CVE-2026-25541
MediumAdvisory
Published 3 Feb 2026In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.9
- base score, highest
- EPSS
- 0.006
- 45th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 9
- of 17,781 indexed, latest versions
- Container images
- 18
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
bytes has integer overflow in BytesMut::reserve
Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 18 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| bytescargo | 1.7.1, 1.8.0, 1.10.0, 1.10.1 | 1.11.1 | 17 |
| uvapk | 0.2.13-r0, 0.8.11-r0 | 0.9.29-r1 | 2 |
- OSV records
- CGA-c7j3-x5p6-h7ghGHSA-434x-w66g-qw3r
- Also known as
- CGA-gq2c-25x3-gmv2, RUSTSEC-2026-0007
Charts affected
9 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| openebsopenebsOfficialVerified publisher | 4.6.1 | 11 of 35See more | 23,894 |
| syftopenmined | 0.9.5 | 1 of 6See more | 17,245 |
| litellmlitellm-helm | 0.2.0 | 1 of 1See more | 4,292 |
| n3uronn3uronVerified publisher | 0.3.5 | 1 of 1See more | 1,879 |
| karakeepself-hosters-by-nightVerified publisher | 2.5.1 | 1 of 1See more | 5,213 |
| nostr-rs-relayk8s-chartsVerified publisher | 1.0.1 | 1 of 1See more | 3,354 |
| mayastormayastorVerified publisher | 2.12.1 | 11 of 31See more | 21,064 |
| matrix-stackrock8sVerified publisher | 0.8.1 | 1 of 7See more | 9,256 |
| karakeeprtomik-helm-chartsVerified publisher | 0.0.1 | 1 of 3See more | 5,338 |
Container images carrying it
18 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.