StackRadar

CVE-2025-9714

Medium

Advisory

Published 4 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
955
of 17,790 indexed, latest versions
Container images
1,038
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 955 of 17,790 indexed charts deploy, on 1,038 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+49 more2.9.1+dfsg1-3ubuntu4.13+esm9, 2.9.3+dfsg1-1ubuntu0.7+esm10, 2.9.4+dfsg1-6.1ubuntu1.9+esm5, 2.9.10+dfsg-5ubuntu0.20.04.10+esm2+5 more714
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+30 more0:2.9.1-6.el7_9.14, 0:2.9.7-21.el8_10.4, 0:2.9.13-3.el9_2.10, 0:2.9.13-13.el9_4+1 more324
OSV records
DEBIAN-CVE-2025-9714RHSA-2025:22162RHSA-2025:22163RHSA-2025:22376RHSA-2026:11349RHSA-2026:22420RLSA-2025:22376RLSA-2026:11349UBUNTU-CVE-2025-9714DLA-4319-1
Also known as
RHSA-2025:22377, RHSA-2026:14832, RHSA-2026:14858, RHSA-2026:15967, USN-7743-1

Charts affected

955 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.4

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5

Open the chart page →

7,697
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.4

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4

Open the chart page →

3,697

Container images carrying it

1,038 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
libxml2@2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
libxml2@2.9.10+dfsg-6.7+deb11u7
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/libretime/libretime-legacy:latest35b4531189c2
libxml2@2.9.10+dfsg-6.7+deb11u7
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
libxml2@2.9.10+dfsg-6.7+deb11u7
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.4
1
ghcr.io/linuxoid69/motion:4.7.0-0.1.0f0f000c3fc47
libxml2@2.9.10+dfsg-6.7+deb11u5
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
libxml2@2.9.13-9.el9_6
0:2.9.13-14.el9_7
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
libxml2@2.9.14+dfsg-1.3ubuntu3.2
2.9.14+dfsg-1.3ubuntu3.5
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.5
1
ghcr.io/monicahq/monica-next:main8be69156acbb
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
2.12.7+dfsg+really2.9.14-2.1+deb13u2
1
ghcr.io/mroxso/pollstr:latest0b4f97faa3d0
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
libxml2@2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
libxml2@2.9.10+dfsg-6.7+deb11u7
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/privacyengineering/hawk-monitor:master13309f068a56
libxml2@2.9.10+dfsg-6.7+deb11u1
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
libxml2@2.9.13-6.el9_4
0:2.9.13-13.el9_4
1
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
libxml2@2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.5
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.5
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.9
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.