StackRadar

CVE-2025-7425

High

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
734
of 17,781 indexed, latest versions
Container images
809
deployed by those charts
Fix available
2 of 4
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 734 of 17,781 indexed charts deploy, on 809 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+40 more2.9.1+dfsg1-3ubuntu4.13+esm10, 2.9.3+dfsg1-1ubuntu0.7+esm11, 2.9.4+dfsg1-6.1ubuntu1.9+esm6, 2.9.10+dfsg-5ubuntu0.20.04.10+esm3+4 more495
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+28 more0:2.9.1-6.el7_9.12, 0:2.9.7-21.el8_10.2, 0:2.9.13-11.el9_6, 2.13.8-3.1291
libxsltdeb1.1.39-0exp1build1, 1.1.39-0exp1ubuntu0.24.04.2, 1.1.39-0exp1ubuntu0.24.04.3, 1.1.45-0.1no fix listed25
libxsltapk1.1.45-r3no fix listed4
OSV records
CGA-393j-mrfx-mmvpRHSA-2025:12447RHSA-2025:12450RHSA-2025:13464RLSA-2025:12447UBUNTU-CVE-2025-7425DSA-5990-1openSUSE-SU-2025:15363-1
Also known as
CGA-j6x2-xhvh-29pw, RHSA-2025:13308, RHSA-2025:13310, RHSA-2025:13311, RHSA-2025:13312, RHSA-2025:13313, RHSA-2025:13314, USN-7852-1, USN-7852-2, USN-7896-1

Charts affected

734 by stars
ChartLatestAffected imagesRadar Score
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libxml2@2.9.13+dfsg-1ubuntu0.2
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

24,917
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.2
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
libxml2@2.9.13-2.el9
0:2.9.13-11.el9_6
quay.io/keycloak/keycloak:20.0054ef67eb7da
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2

Open the chart page →

55,666
drogue-cloud-examplesdrogue-iotVerified publisher0.7.114 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

4 of the 6 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.10
ghcr.io/ctron/kubectl:1.25e37d61b5277c
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

30,699
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2

Open the chart page →

6,915
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

9,244
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

4,586
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.2

Open the chart page →

11,482
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm6

Open the chart page →

10,981
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2

Open the chart page →

4,033
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

25,122
kube-ecp-stackemqx-operator2.5.11 of 16See more

kube-ecp-stack emqx-operator 2.5.1

1 of the 16 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
emqx/ecp-ui:2.5.1e33e9816f147
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

23,685
kube-packetloss-exporterenixVerified publisher0.2.11 of 2See more

kube-packetloss-exporter enix 0.2.1

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

6,131
eoloPlanteolo-plannerVerified publisher0.1.02 of 7See more

eoloPlant eolo-planner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
mastercloudapps/weatherservice:v1.23de859d29c116
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

27,537
eoloplannereoloplannerVerified publisher0.1.02 of 7See more

eoloplanner eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

32,205
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.02 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
mastercloudapps/weatherservice:v1.23de859d29c116
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

27,537
eoloplannereoloplanner-molynx-gat0.1.02 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

28,482
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

27,096
eoloplanteoloplant1.0.02 of 7See more

eoloplant eoloplant 1.0.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
mastercloudapps/weatherservice:v1.23de859d29c116
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

27,537
eoloplantseoloplants-urjcVerified publisher0.1.02 of 7See more

eoloplants eoloplants-urjc 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

27,721
servereoloserverVerified publisher0.1.02 of 7See more

server eoloserver 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
codeurjc/weatherservice:v1.0b9e2f7234349
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2

Open the chart page →

32,205
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

5,290
powfaucetethereum-helm-chartsVerified publisher1.2.11 of 1See more

powfaucet ethereum-helm-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
pk910/powfaucet:v2-stable3dcae6a62896
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

4,456
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

20,933
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

6,026
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

10,741
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

12,454
apollofiware0.1.41 of 1See more

apollo fiware 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/fiware/apollo:0.0.1055330b1b60c1
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.2

Open the chart page →

6,936
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

64,489
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2

Open the chart page →

8,528
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2

Open the chart page →

2,475
contract-managementfiware3.5.361 of 1See more

contract-management fiware 3.5.36

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/fiware/contract-management:3.3.122bcfcf874451
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2

