StackRadar

CVE-2024-55549

High

Advisory

Published 14 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
246
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxslt security update

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 246 images.

Affected packageAffected versionsFixed inImages
libxsltdeb1.1.28-2.1ubuntu0.3, 1.1.28-2ubuntu0.1, 1.1.29-5ubuntu0.2, 1.1.34-4+5 more1.1.28-2.1ubuntu0.3+esm3, 1.1.28-2ubuntu0.2+esm4, 1.1.29-5ubuntu0.3+esm2, 1.1.34-4ubuntu0.20.04.2+3 more173
libxsltapk1.1.38-r0, 1.1.39-r0, 1.1.39-r1, 1.1.42-r11.1.38-r1, 1.1.39-r1, 1.1.39-r2, 1.1.42-r269
libxsltrpm1.1.34-9.el90:1.1.34-13.el9_4, 0:1.1.34-13.el9_64
OSV records
ALPINE-CVE-2024-55549DEBIAN-CVE-2024-55549RHSA-2025:3613RLSA-2025:7410UBUNTU-CVE-2024-55549
Also known as
RHSA-2025:4025, RHSA-2025:7410, USN-7357-1, USN-7787-1

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libxslt@1.1.39-r1
1.1.39-r2

Open the chart page →

13,677
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
libxslt@1.1.38-r0
1.1.38-r1

Open the chart page →

448
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
libxslt@1.1.38-r0
1.1.38-r1

Open the chart page →

1,589

Container images carrying it

246 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/devops-ia/kafka-cruise-control-ui:0.4.096c25035cb02
libxslt@1.1.39-r0
1.1.39-r1
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/element-hq/hydrogen-web:v0.5.12d15d14b201a
libxslt@1.1.39-r1
1.1.39-r2
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/gabe565/mnemonic-ninja:latest1fd90a9e4d04
libxslt@1.1.39-r0
1.1.39-r1
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
libxslt@1.1.34-4build2
1.1.34-4ubuntu0.22.04.2
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
libxslt@1.1.34-4build2
1.1.34-4ubuntu0.22.04.2
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
libxslt@1.1.39-r1
1.1.39-r2
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
libxslt@1.1.39-r0
1.1.39-r1
1
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
libxslt@1.1.39-r0
1.1.39-r1
1
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
libxslt@1.1.39-r0
1.1.39-r1
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
libxslt@1.1.39-r1
1.1.39-r2
1
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
libxslt@1.1.39-r1
1.1.39-r2
1
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
libxslt@1.1.39-r1
1.1.39-r2
1
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
libxslt@1.1.39-r1
1.1.39-r2
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
libxslt@1.1.39-r0
1.1.39-r1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/zazuko/blueprint:v0.1.092ac2f97978e
libxslt@1.1.39-r0
1.1.39-r1
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.2
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libxslt@1.1.34-9.el9
0:1.1.34-13.el9_4
1
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
libxslt@1.1.34-9.el9
0:1.1.34-13.el9_6
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libxslt@1.1.34-9.el9
0:1.1.34-13.el9_4
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
libxslt@1.1.38-r0
1.1.38-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.