StackRadar

CVE-2025-9301

Medium

Advisory

Published 21 Aug 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
cmakedeb3.5.1-1ubuntu3, 3.16.3-1ubuntu1, 3.16.3-1ubuntu1.20.04.1, 3.22.1-1ubuntu1.22.04.2+3 moreno fix listed13
OSV records
DEBIAN-CVE-2025-9301UBUNTU-CVE-2025-9301

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
cmake@3.28.3-1build7
no fix listed

Open the chart page →

19,391
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
cmake@3.28.3-1build7
no fix listed

Open the chart page →

22,002
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
cmake@3.16.3-1ubuntu1.20.04.1
no fix listed

Open the chart page →

11,582
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
cmake@3.31.6-2
no fix listed

Open the chart page →

5,880
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
cmake@3.25.1-1
no fix listed

Open the chart page →

11,458
tdarrgeek-cookbookVerified publisher4.6.21 of 2See more

tdarr geek-cookbook 4.6.2

1 of the 2 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
cmake@3.16.3-1ubuntu1
no fix listed

Open the chart page →

31,000
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
cmake@3.25.1-1
no fix listed

Open the chart page →

7,740
tdarrvhdirkVerified publisher5.0.51 of 2See more

tdarr vhdirk 5.0.5

1 of the 2 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
cmake@3.16.3-1ubuntu1
no fix listed

Open the chart page →

26,657
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
cmake@3.16.3-1ubuntu1
no fix listed

Open the chart page →

25,443
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
cmake@3.5.1-1ubuntu3
no fix listed

Open the chart page →

33,963
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
cmake@3.28.3-1build7
no fix listed

Open the chart page →

19,224
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
cmake@3.31.6-2
no fix listed

Open the chart page →

66,266
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-9301.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
cmake@3.22.1-1ubuntu1.22.04.2
no fix listed

Open the chart page →

7,849

Container images carrying it

13 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dongjiang1989/lxcfs:v6.0.34bf9ae391948
cmake@3.16.3-1ubuntu1.20.04.1
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
cmake@3.25.1-1
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
cmake@3.16.3-1ubuntu1
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
cmake@3.5.1-1ubuntu3
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
cmake@3.28.3-1build7
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
cmake@3.28.3-1build7
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
cmake@3.28.3-1build7
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
cmake@3.31.6-2
no fix listed
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
cmake@3.31.6-2
no fix listed
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
cmake@3.22.1-1ubuntu1.22.04.2
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
cmake@3.25.1-1
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
cmake@3.16.3-1ubuntu1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
cmake@3.16.3-1ubuntu1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.