CVE-2025-9231
MediumAdvisory
Published 30 Sept 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.022
- 82nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 567
- of 17,781 indexed, latest versions
- Container images
- 598
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 567 of 17,781 indexed charts deploy, on 598 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| opensslapk | 3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+15 more | 3.3.5-r0, 3.5.4-r0 | 561 |
| openssldeb | 3.5.1-1 | 3.5.1-1+deb13u1 | 21 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 more | no fix listed | 16 |
- OSV records
- ALPINE-CVE-2025-9231CGA-cpj2-wf29-8hr5DEBIAN-CVE-2025-9231UBUNTU-CVE-2025-9231
- Also known as
- CGA-j26c-v69v-qpfw
Charts affected
567 by stars
Container images carrying it
598 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| pnnlmiscscripts/ | cfbc9b70cbf8 | openssl | 3.3.5-r0 | 6 |
| keelhq/ | 73714afb4443 | openssl | 3.3.5-r0 | 5 |
| library/ | 02419de7eddf | openssl | 3.3.5-r0 | 5 |
| artifacthub/ | 4fd34fa635cc | openssl | 3.5.1-1+deb13u1 | 4 |
| openquantumsafe/ | 543fb00ce31d | openssl | 3.3.5-r0 | 4 |
| ghcr.io/ | d04c003d7593 | openssl | 3.3.5-r0 | 4 |
| derailed/ | 8e68e22c7663 | openssl | 3.3.5-r0 | 3 |
| grafana/ | a0f881232a6f | openssl | 3.3.5-r0 | 3 |
| kiwigrid/ | 4166a019eeaf | openssl | 3.3.5-r0 | 3 |
| kiwigrid/ | cdb361e67b1b | openssl | 3.3.5-r0 | 3 |
| library/ | 468d34fefd63 | openssl | 3.3.5-r0 | 3 |
| opencsghq/ | 57def8e77d0f | openssl | 3.3.5-r0 | 3 |
| public.ecr.aws/ | c88ea2979a49 | openssl | 3.3.5-r0 | 3 |
| quay.io/ | 03c7bf249aa1 | openssl | 3.3.5-r0 | 3 |
| quay.io/ | 98580969b333 | openssl | 3.3.5-r0 | 3 |
| quay.io/ | d30a7c640c63 | openssl | 3.3.5-r0 | 3 |
| quay.io/ | e886b8d2b54b | openssl | 3.3.5-r0 | 3 |
| alpine/ | f0c1b7ca12f6 | openssl | 3.3.5-r0 | 2 |
| alpine/ | 062a01ad7a0e | openssl | 3.3.5-r0 | 2 |
| apache/ | a83cf1980609 | openssl | 3.3.5-r0 | 2 |
| apecloud/ | 94041b080510 | openssl | 3.5.4-r0 | 2 |
| aquasec/ | ea3e33bc3c4e | openssl | 3.3.5-r0 | 2 |
| curlimages/ | 4026b29997dc | openssl | 3.5.4-r0 | 2 |
| devopsfaith/ | f8bdaa8a1a43 | openssl | 3.3.5-r0 | 2 |
| excalidraw/ | f7ee194addd6 | openssl | 3.3.5-r0 | 2 |
| grafana/ | d8ea37798ccc | openssl | 3.3.5-r0 | 2 |
| grafana/ | f0200a9bff6d | openssl | 3.3.5-r0 | 2 |
| hanchuanchuan/ | b3c0dd26fb50 | openssl | 3.3.5-r0 | 2 |
| hazelcast/ | 5dd5d31c7a06 | openssl | 3.3.5-r0 | 2 |
| kiwigrid/ | 8c06e1ba643a | openssl | 3.5.4-r0 | 2 |
| library/ | 611107e29cce | openssl | 3.3.5-r0 | 2 |
| library/ | 148bb5411c18 | openssl | 3.3.5-r0 | 2 |
| lightninglabs/ | f86bbec4dfb3 | openssl | 3.3.5-r0 | 2 |
| linuxserver/ | 9932d6759112 | openssl | 3.3.5-r0 | 2 |
| mojaloop/ | d480a62103d6 | openssl | 3.3.5-r0 | 2 |
| mojaloop/ | 2635baf23298 | openssl | 3.3.5-r0 | 2 |
| mojaloop/ | 1e0d24d28512 | openssl | 3.5.4-r0 | 2 |
| mojaloop/ | 265102a049d6 | openssl | 3.3.5-r0 | 2 |
| natsio/ | 26c826662ac8 | openssl | 3.3.5-r0 | 2 |
| nginxinc/ | 65e3e85dbaed | openssl | 3.3.5-r0 | 2 |
| opea/ | 02d5674ca863 | openssl | 3.3.5-r0 | 2 |
| opencloudeu/ | f9634bb04905 | openssl | 3.3.5-r0 | 2 |
| oryd/ | fe2428f103a6 | openssl | 3.3.5-r0 | 2 |
| percona/ | 904458d04a18 | openssl | 3.3.5-r0 | 2 |
| rancher/ | 9bebefa0b908 | openssl | 3.3.5-r0 | 2 |
| rclone/ | 74c51b8817e5 | openssl | 3.3.5-r0 | 2 |
| sysnet4admin/ | c5bd3bb1b5a6 | openssl | 3.3.5-r0 | 2 |
| tzahi12345/ | 2f943d584711 | nodejs | no fix listed | 2 |
| uselagoon/ | 2c89ed939b8b | openssl | 3.3.5-r0 | 2 |
| ghcr.io/ | 4249e403225a | openssl | 3.5.4-r0 | 2 |