StackRadar

CVE-2016-3709

Medium

Advisory

Published 28 Jul 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
215
of 17,781 indexed, latest versions
Container images
201
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 215 of 17,781 indexed charts deploy, on 201 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.3+dfsg1-1ubuntu0.2, 2.9.3+dfsg1-1ubuntu0.5, 2.9.3+dfsg1-1ubuntu0.6, 2.9.3+dfsg1-1ubuntu0.7+9 more2.9.3+dfsg1-1ubuntu0.7+esm3, 2.9.4+dfsg1-6.1ubuntu1.7, 2.9.10+dfsg-5ubuntu0.20.04.4112
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+6 more0:2.9.7-15.el889
OSV records
RHSA-2022:7715UBUNTU-CVE-2016-3709
Also known as
RHSA-2023:4767, USN-5548-1

Charts affected

215 by stars
ChartLatestAffected imagesRadar Score
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.4

Open the chart page →

30,687
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8

Open the chart page →

11,554
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

6,671
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
libxml2@2.9.7-9.el8
0:2.9.7-15.el8

Open the chart page →

6,596
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

12,455
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8

Open the chart page →

4,960
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm3

Open the chart page →

15,330
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4

Open the chart page →

15,230
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-15.el8

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8

Open the chart page →

6,138
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2016-3709.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-15.el8

Open the chart page →

11,577

Container images carrying it

201 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm3
11
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
10
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm3
6
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm3
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm3
4
mastercloudapps/weatherservice:v1.23de859d29c116
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
4
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm3
3
quay.io/devtron/clair:4.3.675fb847ac045
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
libxml2@2.9.7-13.el8_6.2
0:2.9.7-15.el8
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
3
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm3
2
minio/operator:v4.3.754393e03f3b2
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
2
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libxml2@2.9.4+dfsg1-6.1ubuntu1
2.9.4+dfsg1-6.1ubuntu1.7
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm3
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
libxml2@2.9.7-12.el8_5
0:2.9.7-15.el8
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libxml2@2.9.7-9.el8
0:2.9.7-15.el8
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.7
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.4
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
libxml2@2.9.4+dfsg1-6.1ubuntu1.6
2.9.4+dfsg1-6.1ubuntu1.7
1
anchore/anchore-engine:v0.10.0bde9eedf639d
libxml2@2.9.7-9.el8
0:2.9.7-15.el8
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
libxml2@2.9.7-5.el8
0:2.9.7-15.el8
1
apache/camel-k:1.10.43bb13d14f64a
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
apachepulsar/pulsar:2.9.0d056c89b7131
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
apachepulsar/pulsar:2.8.2d538416d5afe
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
assistiot/identity-manager_kc:latest0df4b4fa899a
libxml2@2.9.7-13.el8_6.1
0:2.9.7-15.el8
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.4
1
bsgrigorov/helm-operator:latest45ab095f09c8
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
1
chetangautamm/repo:sipp.v3e7f7049e1544
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.4
1
cheyang/distributed-tf:1.6.046cc34755493
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm3
1
cloudve/janis-terminal:latestaf56e77ca587
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.7
1
cockroachdb/cockroach-operator:v2.1.0983312754620
libxml2@2.9.7-9.el8_4.2
0:2.9.7-15.el8
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
libxml2@2.9.7-13.el8
0:2.9.7-15.el8
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
libxml2@2.9.7-8.el8
0:2.9.7-15.el8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.