StackRadar

CVE-2025-6170

Low

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
827
of 17,787 indexed, latest versions
Container images
898
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 827 of 17,787 indexed charts deploy, on 898 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more486
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+32 more0:2.9.7-21.el8_10.6, 0:2.9.13-14.el9_8.2, 0:2.12.5-10.el10_2.2346
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r066
OSV records
ALPINE-CVE-2025-6170DEBIAN-CVE-2025-6170RHSA-2026:36734RHSA-2026:39304RHSA-2026:39317RLSA-2026:36734RLSA-2026:39317UBUNTU-CVE-2025-6170
Also known as
USN-7694-1

Charts affected

827 by stars
ChartLatestAffected imagesRadar Score
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.6
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.6

Open the chart page →

12,460
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

12,632
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

25,184
ibm-ucv-prodibm-helm5.2.62 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

2 of the 16 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
libxml2@2.9.7-5.el8
0:2.9.7-21.el8_10.6

Open the chart page →

11,975
monitoring-stackict-platformVerified publisher0.4.01 of 13See more

monitoring-stack ict-platform 0.4.0

1 of the 13 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

9,597
ingress-nginxifmethod-helm-charts4.12.11 of 2See more

ingress-nginx ifmethod-helm-charts 4.12.1

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

1,476
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2

Open the chart page →

3,181
eoloserverihuertas2021-vmartinp2021-helm0.1.02 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6

Open the chart page →

27,812
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

9,032
ikigaiikigai-chartVerified publisher0.0.92 of 58See more

ikigai ikigai-chart 0.0.9

2 of the 58 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
kuberay/operator:v1.0.04e6ac8a3a2c4
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.6

Open the chart page →

37,844
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

3,586
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

6,282
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

11,838
plausible-analyticsimioVerified publisher0.4.23 of 5See more

plausible-analytics imio 0.4.2

3 of the 5 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,152
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
libxml2@2.9.4+dfsg1-6.1ubuntu1.8
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

16,226
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

5,360
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,069
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

10,542
evi-miniointelVerified publisher3.0.32 of 2See more

evi-minio intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6

Open the chart page →

7,457
gmaintelVerified publisher0.1.01 of 1See more

gma intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

7,697
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

18,137
kesintelVerified publisher0.8.31 of 1See more

kes intel 0.8.3

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
minio/kes:v0.22.255f3aef5803e
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6

Open the chart page →

3,570
map5gintelVerified publisher1.0.01 of 1See more

map5g intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

7,697
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

11,123
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

16,558
daveit-at-mOfficialVerified publisher0.2.159 of 11See more

dave it-at-m 0.2.15

9 of the 11 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2

Open the chart page →

15,245
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

1,965
wjh-rechnerit-at-mOfficialVerified publisher1.0.41 of 1See more

wjh-rechner it-at-m 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
libxml2@2.9.13-5.el9_3
0:2.9.13-14.el9_8.2

Open the chart page →

3,487
zammad-ldap-syncit-at-mVerified publisher0.6.51 of 1See more

zammad-ldap-sync it-at-m 0.6.5

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2

Open the chart page →

1,364
opencloudjacobcolvinVerified publisher0.2.37 of 13See more

opencloud jacobcolvin 0.2.3

7 of the 13 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

45,392
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,816
jasperjasperVerified publisher1.0.2031 of 2See more

jasper jasper 1.0.203

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,148
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,097
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
libxml2@2.9.7-5.el8
0:2.9.7-21.el8_10.6

Open the chart page →

9,853
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.6

Open the chart page →

12,856
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

5,256
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

6,648
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

6,629
image-storage-servicejtektVerified publisher0.4.32 of 4See more

image-storage-service jtekt 0.4.3

2 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

22,665
shinsei-managerjtektVerified publisher0.2.05 of 8See more

shinsei-manager jtekt 0.2.0

5 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
moreillon/user-manager:v5.0.2e1c9bfab5c16
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
moreillon/user-manager-front:v5.0.3b067dbbbb6af
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

59,560
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

16,626
jellyfink8s-chartsVerified publisher0.2.41 of 1See more

jellyfin k8s-charts 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.696b09723b22f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,116
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
libxml2@2.9.13+dfsg-1ubuntu0.6
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

6,136
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

8,879
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

2,732
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

14,833
postgresqlkagiso-me0.4.01 of 1See more

postgresql kagiso-me 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/postgres:17.4-alpine7062a2109c4b
libxml2@2.13.4-r3
2.13.9-r0

Open the chart page →

1,488
k10restorekastenVerified publisher8.0.141 of 1See more

k10restore kasten 8.0.14

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

1,478
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

16,464
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,599

Container images carrying it

898 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
libxml2@2.9.13-6.el9_5.2
0:2.9.13-14.el9_8.2
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.6
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
libxml2@2.9.7-5.el8
0:2.9.7-21.el8_10.6
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
quay.io/minio/directpv:v4.0.84560083eb77d
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.6
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.6
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
libxml2@2.9.7-21.el8_10.2
0:2.9.7-21.el8_10.6
1
quay.io/netobserv/network-observability-operator:1.12.0-communityb05d21a015b0
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
1
quay.io/open-cluster-management/managed-serviceaccount:v0.10.0d6284bd7765a
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
libxml2@2.9.7-21.el8_10.5
0:2.9.7-21.el8_10.6
1
quay.io/openshift/origin-cli:4.66722d5041b47
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.6
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.6
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
libxml2@2.9.7-13.el8_6.4
0:2.9.7-21.el8_10.6
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
1
quay.io/projectquay/clair:4.9.023329c3368e4
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
libxml2@2.9.13-3.el9_2.1
0:2.9.13-14.el9_8.2
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.6
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2
1
quay.io/strimzi/operator:0.45.158c727cd2e68
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.6
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.6
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
libxml2@2.9.13-10.el9_6
0:2.9.13-14.el9_8.2
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
libxml2@2.13.8-r0
2.13.9-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
libxml2@2.13.8-r0
2.13.9-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
libxml2@2.13.4-r3
2.13.9-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.