StackRadar

CVE-2025-6170

Low

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
821
of 17,781 indexed, latest versions
Container images
894
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 821 of 17,781 indexed charts deploy, on 894 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more485
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+32 more0:2.9.7-21.el8_10.6, 0:2.9.13-14.el9_8.2, 0:2.12.5-10.el10_2.2345
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r064
OSV records
ALPINE-CVE-2025-6170DEBIAN-CVE-2025-6170RHSA-2026:36734RHSA-2026:39304RHSA-2026:39317RLSA-2026:36734RLSA-2026:39317UBUNTU-CVE-2025-6170
Also known as
USN-7694-1

Charts affected

821 by stars
ChartLatestAffected imagesRadar Score
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.6

Open the chart page →

5,958
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

14,559
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
libxml2@2.9.13-10.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

1,797
mariadbcowboysysopVerified publisher20.4.21 of 1See more

mariadb cowboysysop 20.4.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

3,009
postgresqlcowboysysopVerified publisher15.5.71 of 1See more

postgresql cowboysysop 15.5.7

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r14cc55da2fa366
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,770
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
confluentinc/cp-zookeeper:6.1.078c190f4472c
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6

Open the chart page →

58,857
iam-zencryptexlabsVerified publisher0.12.231 of 4See more

iam-zen cryptexlabs 0.12.23

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

3,860
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opencsghq/kubectl:latestb6d87e1048c2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opencsghq/csgship-portal:v1.2.1865814dc87a1
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

11,335
cypikcypik-app0.1.01 of 2See more

cypik cypik-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,503
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

16,604
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

5,398
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
libxml2@2.9.13-10.el9_6
0:2.9.13-14.el9_8.2

Open the chart page →

3,547
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

22,405
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

6,172
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm4

Open the chart page →

24,335
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

7,486
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,090
dellhw_exporterdellhw-exporterVerified publisher1.0.11 of 1See more

dellhw_exporter dellhw-exporter 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2

Open the chart page →

3,191
prometheus-dellhw-exporterdellhw-exporterVerified publisher1.3.01 of 1See more

prometheus-dellhw-exporter dellhw-exporter 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2

Open the chart page →

1,812
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

14,856
clamav-apidevhatVerified publisher1.0.11 of 1See more

clamav-api devhat 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
libxml2@2.13.4-r3
2.13.9-r0

Open the chart page →

2,097
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,607
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
libxml2@2.9.13+dfsg-1ubuntu0.2
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

12,949
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

68,240
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

3,891
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,607
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
libxml2@2.9.13+dfsg-1ubuntu0.2
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

12,949
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

68,240
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

32,902
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

3,891
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,046
direktivdirektivVerified publisher0.10.01 of 6See more

direktiv direktiv 0.10.0

1 of the 6 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
libxml2@2.13.4-r3
2.13.9-r0

Open the chart page →

3,470
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,141
ownclouddjjudas21Verified publisher0.3.231 of 3See more

owncloud djjudas21 0.3.23

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,035
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4

Open the chart page →

16,954
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

14,627
dnation-kubernetes-monitoring-stackdnationcloud4.0.23 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

3 of the 17 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
libxml2@2.13.4-r6
2.13.9-r0
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6

Open the chart page →

21,641
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2

Open the chart page →

3,167
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libxml2@2.9.13+dfsg-1ubuntu0.2
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

24,917
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
libxml2@2.9.13-2.el9
0:2.9.13-14.el9_8.2
quay.io/keycloak/keycloak:20.0054ef67eb7da
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6

Open the chart page →

55,666
drogue-cloud-examplesdrogue-iotVerified publisher0.7.114 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

4 of the 6 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.8
ghcr.io/ctron/kubectl:1.25e37d61b5277c
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

30,699
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6

Open the chart page →

6,915
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

9,244
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

4,586

Container images carrying it

894 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
2
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
libxml2@2.9.13-6.el9_5.2
0:2.9.13-14.el9_8.2
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
libxml2@2.13.8-r0
2.13.9-r0
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
libxml2@2.13.4-r5
2.13.9-r0
2
1dev/server:11.9.0cd5b12fe5471
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.4
1
5200710/hadoop:3.2.3-java8092d3088a5fb
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
aerospike/aerospike-kubernetes-operator:4.5.070a9eeb991b8
libxml2@2.12.5-10.el10_2.1
0:2.12.5-10.el10_2.2
1
airbyte/pod-sweeper:1.5.198d2c39d512e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
akaunting/akaunting:3.0.1552811b36ec3a
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u3
1
akeyless/base-rhel:0.0.14ba8900a0061
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
libxml2@2.13.8-r0
2.13.9-r0
1
allegroai/clearml:2.0.0-613713ae38f7daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
libxml2@2.9.4+dfsg1-6.1ubuntu1.6
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
alpine/k8s:1.31.106dbe6f391eda
libxml2@2.13.8-r0
2.13.9-r0
1
alpine/k8s:1.31.137a319b15cfc9
libxml2@2.13.8-r0
2.13.9-r0
1
alpine/k8s:1.32.47e1e7d5b7a96
libxml2@2.13.4-r5
2.13.9-r0
1
alpine/k8s:1.31.49c4976d47656
libxml2@2.13.4-r3
2.13.9-r0
1
alpine/k8s:1.32.3eec354133193
libxml2@2.13.4-r5
2.13.9-r0
1
alquimiaai/studio:certification38a1f0341982
libxml2@2.9.13-14.el9_7
0:2.9.13-14.el9_8.2
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.6
1
altinity/metrics-exporter:0.20.01a46d104406d
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.6
1
anchore/anchore-engine:v0.10.0bde9eedf639d
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
libxml2@2.9.7-5.el8
0:2.9.7-21.el8_10.6
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.8
1
andrianrf/backoffice:latest047a7837651e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.6
1
andrianrf/backoffice-be:latest6036614803d4
libxml2@2.9.13-3.el9_1
0:2.9.13-14.el9_8.2
1
andrianrf/iso-server:latest7da47f525c7d
libxml2@2.9.13-3.el9_1
0:2.9.13-14.el9_8.2
1
anguda/ant-media:2.5c435285fc241
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
anujdatar/cups:25.07.01685df04a643b
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
1
apache/airflow:2.8.4-python3.964e58748b6b9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
apache/airflow:2.8.1e5560ad0b86e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
apache/camel-k:1.10.43bb13d14f64a
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6
1
apache/nifi-registry:1.27.063b8e3e40742
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
apache/polaris:lateste66366e783f1
libxml2@2.9.13-14.el9_8.1
0:2.9.13-14.el9_8.2
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
apachepulsar/pulsar:3.0.79c9947de139d
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
apachepulsar/pulsar:2.9.0d056c89b7131
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
apachepulsar/pulsar:2.8.2d538416d5afe
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.