StackRadar

CVE-2021-3541

Medium

Advisory

Published 18 May 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
286
of 17,781 indexed, latest versions
Container images
194
deployed by those charts
Fix available
3 of 3
affected packages

libxml2 - security update

Carried by container images the latest versions of 286 of 17,781 indexed charts deploy, on 194 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.9.10-r1, 2.9.10-r2, 2.9.10-r3, 2.9.10-r4+3 more2.9.11-r0, 2.9.12-r0104
libxml2deb2.9.4+dfsg1-2.2, 2.9.4+dfsg1-2.2+deb9u1, 2.9.4+dfsg1-2.2+deb9u2, 2.9.4+dfsg1-2.2+deb9u3+2 more2.9.4+dfsg1-2.2+deb9u5, 2.9.10+dfsg-5ubuntu0.20.04.189
libxml2rpm2.9.7-3.25.12.9.7-3.37.11
OSV records
ALPINE-CVE-2021-3541UBUNTU-CVE-2021-3541DLA-2669-1SUSE-SU-2021:1917-1
Also known as
USN-4991-1

Charts affected

286 by stars
ChartLatestAffected imagesRadar Score
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

25,769
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

25,769
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

11,841
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.11-r0

Open the chart page →

16,506
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
libxml2@2.9.10-r5
2.9.12-r0

Open the chart page →

3,044
pachydermstatcan0.5.12 of 4See more

pachyderm statcan 0.5.1

2 of the 4 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
pachyderm/dash:1.9.094e9a281e5a4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
pachyderm/grpc-proxy:0.4.92b27f41d4d02
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

4,967
helm-nginxstksrshelm0.1.01 of 1See more

helm-nginx stksrshelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
sample-chartsysbee0.1.11 of 1See more

sample-chart sysbee 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
pi-holet3n1.0.01 of 1See more

pi-hole t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
pihole/pihole:v4.48c172c4cf344
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

1,373
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,480
tama-charttama-chart0.1.11 of 1See more

tama-chart tama-chart 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
libxml2@2.9.10-r3
2.9.12-r0

Open the chart page →

3,993
giropops-senhas-devtechpreta0.1.01 of 1See more

giropops-senhas-dev techpreta 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
giropops-senhas-stgtechpreta0.1.01 of 1See more

giropops-senhas-stg techpreta 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
nginxtest-nginx0.1.01 of 1See more

nginx test-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
nginx-chartstest-nginx-charts0.1.01 of 1See more

nginx-charts test-nginx-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
myapptestrepo0.1.01 of 1See more

myapp testrepo 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
hello-worldthuvu33330.1.01 of 1See more

hello-world thuvu3333 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.11-r0

Open the chart page →

6,881
deis-workflowtohlejezkouska0.1.01 of 1See more

deis-workflow tohlejezkouska 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
mojeaplikacetohlejezkouska0.1.01 of 1See more

mojeaplikace tohlejezkouska 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
helmexampletomsuehelmexample0.1.01 of 1See more

helmexample tomsuehelmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,510
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
libxml2@2.9.10-r4
2.9.12-r0

Open the chart page →

7,429
nginx-file-browserwarjiang0.1.21 of 1See more

nginx-file-browser warjiang 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
libxml2@2.9.4+dfsg1-2.2+deb9u4
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

2,559
nginxwiremindVerified publisher2.1.11 of 1See more

nginx wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.17-alpine763e7f0188e3
libxml2@2.9.10-r2
2.9.12-r0

Open the chart page →

966
upsourcexykongVerified publisher0.1.11 of 1See more

upsource xykong 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
helmexampleycztest0.1.01 of 1See more

helmexample ycztest 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
mychartyi-test-chart0.1.01 of 1See more

mychart yi-test-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3541.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5

