StackRadar

CVE-2019-5815

High

Advisory

Published 11 Dec 2019In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
5
deployed by those charts
Fix available
2 of 2
affected packages

Nokogiri implementation of libxslt vulnerable to heap corruption

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
libxsltdeb1.1.28-2.1ubuntu0.3, 1.1.28-2ubuntu0.1, 1.1.29-5ubuntu0.21.1.28-2.1ubuntu0.3+esm1, 1.1.28-2ubuntu0.2+esm2, 1.1.29-5ubuntu0.34
nokogirigem1.8.21.10.51
OSV records
GHSA-vmfx-gcfq-wvm2UBUNTU-CVE-2019-5815
Also known as
USN-5575-1, USN-5575-2

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2019-5815.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
libxslt@1.1.29-5ubuntu0.2
1.1.29-5ubuntu0.3

Open the chart page →

22,891
honeywell-exporterbryanalves0.1.11 of 1See more

honeywell-exporter bryanalves 0.1.1

1 of the 1 container images this version deploys carry CVE-2019-5815.

Container imageDigestPackageFixed in
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
nokogiri@1.8.2
1.10.5

Open the chart page →

5,437
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2019-5815.

Container imageDigestPackageFixed in
galaxy/galaxy-stable:v18.018e577a626dfd
libxslt@1.1.28-2ubuntu0.1
1.1.28-2ubuntu0.2+esm2

Open the chart page →

70,895
plexfydrah-charts2.2.01 of 1See more

plex fydrah-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2019-5815.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
libxslt@1.1.28-2.1ubuntu0.3
1.1.28-2.1ubuntu0.3+esm1

Open the chart page →

8,965
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2019-5815.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
libxslt@1.1.29-5ubuntu0.2
1.1.29-5ubuntu0.3

Open the chart page →

27,633

Container images carrying it

5 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
nokogiri@1.8.2
1.10.5
1
galaxy/galaxy-stable:v18.018e577a626dfd
libxslt@1.1.28-2ubuntu0.1
1.1.28-2ubuntu0.2+esm2
1
gethue/hue:4.10.05702b2c37ff9
libxslt@1.1.29-5ubuntu0.2
1.1.29-5ubuntu0.3
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
libxslt@1.1.28-2.1ubuntu0.3
1.1.28-2.1ubuntu0.3+esm1
1
scrapinghub/splash:3.4.1a5f89bc84606
libxslt@1.1.29-5ubuntu0.2
1.1.29-5ubuntu0.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.