StackRadar

CVE-2021-3541

Medium

Advisory

Published 18 May 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
286
of 17,781 indexed, latest versions
Container images
194
deployed by those charts
Fix available
3 of 3
affected packages

libxml2 - security update

Carried by container images the latest versions of 286 of 17,781 indexed charts deploy, on 194 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.9.10-r1, 2.9.10-r2, 2.9.10-r3, 2.9.10-r4+3 more2.9.11-r0, 2.9.12-r0104
libxml2deb2.9.4+dfsg1-2.2, 2.9.4+dfsg1-2.2+deb9u1, 2.9.4+dfsg1-2.2+deb9u2, 2.9.4+dfsg1-2.2+deb9u3+2 more2.9.4+dfsg1-2.2+deb9u5, 2.9.10+dfsg-5ubuntu0.20.04.189
libxml2rpm2.9.7-3.25.12.9.7-3.37.11
OSV records
ALPINE-CVE-2021-3541UBUNTU-CVE-2021-3541DLA-2669-1SUSE-SU-2021:1917-1
Also known as
USN-4991-1

Charts affected

286 by stars
ChartLatestAffected imagesRadar Score
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

25,769
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

25,769
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

11,841
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.11-r0

Open the chart page →

16,506
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

3,044
pachydermstatcan0.5.12 of 4See more

pachyderm statcan 0.5.1

2 of the 4 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
pachyderm/dash:1.9.094e9a281e5a4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
pachyderm/grpc-proxy:0.4.92b27f41d4d02
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

4,967
helm-nginxstksrshelm0.1.01 of 1See more

helm-nginx stksrshelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
sample-chartsysbee0.1.11 of 1See more

sample-chart sysbee 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
pi-holet3n1.0.01 of 1See more

pi-hole t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
pihole/pihole:v4.48c172c4cf344
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

1,373
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,480
tama-charttama-chart0.1.11 of 1See more

tama-chart tama-chart 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
libxml2@2.9.10-r3
2.9.12-r0

Open the chart page →

3,993
giropops-senhas-devtechpreta0.1.01 of 1See more

giropops-senhas-dev techpreta 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
giropops-senhas-stgtechpreta0.1.01 of 1See more

giropops-senhas-stg techpreta 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
nginxtest-nginx0.1.01 of 1See more

nginx test-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
nginx-chartstest-nginx-charts0.1.01 of 1See more

nginx-charts test-nginx-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
myapptestrepo0.1.01 of 1See more

myapp testrepo 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
hello-worldthuvu33330.1.01 of 1See more

hello-world thuvu3333 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.11-r0

Open the chart page →

6,881
deis-workflowtohlejezkouska0.1.01 of 1See more

deis-workflow tohlejezkouska 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
mojeaplikacetohlejezkouska0.1.01 of 1See more

mojeaplikace tohlejezkouska 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
helmexampletomsuehelmexample0.1.01 of 1See more

helmexample tomsuehelmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,510
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,429
nginx-file-browserwarjiang0.1.21 of 1See more

nginx-file-browser warjiang 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
libxml2@2.9.4+dfsg1-2.2+deb9u4
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

2,559
nginxwiremindVerified publisher2.1.11 of 1See more

nginx wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.17-alpine763e7f0188e3
libxml2@2.9.10-r2
2.9.12-r0

Open the chart page →

966
upsourcexykongVerified publisher0.1.11 of 1See more

upsource xykong 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
helmexampleycztest0.1.01 of 1See more

helmexample ycztest 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
mychartyi-test-chart0.1.01 of 1See more

