StackRadar

CVE-2025-58767

Medium

Advisory

Published 17 Sept 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 5
affected packages

REXML has DoS condition when parsing malformed XML file

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
ruby2.7deb2.7.0-5ubuntu1.4, 2.7.0-5ubuntu1.5, 2.7.0-5ubuntu1.8no fix listed6
ruby2.3deb2.3.1-2~16.04.5no fix listed2
ruby3.0deb3.0.2-7ubuntu2.4, 3.0.2-7ubuntu2.8no fix listed2
ruby2.5deb2.5.8-1bbox1~bionic1no fix listed1
rexmlgem3.3.6, 3.3.9, 3.4.0, 3.4.13.4.27
OSV records
GHSA-c2f4-jgmc-q2r5UBUNTU-CVE-2025-58767

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
rexml@3.4.0
3.4.2

Open the chart page →

9,203
puppetserverpuppetserver9.5.21 of 5See more

puppetserver puppetserver 9.5.2

1 of the 5 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
ruby3.0@3.0.2-7ubuntu2.4
no fix listed

Open the chart page →

14,184
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
ruby2.5@2.5.8-1bbox1~bionic1
no fix listed

Open the chart page →

18,137
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
ruby2.7@2.7.0-5ubuntu1.4
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
ruby2.7@2.7.0-5ubuntu1.5
no fix listed

Open the chart page →

113,791
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
rexml@3.4.0
3.4.2

Open the chart page →

5,558
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
ruby3.0@3.0.2-7ubuntu2.8
rexml@3.3.6
no fix listed
3.4.2

Open the chart page →

5,886
monitoring-stackdata354-helmVerified publisher1.4.21 of 4See more

monitoring-stack data354-helm 1.4.2

1 of the 4 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
grafana/fluent-plugin-loki:latest8a3882e8c28b
rexml@3.4.1
3.4.2

Open the chart page →

3,176
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
rexml@3.3.9
3.4.2

Open the chart page →

2,942
octoboxhalkeye0.1.11 of 1See more

octobox halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
octoboxio/octobox:latestd909041c46eb
rexml@3.4.0
3.4.2

Open the chart page →

3,255
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
ruby2.3@2.3.1-2~16.04.5
no fix listed

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
ruby2.3@2.3.1-2~16.04.5
no fix listed

Open the chart page →

38,865
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
rexml@3.4.0
3.4.2

Open the chart page →

10,795
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-58767.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
ruby2.7@2.7.0-5ubuntu1.8
no fix listed

Open the chart page →

11,405

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
chatwoot/chatwoot:v4.15.167ebc751c171
rexml@3.4.0
3.4.2
1
grafana/fluent-plugin-loki:latest8a3882e8c28b
rexml@3.4.1
3.4.2
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
ruby2.5@2.5.8-1bbox1~bionic1
no fix listed
1
library/logstash:9.1.233eae14f0867
rexml@3.3.9
3.4.2
1
muluder/prograncontrollermcord:0.1.843b597a93da7
ruby2.3@2.3.1-2~16.04.5
no fix listed
1
octoboxio/octobox:latestd909041c46eb
rexml@3.4.0
3.4.2
1
omecproject/onos-progran:1.0.05715e5648aa0
ruby2.3@2.3.1-2~16.04.5
no fix listed
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
ruby2.7@2.7.0-5ubuntu1.8
no fix listed
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
rexml@3.4.0
3.4.2
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
ruby2.7@2.7.0-5ubuntu1.4
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
rexml@3.4.0
3.4.2
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
ruby3.0@3.0.2-7ubuntu2.4
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
ruby3.0@3.0.2-7ubuntu2.8
rexml@3.3.6
no fix listed
3.4.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.