StackRadar

CVE-2025-9231

Medium

Advisory

Published 30 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
573
of 17,787 indexed, latest versions
Container images
605
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 573 of 17,787 indexed charts deploy, on 605 images.

Affected packageAffected versionsFixed inImages
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+15 more3.3.5-r0, 3.5.4-r0568
openssldeb3.5.1-13.5.1-1+deb13u121
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
OSV records
ALPINE-CVE-2025-9231CGA-cpj2-wf29-8hr5DEBIAN-CVE-2025-9231UBUNTU-CVE-2025-9231
Also known as
CGA-j26c-v69v-qpfw

Charts affected

573 by stars
ChartLatestAffected imagesRadar Score
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
openssl@3.5.1-r0
3.5.4-r0

Open the chart page →

1,527
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
openssl@3.5.1-r0
3.5.4-r0

Open the chart page →

1,690
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

929
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

45,392
vault-raft-snapshot-agentvault-raft-snapshot-agentVerified publisher0.6.91 of 1See more

vault-raft-snapshot-agent vault-raft-snapshot-agent 0.6.9

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

1,114
simple-prima-notavcnngrVerified publisher0.5.33 of 4See more

simple-prima-nota vcnngr 0.5.3

3 of the 4 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
openssl@3.3.3-r0
3.3.5-r0
vcnngr/pnbackend:latesteaf44ad0ad1f
openssl@3.3.3-r0
3.3.5-r0
vcnngr/pnfrontend:latest4e4979ab8c41
openssl@3.5.1-r0
3.5.4-r0

Open the chart page →

4,769
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
openssl@3.3.1-r3
3.3.5-r0

Open the chart page →

4,302
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
no fix listed

Open the chart page →

9,396
mosquittovicsuferVerified publisher0.1.11 of 1See more

mosquitto vicsufer 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.2021421af7b32b
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

364
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

2,077
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
openssl@3.5.2-r0
3.5.4-r0

Open the chart page →

6,470
vote-appvote-appVerified publisher1.0.72 of 6See more

vote-app vote-app 1.0.7

2 of the 6 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
openssl@3.3.0-r2
3.3.5-r0
thecloudspark/app-vote:1.0c7da7417a86a
openssl@3.3.0-r2
3.3.5-r0

Open the chart page →

3,030
waldur-site-agentwaldur-site-agentVerified publisher1.0.71 of 1See more

waldur-site-agent waldur-site-agent 1.0.7

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
openssl@3.3.2-r1
3.3.5-r0

Open the chart page →

534
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
wallarm/node-next:0.5.24314f3d2b918
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

2,408
hazelcastwenerme5.10.31 of 2See more

hazelcast wenerme 5.10.3

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
openssl@3.3.1-r3
3.3.5-r0

Open the chart page →

2,623
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
openssl@3.5.0-r0
3.5.4-r0
temporalio/server:1.29.1c1e3326b2ce1
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

14,618
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
openssl@3.3.1-r3
3.3.5-r0

Open the chart page →

6,323
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
openssl@3.3.2-r4
3.3.5-r0

Open the chart page →

1,286
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

1,187
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

789
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,172
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

13,197
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

9,381

Container images carrying it

605 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
openssl@3.3.0-r2
3.3.5-r0
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
openssl@3.3.2-r0
3.3.5-r0
1
ghcr.io/parca-dev/parca:v0.24.23776500fde82
openssl@3.5.1-r0
3.5.4-r0
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
openssl@3.3.2-r1
3.3.5-r0
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
openssl@3.3.2-r0
3.3.5-r0
1
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
openssl@3.3.2-r1
3.3.5-r0
1
ghcr.io/pyrra-dev/pyrra:v0.8.10e02ef538ef0
openssl@3.3.2-r0
3.3.5-r0
1
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
openssl@3.3.2-r1
3.3.5-r0
1
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
openssl@3.3.2-r1
3.3.5-r0
1
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
openssl@3.3.2-r1
3.3.5-r0
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
openssl@3.5.1-r0
3.5.4-r0
1
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
openssl@3.5.0-r0
3.5.4-r0
1
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
openssl@3.1.4-r2
3.3.5-r0
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
openssl@3.3.1-r0
3.3.5-r0
1
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
openssl@3.3.2-r0
3.3.5-r0
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
openssl@3.5.1-r0
3.5.4-r0
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/usememos/memos:0.24.04723d86e6797
openssl@3.3.2-r4
3.3.5-r0
1
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
openssl@3.3.2-r0
3.3.5-r0
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
openssl@3.5.0-r0
3.5.4-r0
1
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
openssl@3.3.2-r4
3.3.5-r0
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
openssl@3.3.1-r0
3.3.5-r0
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
openssl@3.3.2-r0
3.3.5-r0
1
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
openssl@3.3.2-r4
3.3.5-r0
1
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
openssl@3.3.0-r2
3.3.5-r0
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
openssl@3.3.1-r3
3.3.5-r0
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
openssl@3.3.2-r4
3.3.5-r0
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
openssl@3.5.0-r0
3.5.4-r0
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
openssl@3.3.2-r0
3.3.5-r0
1
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
openssl@3.5.1-r0
3.5.4-r0
1
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
openssl@3.3.4-r0
3.3.5-r0
1
quay.io/cilium/hubble-ui:v0.13.3661d5de70501
openssl@3.5.2-r0
3.5.4-r0
1
quay.io/jupyterhub/configurable-http-proxy:5.1.0eb10d5bf045c
openssl@3.3.4-r0
3.3.5-r0
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
openssl@3.3.3-r0
3.3.5-r0
1
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
openssl@3.5.1-r0
3.5.4-r0
1
quay.io/kubevirt/aaq-operator:v1.7.0d28a2daa5b15
openssl@3.5.1-r0
3.5.4-r0
1
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
openssl@3.3.3-r0
3.3.5-r0
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
openssl@3.3.1-r3
3.3.5-r0
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
openssl@3.3.3-r0
3.3.5-r0
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.4-r0
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
openssl@3.3.3-r0
3.3.5-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.