StackRadar

CVE-2014-3146

Medium

Advisory

Published 14 May 2014In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.063
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

lxml Cross-site Scripting Via Control Characters

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.13.3.511
OSV records
GHSA-57qw-cc2g-pv5p
Also known as
PYSEC-2014-9

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
lxml@3.2.1
3.3.5

Open the chart page →

10,732
rocketmqgin1.1.01 of 2See more

rocketmq gin 1.1.0

1 of the 2 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
apache/rocketmq:4.9.35ac2a4e0f627
lxml@3.2.1
3.3.5

Open the chart page →

9,154
dynamodbkeyporttech0.1.271 of 2See more

dynamodb keyporttech 0.1.27

1 of the 2 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.12.08414d80019b0
lxml@3.2.1
3.3.5

Open the chart page →

1,304
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
3.3.5

Open the chart page →

3,978
heronheron0.20.5-incubating1 of 2See more

heron heron 0.20.5-incubating

1 of the 2 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
apache/bookkeeper:4.14.5a7d9970c148f
lxml@3.2.1
3.3.5

Open the chart page →

1,449
ibm-business-automation-insights-devibm-charts3.2.03 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

3 of the 6 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
3.3.5
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
3.3.5
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
3.3.5

Open the chart page →

39,349
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
lxml@3.2.1
3.3.5

Open the chart page →

444
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
lxml@3.2.1
3.3.5

Open the chart page →

4,153
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
3.3.5

Open the chart page →

3,978
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2014-3146.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
lxml@3.2.1
3.3.5

Open the chart page →

4,240

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
3.3.5
2
amazon/dynamodb-local:1.20.01ed00881c937
lxml@3.2.1
3.3.5
1
amazon/dynamodb-local:1.12.08414d80019b0
lxml@3.2.1
3.3.5
1
apache/bookkeeper:4.14.5a7d9970c148f
lxml@3.2.1
3.3.5
1
apache/hadoop:3af361b20bec0
lxml@3.2.1
3.3.5
1
apache/rocketmq:4.9.35ac2a4e0f627
lxml@3.2.1
3.3.5
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
3.3.5
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
3.3.5
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
3.3.5
1
microcks/microcks:0.8.0e3a3e0c67b09
lxml@3.2.1
3.3.5
1
nacos/nacos-server:1.4.1fe6e5688cdf3
lxml@3.2.1
3.3.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.