mychart yi-test-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702

Container images carrying it

194 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
conduction/kvk-nginx:devcf163d2b95b5
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/kvk-php:dev8f177f9f8a7b
libxml2@2.9.10-r4
2.9.12-r0
1
conduction/pan-nginx:devaf3e9f551ad1
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/pan-php:dev24f03c57568f
libxml2@2.9.10-r4
2.9.12-r0
1
confluentinc/cp-kafkacat:4.1.25f990b0f43c9
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.11-r0
1
douz/helpdesk-frontend:latestfa6a57de2b72
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
libxml2@2.9.4+dfsg1-2.2+deb9u3
2.9.4+dfsg1-2.2+deb9u5
1
erlangsolutions/mongoose-push:2.1.0ad603bcb0b03
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
gitea/gitea:1.12.485416d6f65fe
libxml2@2.9.10-r3
2.9.12-r0
1
gitea/gitea:1.13.0d5ab14cd29af
libxml2@2.9.10-r5
2.9.12-r0
1
gmelillo/bind9:latesteeb2f9371b71
libxml2@2.9.10-r5
2.9.12-r0
1
gmelillo/nginx:2021-01-091b30f79cf7ea
libxml2@2.9.10-r5
2.9.12-r0
1
golenski/fibonacci-front:2.0.048cfd60b8413
libxml2@2.9.10-r4
2.9.12-r0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
libxml2@2.9.10-r4
2.9.12-r0
1
guacamole/guacamole:1.1.0333a7f40c145
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.1
1
hmdmph/redis-pod-labeler:1.0.0-alpine7f1381fe0f3b
libxml2@2.9.10-r4
2.9.12-r0
1
i4trust/pdc-portal:2.0.03e77858e1219
libxml2@2.9.4+dfsg1-2.2+deb9u3
2.9.4+dfsg1-2.2+deb9u5
1
ibmcom/ibm-storage-enabler-for-containers-db:2.1.09a766604a73b
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
jenkinsci/jenkins:2.67a1f33f004659
libxml2@2.9.4+dfsg1-2.2+deb9u1
2.9.4+dfsg1-2.2+deb9u5
1
johnblack77/clustereye:latest-amd64bb53ceb8442e
libxml2@2.9.10-r6
2.9.11-r0
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.1
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.1
1
kanboard/kanboard:v1.2.200b6d33dbbc16
libxml2@2.9.10-r7
2.9.11-r0
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
libxml2@2.9.10-r5
2.9.12-r0
1
koumoul/capture:17108d47be3b2
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
leeyoongti/first-app:1.0.021d66cb76352
libxml2@2.9.4+dfsg1-2.2+deb9u4
2.9.4+dfsg1-2.2+deb9u5
1
library/adminer:4.7143ec8cc2f3a
libxml2@2.9.10-r6
2.9.11-r0
1
library/adminer:4.7.5-standalonef42d935fec5a
libxml2@2.9.10-r1
2.9.12-r0
1
library/cassandra:2.1.20cb079c0d7a57
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
library/elasticsearch:2.4.641ed3a1a16b6
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
library/nginx:1.19.0-alpine17ba9c1ca3db
libxml2@2.9.10-r3
2.9.12-r0
1
library/nginx:1.19.3-alpine5aa44b407756
libxml2@2.9.10-r5
2.9.12-r0
1
library/nginx:1.17-alpine763e7f0188e3
libxml2@2.9.10-r2
2.9.12-r0
1
library/nginx:1.14.2f7988fb6c02e
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
library/postgres:9.6.182f75145ad077
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
library/postgres:9.575ebf479151a
libxml2@2.9.4+dfsg1-2.2+deb9u4
2.9.4+dfsg1-2.2+deb9u5
1
library/postgres:12.3-alpine7693f2082c68
libxml2@2.9.10-r4
2.9.12-r0
1
library/postgres:10.49625c2fb3498
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
library/postgres:11.10bb024e990f4f
libxml2@2.9.4+dfsg1-2.2+deb9u3
2.9.4+dfsg1-2.2+deb9u5
1
library/sonarqube:6.7.6-community0ae5169e3d0f
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
logiqai/toolbox:2.0.155a574ec5b64
libxml2@2.9.10-r2
2.9.12-r0
1
longhornio/longhorn-ui:v1.1.165560eabe3ee
libxml2@2.9.10-r6
2.9.11-r0
1
lsstsqre/lsp-postgres:latest54283318b16b
libxml2@2.9.10-r4
2.9.12-r0
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.