StackRadar

CVE-2025-6170

Low

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
827
of 17,787 indexed, latest versions
Container images
898
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 827 of 17,787 indexed charts deploy, on 898 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more486
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+32 more0:2.9.7-21.el8_10.6, 0:2.9.13-14.el9_8.2, 0:2.12.5-10.el10_2.2346
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r066
OSV records
ALPINE-CVE-2025-6170DEBIAN-CVE-2025-6170RHSA-2026:36734RHSA-2026:39304RHSA-2026:39317RLSA-2026:36734RLSA-2026:39317UBUNTU-CVE-2025-6170
Also known as
USN-7694-1

Charts affected

827 by stars
ChartLatestAffected imagesRadar Score
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,736
opentickopenchartVerified publisher0.1.01 of 1See more

opentick openchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/nginx:1.25.5a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,688
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6

Open the chart page →

18,023
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

63,277
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9
omecproject/onos-progran:1.0.05715e5648aa0
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

88,616
comac-cuopencord0.1.11 of 4See more

comac-cu opencord 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libxml2@2.9.4+dfsg1-6.1ubuntu1
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

8,053
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

26,234
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

42,662
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

29,158
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libxml2@2.9.4+dfsg1-6.1ubuntu1
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

15,660
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

14,550
omec-control-planeopencord0.1.313 of 8See more

omec-control-plane opencord 0.1.31

3 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
omecproject/mme-exporter:paging-latestbcc5f19fd676
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
omecproject/openmme:master-latest64776cb9edb3
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

40,795
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

38,889
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

11,003
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
libxml2@2.12.5-10.el10
0:2.12.5-10.el10_2.2

Open the chart page →

2,043
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6

Open the chart page →

7,457
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6

Open the chart page →

11,795
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2

Open the chart page →

2,386
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.6
andrianrf/backoffice-be:latest6036614803d4
libxml2@2.9.13-3.el9_1
0:2.9.13-14.el9_8.2
andrianrf/iso-server:latest7da47f525c7d
libxml2@2.9.13-3.el9_1
0:2.9.13-14.el9_8.2

Open the chart page →

34,721
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.6

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2

Open the chart page →

18,991
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.6
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2

Open the chart page →

13,034
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6

Open the chart page →

16,554
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2

Open the chart page →

4,145
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
libxml2@2.9.7-21.el8_10.4
0:2.9.7-21.el8_10.6

Open the chart page →

5,863
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6

Open the chart page →

19,449
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
libxml2@2.9.13-3.el9_2.1
0:2.9.13-14.el9_8.2

Open the chart page →

8,634
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6

Open the chart page →

13,608
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6

Open the chart page →

13,570
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6

Open the chart page →

13,553
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6

Open the chart page →

13,457
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6

Open the chart page →

13,101
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
libxml2@2.9.13-6.el9_5.2
0:2.9.13-14.el9_8.2

Open the chart page →

2,063
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

36,230
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

2,003
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6

Open the chart page →

5,609
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm8

Open the chart page →

26,367
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,539
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.02 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

2 of the 40 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/postgres:17.5-alpine6567bca8d7bc
libxml2@2.13.8-r0
2.13.9-r0
library/postgres:17.2-alpine7e5df973a748
libxml2@2.13.4-r3
2.13.9-r0

Open the chart page →

72,154
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

11,095
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

25,681
p4p40.1.02 of 7See more

p4 p4 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
mastercloudapps/weatherservice:v1.23de859d29c116
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6

Open the chart page →

27,667
parcial-1parcial-1-chart1.0.02 of 5See more

parcial-1 parcial-1-chart 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
esteban1930/frontend-1:1.8.0f9078279632c
libxml2@2.13.8-r0
2.13.9-r0
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

3,852
cloudflaredpascaliskeVerified publisher3.0.01 of 1See more

cloudflared pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

2,029
pmm-ha-dependenciespercona1.0.01 of 4See more

pmm-ha-dependencies percona 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
percona/percona-postgresql-operator:2.8.06cce2698d3f5
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

2,449
ps-operatorpercona1.2.01 of 1See more

ps-operator percona 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
percona/percona-server-mysql-operator:1.2.028bfc38c1d4b
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2

Open the chart page →

267
matomopetbattle11.0.12 of 2See more

matomo petbattle 11.0.1

2 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,801

Container images carrying it

898 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
libxml2@2.13.4-r3
2.13.9-r0
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
libxml2@2.13.8-r0
2.13.9-r0
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ghcr.io/huscker/townsquare-frontend:2.15.2dc6384d10cc8
libxml2@2.13.4-r6
2.13.9-r0
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
libxml2@2.9.13-5.el9_3
0:2.9.13-14.el9_8.2
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
libxml2@2.13.4-r6
2.13.9-r0
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.6
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
libxml2@2.9.7-19.el8_10
0:2.9.7-21.el8_10.6
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
libxml2@2.13.8-r0
2.13.9-r0
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
libxml2@2.13.8-r0
2.13.9-r0
1
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
1
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
1
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
libxml2@2.9.4+dfsg1-6.1ubuntu1.8
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libxml2@2.9.10+dfsg-5ubuntu0.20.04.9
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.