StackRadar

CVE-2020-7595

High

Advisory

Published 21 Jan 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.078
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
52
of 17,781 indexed, latest versions
Container images
34
deployed by those charts
Fix available
2 of 2
affected packages

libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation

Carried by container images the latest versions of 52 of 17,781 indexed charts deploy, on 34 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+4 more2.9.1+dfsg1-3ubuntu4.13+esm1, 2.9.3+dfsg1-1ubuntu0.7, 2.9.4+dfsg1-6.1ubuntu1.333
nokogirigem1.8.21.10.81
OSV records
GHSA-7553-jr98-vx47UBUNTU-CVE-2020-7595
Also known as
USN-4274-1

Charts affected

52 by stars
ChartLatestAffected imagesRadar Score
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-7595.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7

Open the chart page →

25,769
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-7595.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7

Open the chart page →

15,330

Container images carrying it

34 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
11
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
6
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
4
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
3
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
2
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libxml2@2.9.4+dfsg1-6.1ubuntu1
2.9.4+dfsg1-6.1ubuntu1.3
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
2
wurstmeister/zookeeper:latest7a7fd44a7210
libxml2@2.9.1+dfsg1-3ubuntu4.3
2.9.1+dfsg1-3ubuntu4.13+esm1
2
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
nokogiri@1.8.2
1.10.8
1
cheyang/distributed-tf:1.6.046cc34755493
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
1
galaxy/galaxy-init:v18.010267bad550e6
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm1
1
galaxy/galaxy-stable:v18.018e577a626dfd
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm1
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
1
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.3
1
kennethreitz/httpbin:latest599fe5e50731
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.3
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
1
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.3
1
omecproject/onos-progran:1.0.05715e5648aa0
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
1
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
libxml2@2.9.3+dfsg1-1ubuntu0.2
2.9.3+dfsg1-1ubuntu0.7
1
opendatacube/pipelines:wofs-1.225d810e8504b8
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.3
1
opendatacube/restcube:latest91870111837c
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.3
1
opendatacube/wms:latest1b90cdf68831
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.3
1
opsmx11/issuegen:v2.1.05c50ca123d88
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm1
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
1
resouer/redis-slave:v2e2f198b49ba7
libxml2@2.9.1+dfsg1-3ubuntu4.4
2.9.1+dfsg1-3ubuntu4.13+esm1
1
scrapinghub/splash:3.4.1a5f89bc84606
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.3
1
sismics/docs:v1.10f4b0ef019cf1
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.3
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.