StackRadar

CVE-2025-9231

Medium

Advisory

Published 30 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
573
of 17,787 indexed, latest versions
Container images
605
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 573 of 17,787 indexed charts deploy, on 605 images.

Affected packageAffected versionsFixed inImages
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+15 more3.3.5-r0, 3.5.4-r0568
openssldeb3.5.1-13.5.1-1+deb13u121
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
OSV records
ALPINE-CVE-2025-9231CGA-cpj2-wf29-8hr5DEBIAN-CVE-2025-9231UBUNTU-CVE-2025-9231
Also known as
CGA-j26c-v69v-qpfw

Charts affected

573 by stars
ChartLatestAffected imagesRadar Score
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
openssl@3.5.1-r0
3.5.4-r0

Open the chart page →

2,632
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

2,318
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

1,949
mongopingmongoping1.3.11 of 1See more

mongoping mongoping 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
udhos/mongoping:1.3.103b08b63f524
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

1,136
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
openssl@3.3.0-r2
3.3.5-r0

Open the chart page →

4,560
nginx-chartmy-nginx-chart0.1.01 of 1See more

nginx-chart my-nginx-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
amaraiheanacho/nginx-site:latest5c86fccf5daa
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

840
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
openssl@3.3.1-r3
3.3.5-r0

Open the chart page →

17,411
fargate-sidecar-injectormziyaboVerified publisher0.1.51 of 1See more

fargate-sidecar-injector mziyabo 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
openssl@3.3.0-r2
3.3.5-r0

Open the chart page →

1,393
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

1,783
proxy-pynas-helm-chartsVerified publisher1.0.01 of 1See more

proxy-py nas-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
abhinavsingh/proxy.py:latest51adc989fd03
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

593
redisneomanexlabsVerified publisher1.1.01 of 1See more

redis neomanexlabs 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

1,288
neosyncneosyncVerified publisher0.5.411 of 3See more

neosync neosync 0.5.41

1 of the 3 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

7,056
appneosync-appVerified publisher0.5.411 of 1See more

app neosync-app 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

1,569
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
openssl@3.5.1-1
3.5.1-1+deb13u1

Open the chart page →

3,821
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
openssl@3.3.3-r0
3.3.5-r0
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
openssl@3.3.3-r0
3.3.5-r0
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
openssl@3.3.2-r4
3.3.5-r0

Open the chart page →

5,036
nginx-sitenginx-site0.1.01 of 1See more

nginx-site nginx-site 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
amaraiheanacho/nginx-site:latest5c86fccf5daa
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

840
ciliumnicklasfrahm-ciliumVerified publisher0.7.41 of 6See more

cilium nicklasfrahm-cilium 0.7.4

1 of the 6 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
quay.io/cilium/hubble-ui:v0.13.3661d5de70501
openssl@3.5.2-r0
3.5.4-r0

Open the chart page →

7,170
wireguardnicklasfrahm-wireguard0.2.01 of 1See more

wireguard nicklasfrahm-wireguard 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

1,158
node-hostnamenode-hostnameVerified publisher1.0.11 of 1See more

node-hostname node-hostname 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
christianhuth/node-hostname:1.0.1c07f414a3e4b
openssl@3.3.2-r4
3.3.5-r0

Open the chart page →

884
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

2,007
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

2,007
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
nodejs@10.23.0-1nodesource1
no fix listed

Open the chart page →

27,486
lensoci-ai-incubations0.1.143 of 16See more

lens oci-ai-incubations 0.1.14

3 of the 16 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
openssl@3.5.0-r0
3.5.4-r0
grafana/grafana:12.1.1a1701c218024
openssl@3.5.1-r0
3.5.4-r0
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.4-r0

Open the chart page →

17,085
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

5,825
oom-traceroom-tracerVerified publisher0.1.01 of 1See more

oom-tracer oom-tracer 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
openssl@3.5.1-r0
3.5.4-r0

Open the chart page →

1,124
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
nodejs@8.9.4-1nodesource1
no fix listed

Open the chart page →

88,616
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
nodejs@8.9.4-1nodesource1
no fix listed

Open the chart page →

38,889
everest-db-namespaceopeneverestVerified publisher1.16.21 of 1See more

everest-db-namespace openeverest 1.16.2

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.5-r0

Open the chart page →

768
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
openssl@3.3.2-r4
3.3.5-r0

Open the chart page →

740
gcp-pubsub-connectoropenfaas0.0.11 of 1See more

gcp-pubsub-connector openfaas 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

1,155
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
openssl@3.3.2-r4
3.3.5-r0

Open the chart page →

1,070
pro-builderopenfaas0.6.131 of 2See more

pro-builder openfaas 0.6.13

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

2,728
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
openssl@3.3.2-r4
3.3.5-r0

Open the chart page →

776
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
openssl@3.3.2-r4
3.3.5-r0

Open the chart page →

766
kruise-gameopenkruise1.1.01 of 1See more

kruise-game openkruise 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

911
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
library/redis:7.2.5-alpine6aaf3f5e6bc8
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

3,462
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
openssl@3.3.4-r0
3.3.5-r0

Open the chart page →

7,848
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
no fix listed

Open the chart page →

36,230
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

2,003
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
replicated/replicated-sdk:1.0.0-beta.318751b4963250
openssl@3.3.2-r2
3.5.4-r0

Open the chart page →

5,609
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
alpine/curl:8.12.08943e8c7e8e4
openssl@3.3.2-r4
3.3.5-r0

Open the chart page →

4,539
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

838
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.04 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

4 of the 40 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
library/postgres:17.5-alpine6567bca8d7bc
openssl@3.5.1-r0
3.5.4-r0
library/postgres:17.2-alpine7e5df973a748
openssl@3.3.2-r4
3.3.5-r0
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.5-r0
yetiplatform/bloomcheck:dev85683ddfccbb
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

72,154
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
openssl@3.3.0-r2
3.3.5-r0

Open the chart page →

5,410
parcaparca-rr0.1.01 of 2See more

parca parca-rr 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.24.23776500fde82
openssl@3.5.1-r0
3.5.4-r0

Open the chart page →

2,367
parcial-1parcial-1-chart1.0.02 of 5See more

parcial-1 parcial-1-chart 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
esteban1930/frontend-1:1.8.0f9078279632c
openssl@3.5.1-r0
3.5.4-r0
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.4-r0

Open the chart page →

3,852
clickhousepascaliskeVerified publisher1.0.01 of 1See more

clickhouse pascaliske 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6.70-alpinecd450891db46
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

345
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
openssl@3.3.2-r1
3.3.5-r0

Open the chart page →

959
everest-db-namespacepercona1.13.01 of 1See more

everest-db-namespace percona 1.13.0

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.5-r0

Open the chart page →

768
blockmeta-servicepinaxVerified publisher0.0.31 of 1See more

blockmeta-service pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-9231.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
openssl@3.1.4-r2
3.3.5-r0

Open the chart page →

1,681

Container images carrying it

605 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.1-1+deb13u1
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.4-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.4-r0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
openssl@3.3.2-r0
3.3.5-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.5-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.