StackRadar

CVE-2025-6170

Low

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
821
of 17,781 indexed, latest versions
Container images
894
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 821 of 17,781 indexed charts deploy, on 894 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more485
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+32 more0:2.9.7-21.el8_10.6, 0:2.9.13-14.el9_8.2, 0:2.12.5-10.el10_2.2345
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r064
OSV records
ALPINE-CVE-2025-6170DEBIAN-CVE-2025-6170RHSA-2026:36734RHSA-2026:39304RHSA-2026:39317RLSA-2026:36734RLSA-2026:39317UBUNTU-CVE-2025-6170
Also known as
USN-7694-1

Charts affected

821 by stars
ChartLatestAffected imagesRadar Score
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6

Open the chart page →

5,067
oesopsmxVerified publisher4.0.327 of 25See more

oes opsmx 4.0.32

7 of the 25 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6

Open the chart page →

107,811
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.6

Open the chart page →

2,995
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

5,435
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

13,521
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

8,690
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

6,328
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

24,488
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2

Open the chart page →

841
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

5,852
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,052
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

6,085
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.6

Open the chart page →

4,714
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
libxml2@2.9.13-9.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

1,819
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

13,635
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
libxml2@2.9.4+dfsg1-6.1ubuntu1.6
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

12,046
upcloud-csiankra-chartsVerified publisher0.4.01 of 8See more

upcloud-csi ankra-charts 0.4.0

1 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

14,917
anteonanteonVerified publisher2.6.41 of 13See more

anteon anteon 2.6.4

1 of the 13 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

22,202
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

7,740
dltbrokerassist-iot-distributed-broker0.2.02 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

2 of the 9 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9
hyperledger/fabric-couchdb:0.4.15f6c724592abf
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.02 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

2 of the 9 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9
hyperledger/fabric-couchdb:0.4.15f6c724592abf
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

77,687
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

13,145
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

7,190
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

7,190
camel-dashboard-operatorcamel-dashboardVerified publisher0.1.01 of 1See more

camel-dashboard-operator camel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.6

Open the chart page →

520
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

15,863
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,971
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

36,094
cockroachdb-chartcockroachdbv226.3.11 of 1See more

cockroachdb-chart cockroachdbv2 26.3.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
libxml2@2.9.7-21.el8_10.4
0:2.9.7-21.el8_10.6

Open the chart page →

703
cockroachdb-operator-chartcockroachdbv21.0.01 of 1See more

cockroachdb-operator-chart cockroachdbv2 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
cockroachdb/cockroachdb-operator-v2:v1.0.04335d8bcbd3d
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

825
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,724
cp-schema-registrycp-schema-registryVerified publisher1.0.01 of 1See more

cp-schema-registry cp-schema-registry 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

1,864
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6

Open the chart page →

6,473
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

13,761
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

5,398
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

4,759
dbrepodbrepo1.13.36 of 25See more

dbrepo dbrepo 1.13.3

6 of the 25 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/postgresql:17.0.0-debian-12-r9d885ac277163
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

52,635
developer-operatordeveloper-operatorVerified publisher2.1.21 of 1See more

developer-operator developer-operator 2.1.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
libxml2@2.9.13-10.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

1,828
clairdevtron0.1.141 of 2See more

clair devtron 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

6,237
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

10,858
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

18,376
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
libxml2@2.9.14+dfsg-1.3ubuntu3.2
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

5,670
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6

Open the chart page →

31,510
eoapieoapiOfficialVerified publisher0.16.21 of 7See more

eoapi eoapi 0.16.2

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.27.4-alpine62a904036bfc
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

6,250
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

11,458
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,333
zabbix-server-mysqlfermosit3.0.22 of 4See more

zabbix-server-mysql fermosit 3.0.2

2 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

12,840
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

17,377
games-on-whalesgeek-cookbookVerified publisher1.8.23 of 7See more

games-on-whales geek-cookbook 1.8.2

3 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

35,305
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

15,653

Container images carrying it

894 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
2
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
libxml2@2.9.13-6.el9_5.2
0:2.9.13-14.el9_8.2
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
libxml2@2.13.8-r0
2.13.9-r0
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
libxml2@2.13.4-r5
2.13.9-r0
2
1dev/server:11.9.0cd5b12fe5471
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.4
1
5200710/hadoop:3.2.3-java8092d3088a5fb
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
aerospike/aerospike-kubernetes-operator:4.5.070a9eeb991b8
libxml2@2.12.5-10.el10_2.1
0:2.12.5-10.el10_2.2
1
airbyte/pod-sweeper:1.5.198d2c39d512e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
akaunting/akaunting:3.0.1552811b36ec3a
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u3
1
akeyless/base-rhel:0.0.14ba8900a0061
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
libxml2@2.13.8-r0
2.13.9-r0
1
allegroai/clearml:2.0.0-613713ae38f7daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
libxml2@2.9.4+dfsg1-6.1ubuntu1.6
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
alpine/k8s:1.31.106dbe6f391eda
libxml2@2.13.8-r0
2.13.9-r0
1
alpine/k8s:1.31.137a319b15cfc9
libxml2@2.13.8-r0
2.13.9-r0
1
alpine/k8s:1.32.47e1e7d5b7a96
libxml2@2.13.4-r5
2.13.9-r0
1
alpine/k8s:1.31.49c4976d47656
libxml2@2.13.4-r3
2.13.9-r0
1
alpine/k8s:1.32.3eec354133193
libxml2@2.13.4-r5
2.13.9-r0
1
alquimiaai/studio:certification38a1f0341982
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.6
1
altinity/metrics-exporter:0.20.01a46d104406d
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.6
1
anchore/anchore-engine:v0.10.0bde9eedf639d
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
libxml2@2.9.7-5.el8
0:2.9.7-21.el8_10.6
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.8
1
andrianrf/backoffice:latest047a7837651e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.6
1
andrianrf/backoffice-be:latest6036614803d4
libxml2@2.9.13-3.el9_1
0:2.9.13-14.el9_8.2
1
andrianrf/iso-server:latest7da47f525c7d
libxml2@2.9.13-3.el9_1
0:2.9.13-14.el9_8.2
1
anguda/ant-media:2.5c435285fc241
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
anujdatar/cups:25.07.01685df04a643b
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
1
apache/airflow:2.8.4-python3.964e58748b6b9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
apache/airflow:2.8.1e5560ad0b86e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
apache/camel-k:1.10.43bb13d14f64a
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6
1
apache/nifi-registry:1.27.063b8e3e40742
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
apache/polaris:lateste66366e783f1
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
apachepulsar/pulsar:3.0.79c9947de139d
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
apachepulsar/pulsar:2.9.0d056c89b7131
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
apachepulsar/pulsar:2.8.2d538416d5afe
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.