StackRadar

CVE-2025-7425

High

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
738
of 17,787 indexed, latest versions
Container images
812
deployed by those charts
Fix available
2 of 4
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 738 of 17,787 indexed charts deploy, on 812 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+40 more2.9.1+dfsg1-3ubuntu4.13+esm10, 2.9.3+dfsg1-1ubuntu0.7+esm11, 2.9.4+dfsg1-6.1ubuntu1.9+esm6, 2.9.10+dfsg-5ubuntu0.20.04.10+esm3+4 more496
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+28 more0:2.9.1-6.el7_9.12, 0:2.9.7-21.el8_10.2, 0:2.9.13-11.el9_6, 2.13.8-3.1293
libxsltdeb1.1.39-0exp1build1, 1.1.39-0exp1ubuntu0.24.04.2, 1.1.39-0exp1ubuntu0.24.04.3, 1.1.45-0.1no fix listed25
libxsltapk1.1.45-r3, 1.1.45-r4no fix listed4
OSV records
CGA-393j-mrfx-mmvpRHSA-2025:12447RHSA-2025:12450RHSA-2025:13464RLSA-2025:12447UBUNTU-CVE-2025-7425DSA-5990-1openSUSE-SU-2025:15363-1
Also known as
CGA-j6x2-xhvh-29pw, RHSA-2025:13308, RHSA-2025:13310, RHSA-2025:13311, RHSA-2025:13312, RHSA-2025:13313, RHSA-2025:13314, USN-7852-1, USN-7852-2, USN-7896-1

Charts affected

738 by stars
ChartLatestAffected imagesRadar Score
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,839
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.03ba6e6f11388
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

15,408
smilencsaVerified publisher1.1.07 of 23See more

smile ncsa 1.1.0

7 of the 23 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
2.9.4+dfsg1-6.1ubuntu1.9+esm6
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
socialmediamacroscope/image_crawler:0.1.2f508216be63c
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
2.9.4+dfsg1-6.1ubuntu1.9+esm6
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
socialmediamacroscope/preprocessing:0.1.3ca863306314b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

109,485
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.2

Open the chart page →

6,982
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.6

Open the chart page →

7,413
nfl-walletnfl-walletVerified publisher0.1.33 of 4See more

nfl-wallet nfl-wallet 0.1.3

3 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2

Open the chart page →

13,047
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

4,731
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

4,731
minio-directpvnineinfra-charts4.0.81 of 5See more

minio-directpv nineinfra-charts 4.0.8

1 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/minio/directpv:v4.0.84560083eb77d
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2

Open the chart page →

7,035
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2

Open the chart page →

3,418
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,831
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

22,713
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

13,331
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

13,405
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

13,387
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
libxml2@2.9.1+dfsg1-3ubuntu4.3
2.9.1+dfsg1-3ubuntu4.13+esm10

Open the chart page →

41,455
nexus2novum-rgi-charts0.1.11 of 1See more

nexus2 novum-rgi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
sonatype/nexus:oss6bc88b51d4d7
libxml2@2.9.1-6.el7_9.6
0:2.9.1-6.el7_9.12

Open the chart page →

3,219
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

27,667
cmsmsoleds-helm-chartsVerified publisher0.1.61 of 1See more

cmsms oleds-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

2,850
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

9,059
apicurioone-acre-fundVerified publisher2.3.03 of 5See more

apicurio one-acre-fund 2.3.0

3 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2

Open the chart page →

18,666
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.6

Open the chart page →

6,083
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,736
opentickopenchartVerified publisher0.1.01 of 1See more

opentick openchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/nginx:1.25.5a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,688
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.2

Open the chart page →

18,023
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm6
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

63,277
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11
omecproject/onos-progran:1.0.05715e5648aa0
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm11
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

88,616
comac-cuopencord0.1.11 of 4See more

comac-cu opencord 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libxml2@2.9.4+dfsg1-6.1ubuntu1
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

8,053
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

26,234
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

42,662
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

29,158
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libxml2@2.9.4+dfsg1-6.1ubuntu1
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

15,660
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm6
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

14,550
omec-control-planeopencord0.1.313 of 8See more

omec-control-plane opencord 0.1.31

3 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
omecproject/mme-exporter:paging-latestbcc5f19fd676
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm6
omecproject/openmme:master-latest64776cb9edb3
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

40,795
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

38,889
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

11,003
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2

Open the chart page →

7,457
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2

Open the chart page →

11,795
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2
andrianrf/backoffice-be:latest6036614803d4
libxml2@2.9.13-3.el9_1
0:2.9.13-11.el9_6
andrianrf/iso-server:latest7da47f525c7d
libxml2@2.9.13-3.el9_1
0:2.9.13-11.el9_6

Open the chart page →

34,721
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6

Open the chart page →

18,991
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6

Open the chart page →

13,034
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2

Open the chart page →

16,554
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.2

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2

Open the chart page →

19,449
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
libxml2@2.9.13-3.el9_2.1
0:2.9.13-11.el9_6

Open the chart page →

8,634
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2

Open the chart page →

13,608
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2

Open the chart page →

13,570

Container images carrying it

812 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
weblate/weblate:2026.9.1.0990720d1737a
libxslt@1.1.45-0.1
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.10
1
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.10
1
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.10
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.6
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libxml2@2.9.14+dfsg-1.3ubuntu3
libxslt@1.1.39-0exp1build1
2.9.14+dfsg-1.3ubuntu3.6
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
libxml2@2.9.1-6.el7_9.6
0:2.9.1-6.el7_9.12
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
libxml2@2.9.13-6.el9_5.2
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
libxml2@2.9.13-6.el9_5.1
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
libxml2@2.9.13-6.el9_5.2
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm11
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
libxml2@2.9.13-9.el9_6
0:2.9.13-11.el9_6
1
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
libxslt@1.1.45-0.1
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.10
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.