StackRadar

CVE-2025-8961

Medium

Advisory

Published 14 Aug 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
350
of 17,787 indexed, latest versions
Container images
355
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 350 of 17,787 indexed charts deploy, on 355 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+37 more4.0.3-7ubuntu0.11+esm16, 4.0.6-1ubuntu0.8+esm19, 4.0.9-5ubuntu0.10+esm9, 4.1.0+git191117-2ubuntu0.20.04.14+esm2+3 more324
tiffapk4.7.0-r04.7.1-r031
OSV records
ALPINE-CVE-2025-8961DEBIAN-CVE-2025-8961UBUNTU-CVE-2025-8961
Also known as
USN-7783-1

Charts affected

350 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

355 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
tiff@4.0.9-5ubuntu0.3
4.0.9-5ubuntu0.10+esm9
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
tiff@4.0.6-1ubuntu0.4
4.0.6-1ubuntu0.8+esm19
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.14+esm2
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.14+esm2
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
tiff@4.5.0-6+deb12u1
no fix listed
1
ispras/svacer:11-2-042aa9fa9f189
tiff@4.3.0-6ubuntu0.10
4.3.0-6ubuntu0.12
1
jaedb/iris:latest048cfbf58d57
tiff@4.5.0-6+deb12u2
no fix listed
1
jbtronics/part-db1:latest5db71f6db59d
tiff@4.5.0-6+deb12u4
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
tiff@4.5.0-6+deb12u1
no fix listed
1
jlesage/firefox:v25.03.1055c28defe31
tiff@4.7.0-r0
4.7.1-r0
1
jordan/icinga2:latestf75025fe8ea8
tiff@4.5.0-6+deb12u4
no fix listed
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
tiff@4.5.0-6+deb12u4
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
tiff@4.5.0-6+deb12u1
no fix listed
1
kong/httpbin:latesta6ac46531193
tiff@4.3.0-6ubuntu0.10
4.3.0-6ubuntu0.12
1
kusionstack/kusion:v0.14.0126c8f0b0976
tiff@4.3.0-6ubuntu0.10
4.3.0-6ubuntu0.12
1
kuzwolka/aws9:main1ad759b961b1
tiff@4.5.0-6+deb12u2
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
tiff@4.5.0-6+deb12u2
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
tiff@4.5.0-6+deb12u2
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
tiff@4.5.0-6+deb12u2
no fix listed
1
laly9999/node-app:1dd0e503913e1
tiff@4.5.0-6+deb12u2
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
tiff@4.5.0-6+deb12u3
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
tiff@4.5.0-6+deb12u1
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
tiff@4.5.0-6+deb12u2
no fix listed
1
library/nginx:1.27.409369da6b103
tiff@4.5.0-6+deb12u2
no fix listed
1
library/nginx:1.27-alpine65645c7bb6a0
tiff@4.7.0-r0
4.7.1-r0
1
library/nginx:1.276784fb0834aa
tiff@4.5.0-6+deb12u2
no fix listed
1
library/nginx:1.25.167f9a4f10d14
tiff@4.5.0-6
no fix listed
1
library/nginx:1.25.49ff236ed47fe
tiff@4.5.0-6+deb12u1
no fix listed
1
library/nginx:1.27.3fb197595ebe7
tiff@4.5.0-6+deb12u1
no fix listed
1
library/node:208f693eaa7e0a
tiff@4.5.0-6+deb12u4
no fix listed
1
library/python:3.8d41127070014
tiff@4.5.0-6+deb12u1
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
tiff@4.5.0-6+deb12u1
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.10+esm9
1
linuxserver/calibre-web:0.6.24241009026e6f
tiff@4.5.1+git230720-4ubuntu2.3
4.5.1+git230720-4ubuntu2.4
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14+esm2
1
linuxserver/deluge:18.04.10ac871624394
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.10+esm9
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.10+esm9
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.10+esm9
1
livekit/ingress:v1.2.21ab01641b366
tiff@4.3.0-6ubuntu0.4
4.3.0-6ubuntu0.12
1
logiqai/flash:v3.10.265b996bc7bdc
tiff@4.5.0-6+deb12u1
no fix listed
1
louislam/uptime-kuma:2.5.33e24e96c89ef
tiff@4.5.0-6+deb12u4
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
tiff@4.5.0-6+deb12u3
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
tiff@4.5.0-6+deb12u4
no fix listed
1
makersquad/harp-proxy:0.8.1a40dd258c527
tiff@4.5.0-6+deb12u2
no fix listed
1
martinhelmich/typo3:12.4c83a4f3fd7ae
tiff@4.5.0-6+deb12u3
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
tiff@4.5.0-6+deb12u4
no fix listed
1
mavrick1/kubestellar-f:latest56bd8eaa53a4
tiff@4.7.0-r0
4.7.1-r0
1
mbround18/valheim:3.1.070bd4da591cd
tiff@4.3.0-6ubuntu0.10
4.3.0-6ubuntu0.12
1
mediagis/nominatim:3.7c15e941485ef
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.14+esm2
1
mediagis/nominatim:4.2d0eae7b51374
tiff@4.3.0-6ubuntu0.7
4.3.0-6ubuntu0.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.