StackRadar

CVE-2022-2309

High

Advisory

Published 5 Jul 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
239
of 17,781 indexed, latest versions
Container images
247
deployed by those charts
Fix available
4 of 5
affected packages

lxml NULL Pointer Dereference allows attackers to cause a denial of service

Carried by container images the latest versions of 239 of 17,781 indexed charts deploy, on 247 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+3 more2.9.14-r199
libxml2deb2.9.10+dfsg-5, 2.9.10+dfsg-5ubuntu0.20.04.1, 2.9.10+dfsg-5ubuntu0.20.04.2, 2.9.10+dfsg-5ubuntu0.20.04.3+4 more2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.3~deb12u190
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+16 more4.9.162
lxmldeb4.8.0-1build1no fix listed1
libxml2rpm2.9.7-lp151.5.3.12.10.1-1.12
OSV records
ALPINE-CVE-2022-2309DEBIAN-CVE-2022-2309GHSA-wrxv-2j5q-m38wUBUNTU-CVE-2022-2309openSUSE-SU-2024:12290-1
Also known as
PYSEC-2022-230, USN-5760-1

Charts affected

239 by stars
ChartLatestAffected imagesRadar Score
rook-cephrookOfficialVerified publisher1.20.71 of 2See more

rook-ceph rook 1.20.7

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
rook/ceph:v1.20.72f970c425617
lxml@4.6.5
4.9.1

Open the chart page →

1,447
ceph-csi-cephfsceph-csiOfficialVerified publisher3.17.11 of 6See more

ceph-csi-cephfs ceph-csi 3.17.1

1 of the 6 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
lxml@4.6.5
4.9.1

Open the chart page →

4,061
ceph-csi-rbdceph-csiOfficialVerified publisher3.17.11 of 6See more

ceph-csi-rbd ceph-csi 3.17.1

1 of the 6 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
lxml@4.6.5
4.9.1

Open the chart page →

4,061
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

32,259
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

16,251
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

33,725
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
libxml2@2.9.12-r1
lxml@4.8.0
2.9.14-r1
4.9.1

Open the chart page →

7,705
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

7,880
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

18,509
loki-simple-scalablegrafana1.8.111 of 3See more

loki-simple-scalable grafana 1.8.11

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.19-alpine084242d8028c
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

6,470
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

11,405
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
lxml@3.2.1
4.9.1

Open the chart page →

10,732
zabbix-serveraekondratievVerified publisher1.0.62 of 4See more

zabbix-server aekondratiev 1.0.6

2 of the 4 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

30,668
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

52,919
taigarc-helm-charts0.1.02 of 7See more

taiga rc-helm-charts 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
taigaio/taiga-back:6.4.29f97323cc150
lxml@4.6.3
4.9.1
taigaio/taiga-front:6.4.24d367b1e1250
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

7,255
matrixzekker6Verified publisher3.30.01 of 4See more

matrix zekker6 3.30.0

1 of the 4 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
vectorim/riot-web:v1.7.3384bb5af00b5d
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

5,557
eshoponabpabp-charts1.0.01 of 15See more

eshoponabp abp-charts 1.0.0

1 of the 15 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/volosoft/eshoponabp/app-web:1.0.0056bb4271626
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

19,799
cardano-kstackcardano-kstackVerified publisher1.0.41 of 3See more

cardano-kstack cardano-kstack 1.0.4

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
library/postgres:14.1-alpine578ca5c8452c
libxml2@2.9.12-r2
2.9.14-r1

Open the chart page →

1,118
ecr-proxyevryfs-ossVerified publisher0.2.91 of 1See more

ecr-proxy evryfs-oss 0.2.9

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
esailors/aws-ecr-http-proxy:1.5.15608ae045fa7
libxml2@2.9.13-r0
2.9.14-r1

Open the chart page →

1,523
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
libxml2@2.9.12-r2
2.9.14-r1

Open the chart page →

3,030
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

10,598
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
lxml@4.8.0
4.9.1

Open the chart page →

7,579
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

13,950
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

9,627
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

10,628
rocketmqgin1.1.01 of 2See more

rocketmq gin 1.1.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
apache/rocketmq:4.9.35ac2a4e0f627
lxml@3.2.1
4.9.1

Open the chart page →

9,154
dynamodbkeyporttech0.1.271 of 2See more

dynamodb keyporttech 0.1.27

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.12.08414d80019b0
lxml@3.2.1
4.9.1

Open the chart page →

1,304
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
lxml@4.8.0
4.9.1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
lxml@4.8.0
4.9.1

Open the chart page →

18,517
laravelrenoki-co1.0.01 of 2See more

laravel renoki-co 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

6,931
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

24,488
wharf-helmwharf-helmOfficialVerified publisher3.2.61 of 5See more

wharf-helm wharf-helm 3.2.6

1 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-web:v1.6.2dc5d1ed91c26
libxml2@2.9.13-r0
2.9.14-r1

