StackRadar

CVE-2026-25794

High

Advisory

Published 24 Feb 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
imagemagickdeb8:7.1.1.43+dfsg1-1, 8:7.1.1.43+dfsg1-1+deb13u2, 8:7.1.1.43+dfsg1-1+deb13u3, 8:7.1.1.43+dfsg1-1+deb13u5+1 more8:7.1.1.43+dfsg1-1+deb13u6, 8:7.1.2.3+dfsg1-1ubuntu0.112
OSV records
DEBIAN-CVE-2026-25794UBUNTU-CVE-2026-25794
Also known as
USN-8263-1

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
imagemagick@8:7.1.1.43+dfsg1-1+deb13u5
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

9,316
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

12,037
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
imagemagick@8:7.1.1.43+dfsg1-1+deb13u5
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

11,205
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
imagemagick@8:7.1.1.43+dfsg1-1+deb13u2
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

11,764
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
imagemagick@8:7.1.2.3+dfsg1-1
8:7.1.2.3+dfsg1-1ubuntu0.1

Open the chart page →

11,103
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

7,696
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
imagemagick@8:7.1.1.43+dfsg1-1
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

7,489
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

13,391
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

7,233
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

8,698
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

10,605
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
imagemagick@8:7.1.1.43+dfsg1-1+deb13u2
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

9,534
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-25794.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6

Open the chart page →

9,755

Container images carrying it

12 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6
2
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
imagemagick@8:7.1.1.43+dfsg1-1
8:7.1.1.43+dfsg1-1+deb13u6
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6
1
library/nextcloud:31.0.10-apacheb7faa1653c39
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6
1
library/python:3.9da5aee29682d
imagemagick@8:7.1.1.43+dfsg1-1+deb13u2
8:7.1.1.43+dfsg1-1+deb13u6
1
library/wordpress:php8.1-apachef73396626d2f
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6
1
photoprism/photoprism:251130db16ee6b1ba3
imagemagick@8:7.1.2.3+dfsg1-1
8:7.1.2.3+dfsg1-1ubuntu0.1
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
imagemagick@8:7.1.1.43+dfsg1-1+deb13u5
8:7.1.1.43+dfsg1-1+deb13u6
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
imagemagick@8:7.1.1.43+dfsg1-1+deb13u5
8:7.1.1.43+dfsg1-1+deb13u6
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
imagemagick@8:7.1.1.43+dfsg1-1+deb13u2
8:7.1.1.43+dfsg1-1+deb13u6
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.