StackRadar

CVE-2016-3709

Medium

Advisory

Published 28 Jul 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
215
of 17,781 indexed, latest versions
Container images
201
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 215 of 17,781 indexed charts deploy, on 201 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.3+dfsg1-1ubuntu0.2, 2.9.3+dfsg1-1ubuntu0.5, 2.9.3+dfsg1-1ubuntu0.6, 2.9.3+dfsg1-1ubuntu0.7+9 more2.9.3+dfsg1-1ubuntu0.7+esm3, 2.9.4+dfsg1-6.1ubuntu1.7, 2.9.10+dfsg-5ubuntu0.20.04.4112
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+6 more0:2.9.7-15.el889
OSV records
RHSA-2022:7715UBUNTU-CVE-2016-3709
Also known as
RHSA-2023:4767, USN-5548-1

Charts affected

215 by stars
ChartLatestAffected imagesRadar Score
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.4

Open the chart page →

30,687
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8

Open the chart page →

11,554
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

6,671
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
libxml2@2.9.7-9.el8
0:2.9.7-15.el8

Open the chart page →

6,596
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

12,455
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8

Open the chart page →

4,960
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm3

Open the chart page →

15,330
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4

Open the chart page →

15,230
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-15.el8

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

6,138
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-15.el8

Open the chart page →

11,577

Container images carrying it

201 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.7
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.4
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.4
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.4
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
libxml2@2.9.7-9.el8
0:2.9.7-15.el8
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
libxml2@2.9.7-13.el8
0:2.9.7-15.el8
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
libxml2@2.9.7-13.el8
0:2.9.7-15.el8
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
libxml2@2.9.7-13.el8
0:2.9.7-15.el8
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libxml2@2.9.7-7.el8
0:2.9.7-15.el8
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
libxml2@2.9.7-12.el8_5
0:2.9.7-15.el8
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-15.el8
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
libxml2@2.9.7-5.el8
0:2.9.7-15.el8
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
1
quay.io/openshift/origin-cli:4.66722d5041b47
libxml2@2.9.7-7.el8
0:2.9.7-15.el8
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libxml2@2.9.7-7.el8
0:2.9.7-15.el8
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
libxml2@2.9.7-13.el8_6.4
0:2.9.7-15.el8
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm3
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
libxml2@2.9.7-9.el8
0:2.9.7-15.el8
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.