Open the chart page →

10,032
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

13,635
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

4,995
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

13,145
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
johnblack77/clustereye:latest-amd64bb53ceb8442e
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

4,855
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

9,724
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
libxml2@2.9.13-r0
2.9.14-r1

Open the chart page →

7,303
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/data-fair/simple-directory:438a4f32fad82
libxml2@2.9.13-r0
2.9.14-r1

Open the chart page →

38,346
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
lxml@4.5.0
4.9.1

Open the chart page →

4,568
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
lxml@4.5.2
4.9.1

Open the chart page →

7,984
matomodigitalist-open-cloud-matomo12.0.201 of 3See more

matomo digitalist-open-cloud-matomo 12.0.20

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
digitalist/nginx:1.21.6eec27ad73eaa
libxml2@2.9.12-r2
2.9.14-r1

Open the chart page →

3,539
spa-demodniel0.7.31 of 1See more

spa-demo dniel 0.7.3

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
dniel/forwardauth-spademo:masterd3e38df449a2
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

1,322
dominodominoVerified publisher0.1.111 of 3See more

domino domino 0.1.11

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/tauffer-consulting/domino-frontend:latesta923b86a0903
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

8,823
vidcheckfactlyVerified publisher0.5.21 of 2See more

vidcheck factly 0.5.2

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
factly/vidcheck-studio:0.12.024be158ec7d3
libxml2@2.9.12-r0
2.9.14-r1

Open the chart page →

3,617
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
library/nginx:1.19-alpine07ab71a2c8e4
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

8,496
appdaemongeek-cookbookVerified publisher8.4.21 of 1See more

appdaemon geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
acockburn/appdaemon:4.0.83a93281d7e94
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

3,461
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
lxml@4.8.0
2.9.10+dfsg-5ubuntu0.20.04.5
4.9.1

Open the chart page →

17,377
games-on-whalesgeek-cookbookVerified publisher1.8.23 of 7See more

games-on-whales geek-cookbook 1.8.2

3 of the 7 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

35,305
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

15,653
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

11,558

Container images carrying it

247 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
stashapp/stash:latest24dbd7607174
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
statcan/ckan:2.93921305425b8
libxml2@2.9.10+dfsg-5
lxml@4.4.2
2.9.10+dfsg-5ubuntu0.20.04.5
4.9.1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
lxml@4.9.0
4.9.1
1
swaggerapi/swagger-ui:v4.12.00d7088d47928
libxml2@2.9.14-r0
2.9.14-r1
1
t3nde/matomo:4.3.1-fpm-alpine329ce194393a
libxml2@2.9.12-r1
2.9.14-r1
1
taemon1337/ingress-dashboard:0.0.10e8f5096c66bb
libxml2@2.9.12-r2
2.9.14-r1
1
taigaio/taiga-back:6.4.29f97323cc150
lxml@4.6.3
4.9.1
1
taigaio/taiga-front:6.4.24d367b1e1250
libxml2@2.9.10-r6
2.9.14-r1
1
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r1
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
libxml2@2.9.10-r6
2.9.14-r1
1
trafex/php-nginx:2.4.07282edfca2bf
libxml2@2.9.12-r1
2.9.14-r1
1
trafex/php-nginx:2.2.0ee0b7c6cce07
libxml2@2.9.12-r1
2.9.14-r1
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
libxml2@2.9.10-r6
2.9.14-r1
1
tvanro/prerender-alpine:6.4.06909015f0328
libxml2@2.9.12-r1
2.9.14-r1
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
4.9.1
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
lxml@4.7.1
4.9.1
1
vectorim/riot-web:v1.7.3384bb5af00b5d
libxml2@2.9.12-r1
2.9.14-r1
1
voltha/voltha-cli:1.6.0c4e41e92f046
lxml@3.6.4
4.9.1
1
voltha/voltha-netconf:1.6.037f80524c207
lxml@3.6.4
4.9.1
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
lxml@3.6.4
4.9.1
1
voltha/voltha-tester:1.7.0655c3048a602
lxml@3.6.4
4.9.1
1
voltha/voltha-voltha:1.6.0ff596b62de59
lxml@3.6.4
4.9.1
1
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
4.9.1
1
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
1
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
1
yuzutech/kroki-bpmn:0.16.0bd629239a64e
libxml2@2.9.12-r1
2.9.14-r1
1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
libxml2@2.9.12-r1
2.9.14-r1
1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
libxml2@2.9.12-r1
2.9.14-r1
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
libxml2@2.9.10-r6
2.9.14-r1
1
gcr.io/kubecost1/frontend:prod-1.81.096dfb19838b8
libxml2@2.9.10-r6
2.9.14-r1
1
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.14-r1
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
libxml2@2.9.12-r2
2.9.14-r1
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
libxml2@2.9.14-r0
2.9.14-r1
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
lxml@4.6.4
4.9.1
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.