StackRadar

CVE-2025-49796

Critical

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
555
of 17,781 indexed, latest versions
Container images
549
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 555 of 17,781 indexed charts deploy, on 549 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more485
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r064
OSV records
ALPINE-CVE-2025-49796DEBIAN-CVE-2025-49796UBUNTU-CVE-2025-49796
Also known as
USN-7694-1

Charts affected

555 by stars
ChartLatestAffected imagesRadar Score
giteagiteaOfficialVerified publisher12.7.02 of 4See more

gitea gitea 12.7.0

2 of the 4 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

8,811
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

11,367
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

32,259
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,622
weblateweblateOfficialVerified publisher0.5.361 of 3See more

weblate weblate 0.5.36

1 of the 3 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

6,699
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

19,391
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

3,606
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

6,927
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
libxml2@2.13.4-r6
2.13.9-r0

Open the chart page →

16,251
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

19,926
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

33,725
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

6,543
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,987
litellm-helmlitellm1.100.11 of 2See more

litellm-helm litellm 1.100.1

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,003
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

7,880
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
libxml2@2.13.4-r3
2.13.9-r0

Open the chart page →

1,023
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

10,670
prefect-serverprefectVerified publisher2026.9.32126051 of 2See more

prefect-server prefect 2026.9.3212605

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,786
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

18,509
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2api:3.86f56d239d280
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2auth:3.833ecfda16608
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2notifier:3.8f190a6212195
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2rulesengine:3.8259503496ff9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2scheduler:3.8b1de2055c362
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2sensorcontainer:3.8b1a338f64773
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2stream:3.81c8904a3bf67
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2timersengine:3.81bf35bfaf00c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
stackstorm/st2workflowengine:3.819fdfffdbba8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

96,419
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

11,405
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

4,244
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

1,154
devtron-operatordevtron0.23.31 of 11See more

devtron-operator devtron 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

32,902
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

3,606
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
libxml2@2.9.14+dfsg-1.3ubuntu3.1
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

5,357
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

23,228
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

17,245
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

8,489
puppetserverpuppetserver9.5.21 of 5See more

puppetserver puppetserver 9.5.2

1 of the 5 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

14,184
zabbix-serveraekondratievVerified publisher1.0.62 of 4See more

zabbix-server aekondratiev 1.0.6

2 of the 4 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

30,668
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

6,457
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

12,111
convoyconvoyVerified publisher3.7.131 of 3See more

convoy convoy 3.7.13

1 of the 3 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,896
emqx-operatoremqx-operator2.3.21 of 2See more

emqx-operator emqx-operator 2.3.2

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
alpine/k8s:1.31.49c4976d47656
libxml2@2.13.4-r3
2.13.9-r0

Open the chart page →

4,531
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
libxml2@2.13.4-r3
2.13.9-r0

Open the chart page →

2,811
passboltpassbolt2.1.11 of 6See more

passbolt passbolt 2.1.1

1 of the 6 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

13,350
baserowbaserow-chartVerified publisher1.0.561 of 6See more

baserow baserow-chart 1.0.56

1 of the 6 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

17,263
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

52,919
headwind-mdmchristianhuthVerified publisher5.10.11 of 2See more

headwind-mdm christianhuth 5.10.1

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,870
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,106
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

27,267
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

12,170
infrahubinfrahubVerified publisher4.33.21 of 5See more

infrahub infrahub 4.33.2

1 of the 5 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,428
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

6,307
kubeflowkubeflow1.6.22 of 45See more

kubeflow kubeflow 1.6.2

2 of the 45 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
library/python:3.7eedf63967cdb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

96,941
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,779
radarrloeken-at-homeVerified publisher5.27.0-nightly1 of 1See more

radarr loeken-at-home 5.27.0-nightly

1 of the 1 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
loeken/radarr:5.27.0-nightlya24409d3846d
libxml2@2.13.4-r6
2.13.9-r0

Open the chart page →

586
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,949
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2025-49796.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

8,722

Container images carrying it

549 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bnjbvr/kresus:0.22.137e216b182c8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
libxml2@2.13.8-r0
2.13.9-r0
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
castopod/castopod:1.12.101fd37280cbb2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
libxml2@2.13.4-r3
2.13.9-r0
1
chetangautamm/repo:sipp.v3e7f7049e1544
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
cheyang/distributed-tf:1.6.046cc34755493
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
libxml2@2.13.8-r0
2.13.9-r0
1
chriseaton/adventureworks:latest54c3384ce701
libxml2@2.9.13+dfsg-1ubuntu0.6
2.9.13+dfsg-1ubuntu0.8
1
ckulka/baikal:0.10.1-nginx434bdd162247
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
1
cloudve/janis-terminal:latestaf56e77ca587
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
countly/countly-server:25.05.4e3c238248f99
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
dannielkil/book-frontend:latest937993927694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ddosify/selfhosted_backend:3.2.93c11e3182652
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
deconzcommunity/deconz:2.29.2062de2362641
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
domainmod/domainmod:4.23.04017bfe4c597
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
emqx/ecp-ui:2.5.1e33e9816f147
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
engrmth/bnkr:2.1.06d8464e6f0e8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
erenozcan17/react_frontend:v4.56e1b14973f9b
libxml2@2.13.8-r0
2.13.9-r0
1
esteban1930/frontend-1:1.8.0f9078279632c
libxml2@2.13.8-r0
2.13.9-r0
1
extrim/perlite:1.5.99cb7eb5598b6
libxml2@2.13.4-r5
2.13.9-r0
1
felipecs8/app-db-connection-test:v129e06c9c6385
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
fnzv/dump1090:latestb3079b95c336
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
galaxy/galaxy-init:v18.010267bad550e6
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm8
1
galaxy/galaxy-stable:v18.018e577a626dfd
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm8
1
gchq/accumulo:2.0.1c460bb587d6d
libxml2@2.9.14+dfsg-1.3ubuntu3.1
2.9.14+dfsg-1.3ubuntu3.4
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
gethue/hue:4.11.011b649636e68
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
gethue/hue:4.10.05702b2c37ff9
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
gethue/hue:latest7d5c1b9f8a79
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.8
1
grafana/oncall:v1.16.5499851658393
libxml2@2.13.4-r6
2.13.9-r0
1
guacamole/guacamole:1.5.50f62f6d17ab3
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u3
1
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
haveagitgat/tdarr:2.00.181256348872ce
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
hazegoodlife/haaze:milksite8d4c63169e14
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.