StackRadar

CVE-2025-7425

High

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
734
of 17,781 indexed, latest versions
Container images
809
deployed by those charts
Fix available
2 of 4
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 734 of 17,781 indexed charts deploy, on 809 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+40 more2.9.1+dfsg1-3ubuntu4.13+esm10, 2.9.3+dfsg1-1ubuntu0.7+esm11, 2.9.4+dfsg1-6.1ubuntu1.9+esm6, 2.9.10+dfsg-5ubuntu0.20.04.10+esm3+4 more495
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+28 more0:2.9.1-6.el7_9.12, 0:2.9.7-21.el8_10.2, 0:2.9.13-11.el9_6, 2.13.8-3.1291
libxsltdeb1.1.39-0exp1build1, 1.1.39-0exp1ubuntu0.24.04.2, 1.1.39-0exp1ubuntu0.24.04.3, 1.1.45-0.1no fix listed25
libxsltapk1.1.45-r3no fix listed4
OSV records
CGA-393j-mrfx-mmvpRHSA-2025:12447RHSA-2025:12450RHSA-2025:13464RLSA-2025:12447UBUNTU-CVE-2025-7425DSA-5990-1openSUSE-SU-2025:15363-1
Also known as
CGA-j6x2-xhvh-29pw, RHSA-2025:13308, RHSA-2025:13310, RHSA-2025:13311, RHSA-2025:13312, RHSA-2025:13313, RHSA-2025:13314, USN-7852-1, USN-7852-2, USN-7896-1

Charts affected

734 by stars
ChartLatestAffected imagesRadar Score
headwind-mdmchristianhuthVerified publisher5.10.11 of 2See more

headwind-mdm christianhuth 5.10.1

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,870
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,106
seafiledatamateVerified publisher0.6.02 of 6See more

seafile datamate 0.6.0

2 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
datamate/seafile-professional:11.0.202dd66b722464
libxml2@2.9.13+dfsg-1ubuntu0.8
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

27,267
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,170
infrahubinfrahubVerified publisher4.33.21 of 5See more

infrahub infrahub 4.33.2

1 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

10,428
plexk8s-home-lab-repo7.3.11 of 1See more

plex k8s-home-lab-repo 7.3.1

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed

Open the chart page →

1,685
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

6,307
keycloak-operatorkeycloak-operatorVerified publisher0.0.41 of 1See more

keycloak-operator keycloak-operator 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2

Open the chart page →

4,652
percona-xtradb-clusterkfirfer1.5.101 of 3See more

percona-xtradb-cluster kfirfer 1.5.10

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

4,957
kubeflowkubeflow1.6.22 of 45See more

kubeflow kubeflow 1.6.2

2 of the 45 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/python:3.7eedf63967cdb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

96,941
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,779
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

7,949
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

8,722
rke2-multusrke2-charts3.7.1-build20210416012 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

2 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
rancher/hardened-cni-plugins:v0.9.1-build20210414be3c1d469bf7
libxml2@2.9.1-6.el7.5
0:2.9.1-6.el7_9.12
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
libxml2@2.9.1-6.el7.5
0:2.9.1-6.el7_9.12

Open the chart page →

4,519
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,746
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
libxslt@1.1.45-0.1
no fix listed

Open the chart page →

1,201
limesurveyarea-42Verified publisher0.3.931 of 2See more

limesurvey area-42 0.3.93

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

4,668
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2

Open the chart page →

9,052
coder-observabilitycoder-observabilityVerified publisher0.7.32 of 21See more

coder-observability coder-observability 0.7.3

2 of the 21 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

24,700
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6

Open the chart page →

7,450
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

17,404
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2

Open the chart page →

3,080
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

28,839
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
libxml2@2.9.7-13.el8_6.2
0:2.9.7-21.el8_10.2

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
libxml2@2.9.7-13.el8_6.2
0:2.9.7-21.el8_10.2

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
libxml2@2.9.7-13.el8_6.2
0:2.9.7-21.el8_10.2

Open the chart page →

13,874
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

22,773
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

10,598
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

13,950
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

9,627
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

10,628
hpe-cosi-driverhpe-storageVerified publisher2.0.01 of 2See more

hpe-cosi-driver hpe-storage 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
libxml2@2.9.13-6.el9_5.2
0:2.9.13-11.el9_6

Open the chart page →

1,648
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

10,530
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.6

Open the chart page →

4,309
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed

Open the chart page →

4,477
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

7,337
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

7,273
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

11,582
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

15,330
memgraph-high-availabilitymemgraphVerified publisher1.4.01 of 2See more

memgraph-high-availability memgraph 1.4.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.0a1dc375774ed
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed

Open the chart page →

1,373
kubecostmesosphere-stable0.37.51 of 9See more

kubecost mesosphere-stable 0.37.5

1 of the 9 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

17,693
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2

Open the chart page →

3,793
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.042a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

4,060
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

5,067
oesopsmxVerified publisher4.0.322 of 25See more

oes opsmx 4.0.32

2 of the 25 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm11
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

107,811
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,435
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

13,521
nominatimrobjuz6.4.12 of 4See more

nominatim robjuz 6.4.1

2 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
mediagis/nominatim:5.3.27923a8e67197
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed

Open the chart page →

8,690
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

24,488
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

7,052

Container images carrying it

809 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.10
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.6
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libxml2@2.9.14+dfsg-1.3ubuntu3
libxslt@1.1.39-0exp1build1
2.9.14+dfsg-1.3ubuntu3.6
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
libxml2@2.9.1-6.el7_9.6
0:2.9.1-6.el7_9.12
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
libxml2@2.9.13-6.el9_5.2
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
libxml2@2.9.13-6.el9_5.1
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
libxml2@2.9.13-6.el9_5.2
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm11
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
libxml2@2.9.13-9.el9_6
0:2.9.13-11.el9_6
1
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
libxslt@1.1.45-0.1
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.10
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.