Open the chart page →

2,411
credentials-config-servicefiware2.6.41 of 1See more

credentials-config-service fiware 2.6.4

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2

Open the chart page →

2,293
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2

Open the chart page →

4,536
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.2

Open the chart page →

11,835
mintakafiware0.4.71 of 1See more

mintaka fiware 0.4.7

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
fiware/mintaka:latestefc6793388cc
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.2

Open the chart page →

7,019
orionfiware1.6.111 of 2See more

orion fiware 1.6.11

1 of the 2 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.2

Open the chart page →

10,637
tm-forum-apifiware0.17.1519 of 19See more

tm-forum-api fiware 0.17.15

19 of the 19 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/fiware/tmforum-account:1.18.06b25aac03414
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
libxml2@2.9.7-21.el8_10.1
0:2.9.7-21.el8_10.2

Open the chart page →

35,112
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.2

Open the chart page →

7,087
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.10

Open the chart page →

4,077
plexfydrah-charts2.2.01 of 1See more

plex fydrah-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm11

Open the chart page →

8,965
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4

Open the chart page →

13,241
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
libxml2@2.9.14+dfsg-1.3ubuntu3.1
libxslt@1.1.39-0exp1build1
2.9.14+dfsg-1.3ubuntu3.6
no fix listed
gchq/hdfs:3.3.35ec58edbb2db
libxml2@2.9.14+dfsg-1.3ubuntu3.1
libxslt@1.1.39-0exp1build1
2.9.14+dfsg-1.3ubuntu3.6
no fix listed

Open the chart page →

16,892
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
libxml2@2.9.14+dfsg-1.3ubuntu3.1
libxslt@1.1.39-0exp1build1
2.9.14+dfsg-1.3ubuntu3.6
no fix listed

Open the chart page →

9,342
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2

Open the chart page →

11,961
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

18,230
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2025-7425.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3

Open the chart page →

14,659

Container images carrying it

809 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
cleveritcz/opencve:1.5.0c75c1636e0b7
libxml2@2.9.13-5.el9_3
0:2.9.13-11.el9_6
1
cloudve/janis-terminal:latestaf56e77ca587
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm6
1
cockroachdb/cockroach:v22.2.91116820f4134
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.2
1
cockroachdb/cockroach-operator:v2.1.0983312754620
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
coderenvs/coder-service:1.44.61deffc4670e6
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
1
coderenvs/timescale:1.44.676fd37fe6830
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
1
codetogether/codetogether:latest4348c8a38752
libxml2@2.9.13-6.el9_4
0:2.9.13-11.el9_6
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.2
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
libxml2@2.9.7-19.el8_10
0:2.9.7-21.el8_10.2
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2
1
confluentinc/cp-kafka:7.5.1dc9b972db002
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.2
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.2
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.2
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.2
1
countly/countly-server:25.05.4e3c238248f99
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
craftypath/sops-operator:v0.8.0402a0024c732
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.2
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
libxml2@2.9.1-6.el7.5
0:2.9.1-6.el7_9.12
1
ctron/hawkbit-operator:0.1.48fdea8f76499
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.2
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
dannielkil/book-frontend:latest937993927694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
datadog/operator:0.3.117f08a860090
libxml2@2.9.1-6.el7.4
0:2.9.1-6.el7_9.12
1
datamate/seafile-professional:11.0.202dd66b722464
libxml2@2.9.13+dfsg-1ubuntu0.8
2.9.13+dfsg-1ubuntu0.10
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.2
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ddosify/selfhosted_backend:3.2.93c11e3182652
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
deconzcommunity/deconz:2.29.2062de2362641
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.2
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
libxml2@2.12.7+dfsg+really2.9.14-2.1
2.12.7+dfsg+really2.9.14-2.1+deb13u1
1
domainmod/domainmod:4.23.04017bfe4c597
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm6
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm6
1
emqx/ecp-ui:2.5.1e33e9816f147
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
engrmth/bnkr:2.1.06d8464e6f0e8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
felipecs8/app-db-connection-test:v129e06c9c6385
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm3
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.