StackRadar

CVE-2025-49794

Critical

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
560
of 17,787 indexed, latest versions
Container images
552
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 560 of 17,787 indexed charts deploy, on 552 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more486
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r066
OSV records
ALPINE-CVE-2025-49794DEBIAN-CVE-2025-49794UBUNTU-CVE-2025-49794
Also known as
USN-7694-1

Charts affected

560 by stars
ChartLatestAffected imagesRadar Score
excalidrawkubitodevVerified publisher1.0.31 of 1See more

excalidraw kubitodev 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
excalidraw/excalidraw:latestf7ee194addd6
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

840
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
penpotapp/exporter:2.2.15c835ffd87ab
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

17,002
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

20,299
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

16,537
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

26,371
excalidrawlinkding0.2.31 of 1See more

excalidraw linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
excalidraw/excalidraw:latestf7ee194addd6
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

840
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

37,518
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

10,773
elastictranscoderluiscajl0.46.02 of 4See more

elastictranscoder luiscajl 0.46.0

2 of the 4 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
elastictranscoder/transcoder:627e21dcb4a0327029e6
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm4
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

58,225
docker-mailservermailserverVerified publisher0.2.652 of 9See more

docker-mailserver mailserver 0.2.65

2 of the 9 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
libxml2@2.13.4-r6
2.13.9-r0
jeboehm/mailserver-web:5.0.929da13edf5aa8
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

10,908
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

8,351
cameramedia-streaming-meshVerified publisher0.2.52 of 3See more

camera media-streaming-mesh 0.2.5

2 of the 3 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
ciscolabs/rtsp-server:latestb59fc10bb821
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

18,712
msm-rtspmedia-streaming-meshVerified publisher0.0.22 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

2 of the 2 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
ciscolabs/rtsp-server:latestb59fc10bb821
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

18,712
rtspmedia-streaming-meshVerified publisher0.0.142 of 2See more

rtsp media-streaming-mesh 0.0.14

2 of the 2 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
ciscolabs/rtsp-server:latestb59fc10bb821
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

18,712
memgptmemgptVerified publisher0.3.191 of 2See more

memgpt memgpt 0.3.19

1 of the 2 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ankane/pgvector:v0.5.1d3a9d8ac27bb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,872
localpathprovisionermesosphere-stable0.1.21 of 1See more

localpathprovisioner mesosphere-stable 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

17,966
postgresmicroboxlabs0.3.01 of 1See more

postgres microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
library/postgres:16.6557fea37a744
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

3,699
teimilvus-helm1.6.01 of 1See more

tei milvus-helm 1.6.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

3,063
zkapps-dashboardminaVerified publisher0.1.21 of 2See more

zkapps-dashboard mina 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
library/postgres:12-alpine7c8f48705831
libxml2@2.13.4-r3
2.13.9-r0

Open the chart page →

1,524
mini-blogmini-blog-helm0.1.02 of 3See more

mini-blog mini-blog-helm 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
beyzkaya/blog-frontend:v1.0.0bf412d75c510
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

12,637
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

42,983
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
moreillon/camera-viewer:lateste418cc694bd5
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

11,694
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
moreillon/group-manager-front:v3.3.1c9f85db3baa5
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,886
user-manager-mongodbmoreillonVerified publisher0.6.22 of 4See more

user-manager-mongodb moreillon 0.6.2

2 of the 4 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
moreillon/user-manager-front:v5.0.3b067dbbbb6af
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

23,263
user-manager-neo4jmoreillonVerified publisher0.9.73 of 6See more

user-manager-neo4j moreillon 0.9.7

3 of the 6 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
moreillon/group-manager-front:v3.3.1c9f85db3baa5
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
moreillon/user-manager:v5.0.2e1c9bfab5c16
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
moreillon/user-manager-front:v5.1.06597e6b98d21
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

30,195
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,602
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

25,989
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

15,731
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

13,711
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

12,861
my-helm-chartmy-helm-charts-2024Verified publisher0.1.01 of 1See more

my-helm-chart my-helm-charts-2024 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
shamimkuet/nginx:1.0.2b82902a76a04
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,383
nginx-chartmy-nginx-chart0.1.01 of 1See more

nginx-chart my-nginx-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
amaraiheanacho/nginx-site:latest5c86fccf5daa
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

840
mystoremystore-chart0.1.02 of 3See more

mystore mystore-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
hazegoodlife/haaze:veggiesite50f02d2d5d4d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
hazegoodlife/haaze:milksite8d4c63169e14
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

8,776
myweatherhelmmyweather1.3.112 of 7See more

myweatherhelm myweather 1.3.11

2 of the 7 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
hecrom/myweatherangularclient:1.3.11bb0372939c19
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

17,411
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

12,839
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.03ba6e6f11388
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

15,408
smilencsaVerified publisher1.1.07 of 23See more

smile ncsa 1.1.0

7 of the 23 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
2.9.4+dfsg1-6.1ubuntu1.9+esm4
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
socialmediamacroscope/image_crawler:0.1.2f508216be63c
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
2.9.4+dfsg1-6.1ubuntu1.9+esm4
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
socialmediamacroscope/preprocessing:0.1.3ca863306314b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

109,485
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

7,413
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,731
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,731
nginx-sitenginx-site0.1.01 of 1See more

nginx-site nginx-site 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
amaraiheanacho/nginx-site:latest5c86fccf5daa
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

840
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,831
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

22,713
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

13,331
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

13,405
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

13,387
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
libxml2@2.9.1+dfsg1-3ubuntu4.3
2.9.1+dfsg1-3ubuntu4.13+esm8

Open the chart page →

41,455
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

27,667
lensoci-ai-incubations0.1.142 of 16See more

lens oci-ai-incubations 0.1.14

2 of the 16 container images this version deploys carry CVE-2025-49794.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
libxml2@2.13.8-r0
2.13.9-r0
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

17,085

Container images carrying it

552 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
sysnet4admin/colosseum-cms:loge74b43c7f492
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
teknas09/bird-pod:latest12a1fa85c4aa
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9
1
theradius/loggia:0.463ba348546ec
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
thongngo3301/stakefish:latesta341af5976e3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libxml2@2.9.13+dfsg-1ubuntu0.2
2.9.13+dfsg-1ubuntu0.8
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
libxml2@2.9.13+dfsg-1ubuntu0.5
2.9.13+dfsg-1ubuntu0.8
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.9
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
vcnngr/pnfrontend:latest4e4979ab8c41
libxml2@2.13.8-r0
2.13.9-r0
1
vlebediantsev/notes-admin-front:latest007c6670ff48
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
vlebediantsev/notes-project-front:latest945675fd2636
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
wavefronthq/proxy:9.2d1064d28f6eb
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.8
1
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.8
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
libxml2@2.13.8-r0
2.13.9-r0
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm9
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
libxml2@2.13.4-r5
2.13.9-r0
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
libxml2@2.13.4-r5
2.13.9-r0
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.