StackRadar

CVE-2024-55549

High

Advisory

Published 14 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
246
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxslt security update

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 246 images.

Affected packageAffected versionsFixed inImages
libxsltdeb1.1.28-2.1ubuntu0.3, 1.1.28-2ubuntu0.1, 1.1.29-5ubuntu0.2, 1.1.34-4+5 more1.1.28-2.1ubuntu0.3+esm3, 1.1.28-2ubuntu0.2+esm4, 1.1.29-5ubuntu0.3+esm2, 1.1.34-4ubuntu0.20.04.2+3 more173
libxsltapk1.1.38-r0, 1.1.39-r0, 1.1.39-r1, 1.1.42-r11.1.38-r1, 1.1.39-r1, 1.1.39-r2, 1.1.42-r269
libxsltrpm1.1.34-9.el90:1.1.34-13.el9_4, 0:1.1.34-13.el9_64
OSV records
ALPINE-CVE-2024-55549DEBIAN-CVE-2024-55549RHSA-2025:3613RLSA-2025:7410UBUNTU-CVE-2024-55549
Also known as
RHSA-2025:4025, RHSA-2025:7410, USN-7357-1, USN-7787-1

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libxslt@1.1.39-r1
1.1.39-r2

Open the chart page →

13,677
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
libxslt@1.1.38-r0
1.1.38-r1

Open the chart page →

448
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-55549.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
libxslt@1.1.38-r0
1.1.38-r1

Open the chart page →

1,589

Container images carrying it

246 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
libxslt@1.1.39-r1
1.1.39-r2
6
quay.io/devtron/postgres:14.91b594392f7cb
libxslt@1.1.35-1
1.1.35-1+deb12u1
6
library/postgres:122f2a8c2a7d10
libxslt@1.1.35-1
1.1.35-1+deb12u1
5
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
libxslt@1.1.38-r0
1.1.38-r1
5
bitnamilegacy/postgresql:16233f361c5819
libxslt@1.1.35-1
1.1.35-1+deb12u1
4
library/nginx:1.27.1287ff321f9e3
libxslt@1.1.35-1
1.1.35-1+deb12u1
4
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxslt@1.1.35-1
1.1.35-1+deb12u1
3
gchq/hdfs:3.3.35ec58edbb2db
libxslt@1.1.39-0exp1build1
1.1.39-0exp1ubuntu0.24.04.1
3
library/nginx:1.25.5-alpine:1.25-alpine516475cc129d
libxslt@1.1.39-r0
1.1.39-r1
3
library/nginx:1.25:1.25.5a484819eb602
libxslt@1.1.35-1
1.1.35-1+deb12u1
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
libxslt@1.1.39-r1
1.1.39-r2
3
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
libxslt@1.1.38-r0
1.1.38-r1
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
libxslt@1.1.38-r0
1.1.38-r1
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxslt@1.1.35-1
1.1.35-1+deb12u1
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxslt@1.1.35-1
1.1.35-1+deb12u1
3
apache/nifi-registry:1.26.07cdfd8deec92
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
library/nginx:1.27.098f8ec75657d
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
library/postgres:16.109f23e02d766
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
library/postgres:16.24aea012537ed
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
library/postgres:16.4e62fbf9d3e2b
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
library/postgres:11-alpineea50b9fd617b
libxslt@1.1.39-r0
1.1.39-r1
2
library/python:3.7eedf63967cdb
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
opea/chatqna-conversation-ui:1.002d5674ca863
libxslt@1.1.39-r1
1.1.39-r2
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
ghcr.io/airflow-helm/postgresql-bitnami:11.22-patch.0df576862b7c0
libxslt@1.1.39-r0
1.1.39-r1
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
libxslt@1.1.35-1
1.1.35-1+deb12u1
2
ankane/pgvector:v0.5.1d3a9d8ac27bb
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
apache/airflow:2.8.4-python3.964e58748b6b9
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
apache/airflow:2.8.1e5560ad0b86e
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
apache/nifi-registry:1.27.063b8e3e40742
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1
assistiot/identity-manager_db:latest0d3e6d35f168
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
avinash263/pyredis263:latestaa2b8727f1a6
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
avzini/web-app:latestf40b30210ed0
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
baserow/backend:1.31.1e0b3c8130b91
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
baserow/baserow:1.30.1df0c42eb67e8
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
libxslt@1.1.35-1
1.1.35-1+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.