Open the chart page →

702

Container images carrying it

194 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/nginx:1.16.03e373fd5b8d4
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
86
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.12-r0
7
oscarsotosanchez/server:v1.06e2e1279126b
libxml2@2.9.4+dfsg1-2.2+deb9u3
2.9.4+dfsg1-2.2+deb9u5
4
osixia/phpldapadmin:0.7.11ab629698ae0
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
4
buddy/repman:1.4.0097c897f8b54
libxml2@2.9.10-r3
2.9.12-r0
3
cankush625/webpage:latest9479f73bab03
libxml2@2.9.10-r2
2.9.12-r0
3
library/nginx:1.18.0-alpine:1.18-alpine93baf2ec1bfe
libxml2@2.9.10-r4
2.9.12-r0
3
nginxinc/nginx-unprivileged:1.19-alpine084242d8028c
libxml2@2.9.10-r6
2.9.11-r0
3
quay.io/devtron/postgres:11.3ef035ac10498
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
3
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
2
library/nginx:1.19-alpine07ab71a2c8e4
libxml2@2.9.10-r6
2.9.11-r0
2
library/nginx:1.13.12b1d09e971889
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
2
library/postgres:11.5b3770d9c4ef1
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
2
library/postgres:12.4-alpinee27594243877
libxml2@2.9.10-r5
2.9.12-r0
2
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
2
neilpeterson/azure-vote-front:v384062718347c
libxml2@2.9.4+dfsg1-2.2+deb9u1
2.9.4+dfsg1-2.2+deb9u5
2
osixia/openldap:1.2.4d212a12aa728
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
2
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
libxml2@2.9.10-r5
2.9.12-r0
2
statsd/statsd:v0.8.6dab129e74c25
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
2
acockburn/appdaemon:4.0.83a93281d7e94
libxml2@2.9.10-r6
2.9.11-r0
1
adferrand/backuppc:4.4.06fea97b02758
libxml2@2.9.10-r4
2.9.12-r0
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.1
1
ajanvier/polr:2.3.091ac61b88c85
libxml2@2.9.10-r6
2.9.11-r0
1
alphayax/phpmemcachedadmin:latestc284977f027a
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
amancevice/superset:0.28.1c8c04bfe3d66
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
blockstack/envsubst:latestd64d7430289a
libxml2@2.9.10-r6
2.9.11-r0
1
brannondorsey/alpine-xmrig:v5.8.242d01bbe307f
libxml2@2.9.10-r2
2.9.12-r0
1
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
bryanalves/smart_exporter:0.2af47dfbb9413
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
camptocamp/pghoard:10bff736b15623
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
chetangautamm/repo:sipp.v3e7f7049e1544
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.1
1
codaprotocol/buildkite-exporter:0.2.137c68e67a401
libxml2@2.9.4+dfsg1-2.2+deb9u3
2.9.4+dfsg1-2.2+deb9u5
1
codaprotocol/coda-user-agent:0.1.54ba4dd3a041f
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/agendaservice-nginx:lateste1c176458aaf
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/agendaservice-php:latest9cfeeb6c7c20
libxml2@2.9.10-r4
2.9.12-r0
1
conduction/balance-registration-nginx:dev9e24264ea8f3
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/balance-registration-php:devc36094a41369
libxml2@2.9.10-r4
2.9.12-r0
1
conduction/betaalservice-nginx:latestd3577ddd5c67
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/betaalservice-php:latestece1ab544c57
libxml2@2.9.10-r4
2.9.12-r0
1
conduction/cgrc-nginx:devd8e23f10e882
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/cgrc-php:dev25415534d245
libxml2@2.9.10-r3
2.9.12-r0
1
conduction/checkin-component-nginx:dev583d2cd8476c
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/checkin-component-php:dev3423845692c1
libxml2@2.9.10-r4
2.9.12-r0
1
conduction/conduction-ui-nginx:devd9b38e234de9
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/conduction-ui-php:dev2744565516e8
libxml2@2.9.10-r4
2.9.12-r0
1
conduction/contactmoment-component-nginx:dev353dc46303ac
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
libxml2@2.9.10-r4
2.9.12-r0
1
conduction/docparser-nginx:dev08524d8327b8
libxml2@2.9.4+dfsg1-2.2+deb9u2
2.9.4+dfsg1-2.2+deb9u5
1
conduction/docparser-php:devb6f95c8ead7d
libxml2@2.9.10-r4
2.9.12-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.