StackRadar

CVE-2025-8713

Low

Advisory

Published 14 Aug 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
215
of 17,781 indexed, latest versions
Container images
193
deployed by those charts
Fix available
8 of 12
affected packages

PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table

Carried by container images the latest versions of 215 of 17,781 indexed charts deploy, on 193 images.

Affected packageAffected versionsFixed inImages
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+1, 15.5-0+deb12u1+7 more15.14-0+deb12u197
postgresqlbitnami11.8.0-10, 11.12.0-7, 14.4.0-0, 14.4.0-11+25 more13.22.030
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 moreno fix listed17
postgresql16apk16.1-r0, 16.2-r0, 16.2-r1, 16.3-r0+3 more16.10-r015
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+5 more14.19-0ubuntu0.22.04.113
PostgreSQLbitnami15.3.0, 15.4.0, 15.5.0-42, 16.0.0+6 more13.22.011
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql17apk17.2-r0, 17.4-r0, 17.5-r017.6-r05
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.1, 16.9-0ubuntu0.24.04.116.10-0ubuntu0.24.04.13
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-17deb17.5-1, 17.5-1.pgdg130+117.6-0+deb13u12
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
OSV records
ALPINE-CVE-2025-8713BIT-postgresql-2025-8713DEBIAN-CVE-2025-8713UBUNTU-CVE-2025-8713
Also known as
USN-7741-1

Charts affected

215 by stars
ChartLatestAffected imagesRadar Score
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1

Open the chart page →

28,858
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
postgresql-12@12.19-0ubuntu0.20.04.1
no fix listed

Open the chart page →

10,006
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
13.22.0

Open the chart page →

5,535
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
postgresql-15@15.5-0+deb12u1
15.14-0+deb12u1

Open the chart page →

17,323
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.10-0ubuntu0.24.04.1

Open the chart page →

45,239
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.14-0+deb12u1

Open the chart page →

14,358
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
postgresql-15@15.10-0+deb12u1
15.14-0+deb12u1

Open the chart page →

10,795
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgresql-14@14.11-1.pgdg22.04+1
14.19-0ubuntu0.22.04.1

Open the chart page →

13,459
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1

Open the chart page →

7,085
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1

Open the chart page →

8,811
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
postgresql17@17.5-r0
17.6-r0

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
13.22.0

Open the chart page →

7,624
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-8713.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
postgresql@16.6.0-1
13.22.0

Open the chart page →

11,577

Container images carrying it

193 by charts deploying them

A fixed version is listed for 8 of the 12 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
postgresql@17.2.0-4
13.22.0
1
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
postgresql@17.2.0-1
13.22.0
1
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
postgresql@16.2.0-2
PostgreSQL@16.2.0-2
13.22.0
13.22.0
1
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
postgresql@17.4.0-9
13.22.0
1
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
postgresql@16.3.0-12
13.22.0
1
bmeares/meerschaum:2.8.48e9c5bacaa82
postgresql-15@15.10-0+deb12u1
15.14-0+deb12u1
1
bnjbvr/kresus:0.22.137e216b182c8
postgresql-15@15.10-0+deb12u1
15.14-0+deb12u1
1
calltelemetry/web:0.8.1-rc7205d13269e350
postgresql-15@15.8-0+deb12u1
15.14-0+deb12u1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
postgresql-15@15.8-0+deb12u1
15.14-0+deb12u1
1
ckulka/baikal:0.10.1-nginx434bdd162247
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
postgresql17@17.5-r0
17.6-r0
1
devopstales/kubedash:3.1.08bb837da5aec
postgresql16@16.9-r0
16.10-r0
1
djjudas21/dbdump:0.0.917fc245e29bd
postgresql16@16.2-r0
16.10-r0
1
felipecs8/app-db-connection-test:v129e06c9c6385
postgresql-15@15.10-0+deb12u1
15.14-0+deb12u1
1
firefart/requesttracker:5.0.40d6249906d8c
postgresql-15@15.3-0+deb12u1
15.14-0+deb12u1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1
1
fluent/fluent-bit:4.0.4ca08b7d2df5b
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
postgresql16@16.4-r0
16.10-r0
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
postgresql-14@14.18-0ubuntu0.22.04.1
14.19-0ubuntu0.22.04.1
1
galaxy/galaxy-stable:v18.018e577a626dfd
postgresql-9.3@9.3.22-0ubuntu0.14.04
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
postgresql-10@10.14-0ubuntu0.18.04.1
no fix listed
1
graphprotocol/graph-node:v0.37.0f4452cdedd68
postgresql-15@15.10-0+deb12u1
15.14-0+deb12u1
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
postgresql-15@15.3-0+deb12u1
15.14-0+deb12u1
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
postgresql-10@10.15-0ubuntu0.18.04.1
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
postgresql-15@15.5-0+deb12u1
15.14-0+deb12u1
1
knspar/phronetis-operator:0.1.60c4f0543ee58
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1
1
laly9999/node-app:1dd0e503913e1
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1
1
library/nextcloud:31.0.6-apache588609d76b21
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1
1
library/postgres:15.38775adb39f0d
postgresql-15@15.3-1.pgdg120+1
15.14-0+deb12u1
1
library/postgres:17.5aadf2c0696f5
postgresql-17@17.5-1.pgdg130+1
17.6-0+deb13u1
1
library/python:3.8d41127070014
postgresql-15@15.8-0+deb12u1
15.14-0+deb12u1
1
librenms/librenms:24.11.00920bc9117a8
postgresql16@16.6-r0
16.10-r0
1
linuxserver/heimdall:2.6.371597f4461e4
postgresql16@16.9-r0
16.10-r0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
postgresql-15@15.12-0+deb12u2
15.14-0+deb12u1
1
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
postgresql-15@15.8-0+deb12u1
15.14-0+deb12u1
1
matterlabs/external-node:v24.0.06cbfea4c694a
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1
1
mediagis/nominatim:3.7c15e941485ef
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
postgresql-14@14.10-0ubuntu0.22.04.1
14.19-0ubuntu0.22.04.1
1
middlewareeng/middleware:0.3.1747d880812f1
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
postgresql-15@15.12-0+deb12u2
15.14-0+deb12u1
1
moreillon/api-proxy:latestd7d4a5463525
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1
1
moreillon/food-manager:lateste8fd856e593d
postgresql-15@15.13-0+deb12u1
15.14-0+deb12u1
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
postgresql-15@15.5-0+deb12u1
15.14-0+deb12u1
1
muhammedgamal/fp23:latest74b4cd69b6fa
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1
1
netboxcommunity/netbox:v3.2.83d652dca5351
postgresql-14@14.4-0ubuntu0.22.04.1
14.19-0ubuntu0.22.04.1
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1
1
opea/codetrans-ui:1.03ef121f34610
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1
1
opea/docsum-ui:1.07f854e9bffaf
postgresql-15@15.6-0+deb12u1
15.14-0+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.