StackRadar

CVE-2023-39615

Medium

Advisory

Published 29 Aug 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
374
of 17,781 indexed, latest versions
Container images
406
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 374 of 17,781 indexed charts deploy, on 406 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.14+dfsg-1.2, 2.9.14+dfsg-1.3~deb12u12.9.14+dfsg-1.3~deb12u2224
libxml2rpm2.9.7-3.22.1, 2.9.7-3.25.1, 2.9.7-5.el8, 2.9.7-7.el8+16 more0:2.9.7-16.el8_8.2, 0:2.9.7-18.el8_9, 0:2.9.13-5.el9_3, 2.9.7-150000.3.60.1+1 more182
OSV records
DEBIAN-CVE-2023-39615RHSA-2023:7544RHSA-2023:7747RHSA-2024:0119RLSA-2024:0119openSUSE-SU-2024:13192-1SUSE-SU-2023:3698-1

Charts affected

374 by stars
ChartLatestAffected imagesRadar Score
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

9,616
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

5,350
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

3,958
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_9

Open the chart page →

12,455
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

17,323
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

8,607
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
libxml2@2.9.7-13.el8_6.1
0:2.9.7-18.el8_9

Open the chart page →

4,960
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

45,239
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

14,358
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

10,795
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

10,001
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_9

Open the chart page →

28,605
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-18.el8_9

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_9

Open the chart page →

6,138
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-18.el8_9

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

7,673
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-18.el8_9

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-39615.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_9

Open the chart page →

3,697

Container images carrying it

406 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
localstack/localstack:3.19d278167f2b7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
mariadb/maxscale:23.02.256c5e0908148
libxml2@2.9.7-16.el8
0:2.9.7-18.el8_9
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
merlos/zookeeper:3.9.3a38fc7e09ed7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
middlewareeng/middleware:0.3.1747d880812f1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
minio/kes:v0.22.255f3aef5803e
libxml2@2.9.7-15.el8
0:2.9.7-18.el8_9
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
libxml2@2.9.7-8.el8
0:2.9.7-18.el8_9
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
libxml2@2.9.7-12.el8_5
0:2.9.7-18.el8_9
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_9
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_9
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_9
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
libxml2@2.9.7-13.el8_6.1
0:2.9.7-18.el8_9
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
libxml2@2.9.7-15.el8
0:2.9.7-18.el8_9
1
minio/operator:v5.0.9170b154d2c61
libxml2@2.9.7-16.el8_8.1
0:2.9.7-16.el8_8.2
1
minio/operator:v4.1.02adc5be088f5
libxml2@2.9.7-9.el8
0:2.9.7-18.el8_9
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
moreillon/api-proxy:latestd7d4a5463525
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
moreillon/camera-viewer:lateste418cc694bd5
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
moreillon/food-manager:lateste8fd856e593d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
moreillon/user-manager-front:v5.1.06597e6b98d21
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
muhammedgamal/fp23:latest74b4cd69b6fa
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
nirmalnaveen/supermario:latest8541a39162f3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/chatqna:1.038c51b791efa
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/codegen:1.058f91683892d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/codegen-ui:1.02bee4eb66f3e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/codetrans:1.0e2436483b73d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/codetrans-ui:1.03ef121f34610
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/docsum:1.03eaa91849512
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/docsum-ui:1.07f854e9bffaf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/guardrails-tgi:1.0262c6048aab8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/guardrails-tgi:latestf68bec6a1271
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/speecht5:1.0249afad3d268
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opea/web-retriever-chroma:1.0fe08165d7770
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
opencsghq/kubectl:latestb6d87e1048c2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
libxml2@2.9.7-13.el8_6.1
0:2.9.7-18.el8_9
1
phan2410/dummy-service:0.0.89c6ed6de26ca
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
pk910/powfaucet:v2-stable3dcae6a62896
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
libxml2@2.9.7-5.el8
0:2.9.7-18.el8_9
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
libxml2@2.9.7-16.el8_8.1
0:2.9.7-18.el8_9
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
libxml2@2.9.7-16.el8_8.1
0:2.9.7-16.el8_8.2
1
praravind1801/helmimages:3.0.0f29d637b9ce1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
rm3l/dev-feed-api:latest9a7f732245a3
libxml2@2.9.13-3.el9_2.1
0:2.9.13-5.el9_3
1
sarwansharma/minio:v359d1da9385d1
libxml2@2.9.7-13.el8_6.1
0:2.9.7-18.el8_9
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_9
1
shamimkuet/nginx:1.0.2b82902a76a04
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.