified publisher4.1.161 of 3See more

maxscale four-allportal 4.1.16

1 of the 3 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
mariadb/maxscale:23.02.256c5e0908148
python3@3.6.8-51.el8.rocky.0
0:3.6.8-71.el8_10.rocky.0

Open the chart page →

6,610
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
python3@3.6.8-56.el8_9.3
0:3.6.8-71.el8_10

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
python3@3.6.8-56.el8_9.3
0:3.6.8-71.el8_10

Open the chart page →

11,961
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
python3.8@3.8.5-1~20.04.3
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

18,217
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

16,178
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm6

Open the chart page →

13,572
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
python3.8@3.8.10-0ubuntu1~20.04.1
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

12,270
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

11,042
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7

Open the chart page →

12,993
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
python3.10@3.10.4-3ubuntu0.1
3.10.12-1~22.04.11

Open the chart page →

12,124
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

17,758
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

28,039
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

15,792
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

11,855
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

24,355
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
python3.6@3.6.6-1~18.04
3.6.9-1~18.04ubuntu1.13+esm6

Open the chart page →

26,996
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

11,909
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm2

Open the chart page →

17,996
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7

Open the chart page →

4,266
knativegitlabVerified publisher0.10.03 of 10See more

knative gitlab 0.10.0

3 of the 10 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
istio/node-agent-k8s:1.2.9268ab879ea51
python3.5@3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.13+esm19
istio/pilot:1.2.9c09319753454
python3.5@3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.13+esm19
istio/proxyv2:1.2.90c78be035e98
python3.5@3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.13+esm19

Open the chart page →

36,145
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u7

Open the chart page →

12,270
jaegergpg-dev3.3.32 of 5See more

jaeger gpg-dev 3.3.3

2 of the 5 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.11
library/cassandra:3.11.65aa8400b4b3b
python2.7@2.7.17-1~18.04ubuntu1.1
2.7.17-1~18.04ubuntu1.13+esm12

Open the chart page →

19,291
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
python3.12@3.12.3-1ubuntu0.1
3.12.3-1ubuntu0.8

Open the chart page →

7,935
temporalgroundcover1.12.3591 of 2See more

temporal groundcover 1.12.359

1 of the 2 container images this version deploys carry CVE-2025-8194.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
python3.13@3.13.5-2+e30
3.13.5-2+e36

Open the chart page →

2,001

Container images carrying it

597 by charts deploying them

A fixed version is listed for 25 of the 25 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u7
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python3.8@3.8.10-0ubuntu1~20.04.4
python2.7@2.7.18-1~20.04.1
3.8.10-0ubuntu1~20.04.18+esm2
2.7.18-1~20.04.7+esm8
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
python3.9@3.9.18-3.el9_4.1
0:3.9.21-2.el9_6.2
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.8
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.8
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm2
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.11
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u7
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u7
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
python3.11@3.11.2-6+deb12u4
3.11.2-6+deb12u7
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
python3.11@3.11.2-6+deb12u4
3.11.2-6+deb12u7
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
2.7.17-1~18.04ubuntu1.13+esm12
3.6.9-1~18.04ubuntu1.13+esm6
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm2
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
2.7.17-1~18.04ubuntu1.13+esm12
3.6.9-1~18.04ubuntu1.13+esm6
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
python3.13@3.13.5-2+e30
3.13.5-2+e36
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u7
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
python3.9@3.9.19-8.el9_5.1
0:3.9.21-2.el9_6.2
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
python3.9@3.9.19-8.el9_5.1
0:3.9.21-2.el9_6.2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm2
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
python3.11@3.11.2-6
3.11.2-6+deb12u7
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
python3.9@3.9.18-3.el9_4.5
0:3.9.21-2.el9_6.2
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
python3.11@3.11.7-1.el9_4.5
python3.9@3.9.18-3.el9_4.5
0:3.11.11-2.el9_6.2
0:3.9.21-2.el9_6.2
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
python3@3.6.8-56.el8_9.3
0:3.6.8-71.el8_10
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
python3@3.6.8-56.el8_9
0:3.6.8-71.el8_10
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-51.el8_8.1
python3x-pip@19.3.1-6.module+el8.7.0+15823+8950cfa7
python3x-setuptools@41.6.0-5.module+el8.5.0+12205+a865257a
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
0:3.6.8-71.el8_10
0:20.2.4-7.module+el8.6.0+13003+6bb2c488
0:50.3.2-7.module+el8.8.0+23471+79c1a070
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-37.el8
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-urllib3@1.24.2-5.el8
python3@3.6.8-37.el8
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-3.module+el8.4.0+9822+20bf1249
0:3.6.8-71.el8_10
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
python3.9@3.9.21-1.el9_5
0:3.9.21-2.el9_6.2
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
python3.6@3.6.9-1~18.04ubuntu1.8
3.6.9-1~18.04ubuntu1.13+esm6
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
python3@3.6.8-45.el8
0:3.6.8-71.el8_10
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
python3@3.6.8-41.el8
0:3.6.8-71.el8_10
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
python3@3.6.8-67.el8_10
0:3.6.8-71.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
python3@3.6.8-45.el8
0:3.6.8-71.el8_10
1
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
python3@3.6.8-39.el8_4
0:3.6.8-71.el8_10
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
python3@3.6.8-70.el8_10
0:3.6.8-71.el8_10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.