StackRadar

CVE-2025-6170

Low

Advisory

Published 16 Jun 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
827
of 17,787 indexed, latest versions
Container images
898
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 827 of 17,787 indexed charts deploy, on 898 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+35 more2.9.1+dfsg1-3ubuntu4.13+esm8, 2.9.3+dfsg1-1ubuntu0.7+esm9, 2.9.4+dfsg1-6.1ubuntu1.9+esm4, 2.9.10+dfsg-5ubuntu0.20.04.10+esm1+3 more486
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+32 more0:2.9.7-21.el8_10.6, 0:2.9.13-14.el9_8.2, 0:2.12.5-10.el10_2.2346
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r02.13.9-r066
OSV records
ALPINE-CVE-2025-6170DEBIAN-CVE-2025-6170RHSA-2026:36734RHSA-2026:39304RHSA-2026:39317RLSA-2026:36734RLSA-2026:39317UBUNTU-CVE-2025-6170
Also known as
USN-7694-1

Charts affected

827 by stars
ChartLatestAffected imagesRadar Score
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6

Open the chart page →

4,960
opencloudunxwaresVerified publisher0.2.37 of 13See more

opencloud unxwares 0.2.3

7 of the 13 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.4
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

45,239
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm9

Open the chart page →

15,330
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

14,358
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

4,768
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,795
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
libxml2@2.13.4-r5
2.13.9-r0

Open the chart page →

2,076
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
libxml2@2.13.8-r0
2.13.9-r0

Open the chart page →

twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

13,459
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

11,405
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

9,130
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

9,130
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

28,605
giteawenerme12.7.02 of 4See more

gitea wenerme 12.7.0

2 of the 4 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

8,811
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1

Open the chart page →

15,230
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6

Open the chart page →

6,138
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
libxml2@2.9.7-21.el8_10.2
0:2.9.7-21.el8_10.6

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,624
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.6

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3

Open the chart page →

7,673
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-6170.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6

Open the chart page →

3,697

Container images carrying it

898 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/nginx:1.25.167f9a4f10d14
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
library/nginx:1.25.49ff236ed47fe
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
library/nginx:1.27.3fb197595ebe7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
library/postgres:17.4304ab8135187
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
library/postgres:16.6557fea37a744
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
library/postgres:17.5-alpine6567bca8d7bc
libxml2@2.13.8-r0
2.13.9-r0
1
library/postgres:17.4-alpine7062a2109c4b
libxml2@2.13.4-r3
2.13.9-r0
1
library/postgres:12-alpine7c8f48705831
libxml2@2.13.4-r3
2.13.9-r0
1
library/postgres:17.2-alpine7e5df973a748
libxml2@2.13.4-r3
2.13.9-r0
1
library/postgres:15.38775adb39f0d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
library/postgres:13.12ced3ba927f4c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
library/postgres:17.5-bookwormfbcea1bd13b6
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
1
library/python:3.8d41127070014
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
library/wordpress:6.4.3-apache8ae66efb09a2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
linuxserver/deluge:18.04.10ac871624394
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
linuxserver/jellyfin:10.7.72427dde159a2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
lis314/project-zomboid-docker:latestaa2089c37920
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
livekit/ingress:v1.2.21ab01641b366
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
localstack/localstack:3.19d278167f2b7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
loeken/radarr:5.27.0-nightlya24409d3846d
libxml2@2.13.4-r6
2.13.9-r0
1
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm4
1
mariadb/maxscale:23.02.256c5e0908148
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.6
1
mathnao/certs:2.1.3b900e6b64684
libxml2@2.13.4-r6
2.13.9-r0
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
mavrick1/kubestellar-f:latest56bd8eaa53a4
libxml2@2.13.4-r5
2.13.9-r0
1
mbround18/valheim:3.1.070bd4da591cd
libxml2@2.9.13+dfsg-1ubuntu0.6
2.9.13+dfsg-1ubuntu0.8
1
mediagis/nominatim:3.7c15e941485ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm1
1
mediagis/nominatim:4.2d0eae7b51374
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.8
1
merlos/zookeeper:3.9.3a38fc7e09ed7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
middlewareeng/middleware:0.3.1747d880812f1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
minio/kes:v0.22.255f3aef5803e
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.6
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.6
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.6
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.6
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.6
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.6
1
minio/operator:v5.0.9170b154d2c61
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.6
1
minio/operator:v4.1.02adc5be088f5
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.6
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
mlikiowa/napcat-docker:latest1336a777f9a4
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.8
1
moreillon/api-proxy:latestd7d4a5463525
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
moreillon/camera-viewer:lateste418cc694bd5
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
moreillon/food-manager:lateste8fd856e593d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1
moreillon/user-manager-front:v5.1.06597e6b98d21
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.