StackRadar

CVE-2023-52426

Medium

Advisory

Published 4 Feb 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
550
of 17,787 indexed, latest versions
Container images
547
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 550 of 17,787 indexed charts deploy, on 547 images.

Affected packageAffected versionsFixed inImages
expatdeb2.5.0-1, 2.5.0-1+deb12u1, 2.5.0-1+deb12u2, 2.5.0-1+deb12u3no fix listed390
expatapk2.4.8-r0, 2.4.9-r0, 2.5.0-r0, 2.5.0-r1+1 more2.6.0-r0157
OSV records
ALPINE-CVE-2023-52426DEBIAN-CVE-2023-52426

Charts affected

550 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

547 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
assistiot/open_api_kong:1.0.03fe850384689
expat@2.4.9-r0
2.6.0-r0
1
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
expat@2.5.0-r1
2.6.0-r0
1
assistiot/resource-provisioning_im:1.0.0a942dc14030a
expat@2.5.0-r2
2.6.0-r0
1
assistiot/semantic_translation:latest2a2587804717
expat@2.5.0-r1
2.6.0-r0
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
expat@2.5.0-1
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
expat@2.5.0-1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
expat@2.5.0-1
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
expat@2.5.0-1
no fix listed
1
avzini/web-app:latestf40b30210ed0
expat@2.5.0-1
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
expat@2.5.0-1+deb12u1
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
expat@2.5.0-1+deb12u1
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.301249fc292e84
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.3164614ef8290f
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
expat@2.5.0-1
no fix listed
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
expat@2.5.0-1+deb12u1
no fix listed
1
blockscout/blockscout:5.1.5c365a8f2dc12
expat@2.4.8-r0
2.6.0-r0
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
expat@2.5.0-1+deb12u1
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
expat@2.5.0-1+deb12u1
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
expat@2.5.0-1+deb12u1
no fix listed
1
boky/postfix:4.4.0f3f247fd4252
expat@2.5.0-1+deb12u1
no fix listed
1
budibase/database:2.1.0d90f656261c9
expat@2.5.0-1+deb12u2
no fix listed
1
calltelemetry/web:0.8.1-rc7205d13269e350
expat@2.5.0-1+deb12u1
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
expat@2.5.0-1+deb12u1
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
expat@2.5.0-1+deb12u1
no fix listed
1
charmcli/soft-serve:v0.4.039523c1a6ba8
expat@2.4.8-r0
2.6.0-r0
1
ckulka/baikal:0.10.1-nginx434bdd162247
expat@2.5.0-1+deb12u1
no fix listed
1
cloudtooling/moodle:5.2.3f4f04e0fc401
expat@2.5.0-1+deb12u3
no fix listed
1
codecov/self-hosted-api:24.4.10475cb1c3136
expat@2.5.0-r1
2.6.0-r0
1
codedesignplus/ms-emails-grpc:lateste336012bc781
expat@2.5.0-1+deb12u2
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
expat@2.5.0-1+deb12u2
no fix listed
1
collabora/code:24.04.13.2.101dc4ab83977
expat@2.5.0-1+deb12u1
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
expat@2.5.0-1
no fix listed
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
expat@2.5.0-1+deb12u1
no fix listed
1
crazymax/rrdcached:1.8.0841b10cdae76
expat@2.5.0-r1
2.6.0-r0
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
expat@2.5.0-r0
2.6.0-r0
1
cspconsole/config-provider:1.0.365524a26a6c23
expat@2.5.0-1+deb12u2
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
expat@2.5.0-1+deb12u2
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
expat@2.5.0-1
no fix listed
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
expat@2.5.0-1+deb12u2
no fix listed
1
dannielkil/book-frontend:latest937993927694
expat@2.5.0-1
no fix listed
1
datasaker/dsk-container-agent:latest08b52999f67b
expat@2.5.0-r2
2.6.0-r0
1
davidvmar/urjc-davidvmar-rabbitmq:1.0.0e9ce2608f799
expat@2.4.8-r0
2.6.0-r0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
expat@2.5.0-1
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
expat@2.5.0-1
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
expat@2.5.0-1
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
expat@2.5.0-1
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
expat@2.5.0-1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.