StackRadar

CVE-2021-21366

Medium

Advisory

Published 12 Mar 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

Misinterpretation of malicious XML input

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
xmldomnpm0.1.19, 0.1.27, 0.1.31, 0.3.0+1 more0.5.021
OSV records
GHSA-h6q6-9hqw-rwfv

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xmldom@0.1.31
0.5.0

Open the chart page →

2,938
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
xmldom@0.1.27
0.5.0

Open the chart page →

8,213
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
xmldom@0.1.31
0.5.0

Open the chart page →

5,946
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
kobotoolbox/kpi:2.022.24dbcacc01bccd4
xmldom@0.1.31
0.5.0

Open the chart page →

18,517
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xmldom@0.1.31
0.5.0

Open the chart page →

977
trifidappuio2.0.21 of 1See more

trifid appuio 2.0.2

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
zazuko/trifid:2.3.7054be137de70
xmldom@0.1.19
0.5.0

Open the chart page →

2,783
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
xmldom@0.1.31
0.5.0

Open the chart page →

4,251
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
xmldom@0.1.31
0.5.0

Open the chart page →

1,755
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
xmldom@0.3.0
0.5.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
xmldom@0.3.0
0.5.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
xmldom@0.3.0
0.5.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
xmldom@0.3.0
0.5.0

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
xmldom@0.1.27
0.5.0

Open the chart page →

8,213
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
xmldom@0.1.31
0.5.0

Open the chart page →

4,253
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
xmldom@0.1.27
0.5.0

Open the chart page →

7,232
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
xmldom@0.1.27
0.5.0

Open the chart page →

4,614
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
xmldom@0.3.0
0.5.0

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
xmldom@0.3.0
0.5.0

Open the chart page →

7,027
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
xmldom@0.1.27
0.5.0
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
xmldom@0.1.27
0.5.0

Open the chart page →

7,048
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
xmldom@0.4.0
0.5.0

Open the chart page →

27,465
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
xmldom@0.1.27
0.5.0

Open the chart page →

6,524
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
xmldom@0.1.19
0.5.0

Open the chart page →

5,215
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
xmldom@0.1.31
0.5.0

Open the chart page →

3,118
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
xmldom@0.1.19
0.5.0

Open the chart page →

3,638
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xmldom@0.1.31
0.5.0

Open the chart page →

2,638
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-21366.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
xmldom@0.1.31
0.5.0

Open the chart page →

3,118

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xmldom@0.1.31
0.5.0
3
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
xmldom@0.1.27
0.5.0
2
mesosphere/kommander:6.100.13917e82333a9
xmldom@0.3.0
0.5.0
2
migmartri/prerender:latest486aacfd5aa9
xmldom@0.1.27
0.5.0
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
xmldom@0.1.31
0.5.0
2
gristlabs/grist:0.7.96e71b1914a7e
xmldom@0.1.19
0.5.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
xmldom@0.1.31
0.5.0
1
linuxserver/codimd:latestb801bbcf6386
xmldom@0.4.0
0.5.0
1
phntom/codimd:2.4.31b9aafbb62e6
xmldom@0.1.27
0.5.0
1
requarks/wiki:canary-2.5.2438b5865a7386c
xmldom@0.1.31
0.5.0
1
roadiehq/community-backstage-image:latestef355bf5b639
xmldom@0.1.27
0.5.0
1
zazuko/trifid:2.3.7054be137de70
xmldom@0.1.19
0.5.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
xmldom@0.3.0
0.5.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
xmldom@0.3.0
0.5.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
xmldom@0.3.0
0.5.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
xmldom@0.3.0
0.5.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
xmldom@0.1.31
0.5.0
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
xmldom@0.1.31
0.5.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
xmldom@0.1.31
0.5.0
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
xmldom@0.1.27
0.5.0
1
quay.io/wekan/wekan:v5.65cb17600883a3
xmldom@0.1.19
0.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.