StackRadar

CVE-2025-7425

High

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
732
of 17,787 indexed, latest versions
Container images
807
deployed by those charts
Fix available
2 of 4
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 732 of 17,787 indexed charts deploy, on 807 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+40 more2.9.1+dfsg1-3ubuntu4.13+esm10, 2.9.3+dfsg1-1ubuntu0.7+esm11, 2.9.4+dfsg1-6.1ubuntu1.9+esm6, 2.9.10+dfsg-5ubuntu0.20.04.10+esm3+4 more495
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+28 more0:2.9.1-6.el7_9.12, 0:2.9.7-21.el8_10.2, 0:2.9.13-11.el9_6, 2.13.8-3.1291
libxsltdeb1.1.39-0exp1build1, 1.1.39-0exp1ubuntu0.24.04.2, 1.1.39-0exp1ubuntu0.24.04.3, 1.1.45-0.1no fix listed24
libxsltapk1.1.45-r3no fix listed3
OSV records
CGA-393j-mrfx-mmvpRHSA-2025:12447RHSA-2025:12450RHSA-2025:13464RLSA-2025:12447UBUNTU-CVE-2025-7425DSA-5990-1openSUSE-SU-2025:15363-1
Also known as
CGA-j6x2-xhvh-29pw, RHSA-2025:13308, RHSA-2025:13310, RHSA-2025:13311, RHSA-2025:13312, RHSA-2025:13313, RHSA-2025:13314, USN-7852-1, USN-7852-2, USN-7896-1

Charts affected

732 by stars
ChartLatestAffected imagesRadar Score
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

13,551
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

12,222
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

9,698
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

14,283
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,958
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

12,076
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

27,949
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

19,503
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

15,730
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

11,807
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

10,379
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

24,293
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

26,944
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

11,861
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

17,929
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

3,246
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,170
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

49,025
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

15,722
mimir-openshift-experimentalgrafana2.1.02 of 4See more

mimir-openshift-experimental grafana 2.1.0

2 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2

Open the chart page →

17,759
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
libxml2@2.9.13-10.el9_6
0:2.9.13-11.el9_6

Open the chart page →

8,188
hatchet-hahatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-ha hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

7,344
hatchet-stackhatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-stack hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

7,344
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

24,995
hello-worldhello-world-pponyVerified publisher0.3.01 of 1See more

hello-world hello-world-ppony 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/nginx:1.25.49ff236ed47fe
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,839
ditto-operatorhelm-chartsVerified publisher0.3.01 of 1See more

ditto-operator helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

2,674
hawkbit-operatorhelm-chartsVerified publisher0.1.41 of 1See more

hawkbit-operator helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ctron/hawkbit-operator:0.1.48fdea8f76499
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2

Open the chart page →

5,792
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

24,161
streamsheetshelm-chartsVerified publisher0.2.35 of 8See more

streamsheets helm-charts 0.2.3

5 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

89,959
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
dannielkil/book-frontend:latest937993927694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,122
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

18,813
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,653
netboxhelmforgeVerified publisher2.0.11 of 4See more

netbox helmforge 2.0.1

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
libxslt@1.1.45-0.1
no fix listed

Open the chart page →

4,243
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,607
openaevhelm-openbasVerified publisher2.0.51 of 7See more

openaev helm-openbas 2.0.5

1 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

7,437
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

25,017
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

6,015
samplehelmapphelmtraining3.0.01 of 1See more

samplehelmapp helmtraining 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
praravind1801/helmimages:3.0.0f29d637b9ce1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,973
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

14,290
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

16,384
eoloplanthttpd-eoloplant0.1.02 of 7See more

eoloplant httpd-eoloplant 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

32,205
ibm-app-navigatoribm-charts1.0.15 of 5See more

ibm-app-navigator ibm-charts 1.0.1

5 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/app-nav-controller:1.0.1ee4624ba513d
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/app-nav-init:1.0.1240ff499eb5b
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/app-nav-ui:1.0.1e2a86997b36b
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/app-nav-was-controller:1.0.1a6748792da26
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.06 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

6 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

39,349
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2

Open the chart page →

12,461
ibm-open-libertyibm-charts1.10.01 of 1See more

ibm-open-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

2,063
ibm-open-liberty-springibm-charts1.10.01 of 1See more

ibm-open-liberty-spring ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

2,063
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

12,611
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

25,160
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

4,505
ibm-websphere-libertyibm-charts1.10.01 of 1See more

ibm-websphere-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

2,063

Container images carrying it

807 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.6
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libxml2@2.9.14+dfsg-1.3ubuntu3
libxslt@1.1.39-0exp1build1
2.9.14+dfsg-1.3ubuntu3.6
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
libxml2@2.9.1-6.el7_9.6
0:2.9.1-6.el7_9.12
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
libxml2@2.9.13-6.el9_5.2
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
libxml2@2.9.13-6.el9_5.1
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
libxml2@2.9.13-6.el9_5.2
0:2.9.13-11.el9_6
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm11
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
libxml2@2.9.13-9.el9_6
0:2.9.13-11.el9_6
1
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
libxslt@1.1.45-0.1
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.10
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.