StackRadar

CVE-2024-55549

High

Advisory

Published 14 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
246
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxslt security update

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 246 images.

Affected packageAffected versionsFixed inImages
libxsltdeb1.1.28-2.1ubuntu0.3, 1.1.28-2ubuntu0.1, 1.1.29-5ubuntu0.2, 1.1.34-4+5 more1.1.28-2.1ubuntu0.3+esm3, 1.1.28-2ubuntu0.2+esm4, 1.1.29-5ubuntu0.3+esm2, 1.1.34-4ubuntu0.20.04.2+3 more173
libxsltapk1.1.38-r0, 1.1.39-r0, 1.1.39-r1, 1.1.42-r11.1.38-r1, 1.1.39-r1, 1.1.39-r2, 1.1.42-r269
libxsltrpm1.1.34-9.el90:1.1.34-13.el9_4, 0:1.1.34-13.el9_64
OSV records
ALPINE-CVE-2024-55549DEBIAN-CVE-2024-55549RHSA-2025:3613RLSA-2025:7410UBUNTU-CVE-2024-55549
Also known as
RHSA-2025:4025, RHSA-2025:7410, USN-7357-1, USN-7787-1

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libxslt@1.1.39-r1
1.1.39-r2

Open the chart page →

13,677
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
libxslt@1.1.38-r0
1.1.38-r1

Open the chart page →

448
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
libxslt@1.1.38-r0
1.1.38-r1

Open the chart page →

1,589

Container images carrying it

246 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
praravind1801/helmimages:3.0.0f29d637b9ce1
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
resurfaceio/resurface:3.7.84d5cda2f64109
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
scrapinghub/splash:3.4.1a5f89bc84606
libxslt@1.1.29-5ubuntu0.2
1.1.29-5ubuntu0.3+esm2
1
seafileltd/seafile-mc:9.0.106693911bcc40
libxslt@1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.2
1
seafileltd/seafile-mc:9.0.97ac833196f60
libxslt@1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.2
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
shamimkuet/nginx:1.0.2b82902a76a04
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
sky5367/locust-plugins-timescale:latestd3150f201471
libxslt@1.1.38-r0
1.1.38-r1
1
snipe/snipe-it:v6.0.1455fb7636a98c
libxslt@1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.2
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
somnathmore/custom-nginx:v2bdfc06cad4ec
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
statcan/ckan:2.93921305425b8
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
substratusai/verba:v0.4.0-baseURL261695be635eb
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libxslt@1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.2
1
swaggerapi/swagger-ui:v5.6.2342808e22de4
libxslt@1.1.38-r0
1.1.38-r1
1
teknas09/bird-pod:latest12a1fa85c4aa
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
theradius/loggia:0.463ba348546ec
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
thongngo3301/stakefish:latesta341af5976e3
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
timescale/timescaledb:latest-pg12645fd9e92d76
libxslt@1.1.38-r0
1.1.38-r1
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxslt@1.1.34-4build2
1.1.34-4ubuntu0.22.04.2
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
libxslt@1.1.39-r0
1.1.39-r1
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
vlebediantsev/notes-admin-front:latest007c6670ff48
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
vlebediantsev/notes-project-front:latest945675fd2636
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
xeladock/mysql_dns:latest4baf531453f1
libxslt@1.1.34-4build2
1.1.34-4ubuntu0.22.04.2
1
xeladock/nginx2:latestc259a67b1dff
libxslt@1.1.34-4build2
1.1.34-4ubuntu0.22.04.2
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libxslt@1.1.39-0exp1build1
1.1.39-0exp1ubuntu0.24.04.1
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
gcr.io/kubecost1/frontend:prod-1.108.14c6df805bbf2
libxslt@1.1.38-r0
1.1.38-r1
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
libxslt@1.1.39-r1
1.1.39-r2
1
ghcr.io/appscode/marketplace-ui:0.3.1d52177072013
libxslt@1.1.39-r1
1.1.39-r2
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
libxslt@1.1.35-1
1.1.35-1+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.