StackRadar

CVE-2025-6170

Low

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
822
of 17,787 indexed, latest versions
Container images
894
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 822 of 17,787 indexed charts deploy, on 894 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more485
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+32 more0:2.9.7-21.el8_10.6, 0:2.9.13-14.el9_8.2, 0:2.12.5-10.el10_2.2345
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r064
OSV records
ALPINE-CVE-2025-6170DEBIAN-CVE-2025-6170RHSA-2026:36734RHSA-2026:39304RHSA-2026:39317RLSA-2026:36734RLSA-2026:39317UBUNTU-CVE-2025-6170
Also known as
USN-7694-1

Charts affected

822 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

4,768
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,795
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

2,076
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

13,459
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

11,405
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

9,130
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

9,130
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

28,605
giteawenerme12.7.02 of 4See more

gitea wenerme 12.7.0

2 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

8,811
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

15,230
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

6,138
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
libxml2@2.9.7-21.el8_10.2
0:2.9.7-21.el8_10.6

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,624
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.6

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,673
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6

Open the chart page →

3,697

Container images carrying it

894 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
bitnami/mariadb:11.7.216a7dae804fb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
bnjbvr/kresus:0.22.137e216b182c8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
bsgrigorov/helm-operator:latest45ab095f09c8
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
libxml2@2.13.8-r0
2.13.9-r0
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
castopod/castopod:1.12.101fd37280cbb2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
libxml2@2.13.4-r3
2.13.9-r0
1
chetangautamm/repo:sipp.v3e7f7049e1544
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
cheyang/distributed-tf:1.6.046cc34755493
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm9
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
libxml2@2.13.8-r0
2.13.9-r0
1
chriseaton/adventureworks:latest54c3384ce701
libxml2@2.9.13+dfsg-1ubuntu0.6
2.9.13+dfsg-1ubuntu0.8
1
ckulka/baikal:0.10.1-nginx434bdd162247
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
1
cleveritcz/opencve:1.5.0c75c1636e0b7
libxml2@2.9.13-5.el9_3
0:2.9.13-14.el9_8.2
1
cloudve/janis-terminal:latestaf56e77ca587
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
cockroachdb/cockroach:v22.2.91116820f4134
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
1
cockroachdb/cockroachdb-operator-v2:v1.0.04335d8bcbd3d
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_8.2
1
cockroachdb/cockroach-operator:v2.1.0983312754620
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
1
coderenvs/coder-service:1.44.61deffc4670e6
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
1
coderenvs/timescale:1.44.676fd37fe6830
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
1
codetogether/codetogether:latest4348c8a38752
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_8.2
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.6
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
libxml2@2.9.7-19.el8_10
0:2.9.7-21.el8_10.6
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.6
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.6
1
confluentinc/cp-kafka:7.5.1dc9b972db002
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.6
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.6
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.6
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.6
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
countly/countly-server:25.05.4e3c238248f99
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
craftypath/sops-operator:v0.8.0402a0024c732
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6
1
ctron/hawkbit-operator:0.1.48fdea8f76499
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.6
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
dannielkil/book-frontend:latest937993927694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
ddosify/selfhosted_backend:3.2.93c11e3182652
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.