StackRadar

CVE-2025-7425

High

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
732
of 17,787 indexed, latest versions
Container images
807
deployed by those charts
Fix available
2 of 4
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 732 of 17,787 indexed charts deploy, on 807 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+40 more2.9.1+dfsg1-3ubuntu4.13+esm10, 2.9.3+dfsg1-1ubuntu0.7+esm11, 2.9.4+dfsg1-6.1ubuntu1.9+esm6, 2.9.10+dfsg-5ubuntu0.20.04.10+esm3+4 more495
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+28 more0:2.9.1-6.el7_9.12, 0:2.9.7-21.el8_10.2, 0:2.9.13-11.el9_6, 2.13.8-3.1291
libxsltdeb1.1.39-0exp1build1, 1.1.39-0exp1ubuntu0.24.04.2, 1.1.39-0exp1ubuntu0.24.04.3, 1.1.45-0.1no fix listed24
libxsltapk1.1.45-r3no fix listed3
OSV records
CGA-393j-mrfx-mmvpRHSA-2025:12447RHSA-2025:12450RHSA-2025:13464RLSA-2025:12447UBUNTU-CVE-2025-7425DSA-5990-1openSUSE-SU-2025:15363-1
Also known as
CGA-j6x2-xhvh-29pw, RHSA-2025:13308, RHSA-2025:13310, RHSA-2025:13311, RHSA-2025:13312, RHSA-2025:13313, RHSA-2025:13314, USN-7852-1, USN-7852-2, USN-7896-1

Charts affected

732 by stars
ChartLatestAffected imagesRadar Score
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

13,551
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

12,222
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

9,698
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

14,283
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,958
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

12,076
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

27,949
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

19,503
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

15,730
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

11,807
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

10,379
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

24,293
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

26,944
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

11,861
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

17,929
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

3,246
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,170
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

49,025
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

15,722
mimir-openshift-experimentalgrafana2.1.02 of 4See more

mimir-openshift-experimental grafana 2.1.0

2 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2

Open the chart page →

17,759
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
libxml2@2.9.13-10.el9_6
0:2.9.13-11.el9_6

Open the chart page →

8,188
hatchet-hahatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-ha hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

7,344
hatchet-stackhatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-stack hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

7,344
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

24,995
hello-worldhello-world-pponyVerified publisher0.3.01 of 1See more

hello-world hello-world-ppony 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/nginx:1.25.49ff236ed47fe
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,839
ditto-operatorhelm-chartsVerified publisher0.3.01 of 1See more

ditto-operator helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

2,674
hawkbit-operatorhelm-chartsVerified publisher0.1.41 of 1See more

hawkbit-operator helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ctron/hawkbit-operator:0.1.48fdea8f76499
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2

Open the chart page →

5,792
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

24,161
streamsheetshelm-chartsVerified publisher0.2.35 of 8See more

streamsheets helm-charts 0.2.3

5 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

89,959
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
dannielkil/book-frontend:latest937993927694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,122
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

18,813
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,653
netboxhelmforgeVerified publisher2.0.11 of 4See more

netbox helmforge 2.0.1

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
libxslt@1.1.45-0.1
no fix listed

Open the chart page →

4,243
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,607
openaevhelm-openbasVerified publisher2.0.51 of 7See more

openaev helm-openbas 2.0.5

1 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

7,437
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

25,017
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

6,015
samplehelmapphelmtraining3.0.01 of 1See more

samplehelmapp helmtraining 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
praravind1801/helmimages:3.0.0f29d637b9ce1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,973
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

14,290
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

16,384
eoloplanthttpd-eoloplant0.1.02 of 7See more

eoloplant httpd-eoloplant 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

32,205
ibm-app-navigatoribm-charts1.0.15 of 5See more

ibm-app-navigator ibm-charts 1.0.1

5 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/app-nav-controller:1.0.1ee4624ba513d
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/app-nav-init:1.0.1240ff499eb5b
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/app-nav-ui:1.0.1e2a86997b36b
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/app-nav-was-controller:1.0.1a6748792da26
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.06 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

6 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

39,349
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2

Open the chart page →

12,461
ibm-open-libertyibm-charts1.10.01 of 1See more

ibm-open-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

2,063
ibm-open-liberty-springibm-charts1.10.01 of 1See more

ibm-open-liberty-spring ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

2,063
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

12,611
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

25,160
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

4,505
ibm-websphere-libertyibm-charts1.10.01 of 1See more

ibm-websphere-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.12

Open the chart page →

2,063

Container images carrying it

807 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm6
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
libxml2@2.9.13-10.el9_6
0:2.9.13-11.el9_6
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
libxml2@2.9.13-5.el9_3
0:2.9.13-11.el9_6
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.6
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.6
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.6
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
libxml2@2.9.7-19.el8_10
0:2.9.7-21.el8_10.2
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
1
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
libxml2@2.9.4+dfsg1-6.1ubuntu1.8
2.9.4+dfsg1-6.1ubuntu1.9+esm6
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libxml2@2.9.10+dfsg-5ubuntu0.20.04.9
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
ghcr.io/kubelauncher/postgresql1a27e11e5925
libxslt@1.1.45-0.1
no fix listed
1
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.