StackRadar

CVE-2025-9714

Medium

Advisory

Published 4 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
955
of 17,787 indexed, latest versions
Container images
1,038
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 955 of 17,787 indexed charts deploy, on 1,038 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+49 more2.9.1+dfsg1-3ubuntu4.13+esm9, 2.9.3+dfsg1-1ubuntu0.7+esm10, 2.9.4+dfsg1-6.1ubuntu1.9+esm5, 2.9.10+dfsg-5ubuntu0.20.04.10+esm2+5 more714
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+30 more0:2.9.1-6.el7_9.14, 0:2.9.7-21.el8_10.4, 0:2.9.13-3.el9_2.10, 0:2.9.13-13.el9_4+1 more324
OSV records
DEBIAN-CVE-2025-9714RHSA-2025:22162RHSA-2025:22163RHSA-2025:22376RHSA-2026:11349RHSA-2026:22420RLSA-2025:22376RLSA-2026:11349UBUNTU-CVE-2025-9714DLA-4319-1
Also known as
RHSA-2025:22377, RHSA-2026:14832, RHSA-2026:14858, RHSA-2026:15967, USN-7743-1

Charts affected

955 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.4

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5

Open the chart page →

7,685
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.4

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4

Open the chart page →

3,697

Container images carrying it

1,038 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
yzhou442/equiz:latesta3f7ca69e28d
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.5
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.9
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
libxml2@2.9.14+dfsg-1.3~deb12u4
2.9.14+dfsg-1.3~deb12u5
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
libxml2@2.9.14+dfsg-1.3~deb12u4
2.9.14+dfsg-1.3~deb12u5
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_7
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.4
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.4
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.4
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.4
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4
2
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
libxml2@2.9.7-19.el8_10
0:2.9.7-21.el8_10.4
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.4
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.4
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.4
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
libxml2@2.9.13-6.el9_5.2
0:2.9.13-14.el9_7
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_7
2
1dev/server:11.9.0cd5b12fe5471
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.5
1
5200710/hadoop:3.2.3-java8092d3088a5fb
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
activepieces/activepieces:0.23.0c26188b44e62
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
adolfintel/speedtest:latest1f828fe83374
libxml2@2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u9
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
aidasi/swpapi:v1-1-net6-k8s-test-beta838b5e2080bc
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
aidasi/swpspa:v1-1-net6-k8s-test-betadee4ec566312
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
airbyte/pod-sweeper:1.5.198d2c39d512e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
akaunting/akaunting:3.0.1552811b36ec3a
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u5
1
akeyless/base-rhel:0.0.14ba8900a0061
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
allegroai/clearml:2.0.0-613713ae38f7daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
libxml2@2.9.4+dfsg1-6.1ubuntu1.6
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.4
1
altinity/clickhouse-operator:0.16.1db7dde971407
libxml2@2.9.1-6.el7_9.6
0:2.9.1-6.el7_9.14
1
altinity/metrics-exporter:0.20.01a46d104406d
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.4
1
altinity/metrics-exporter:0.16.185b4fdbae053
libxml2@2.9.1-6.el7_9.6
0:2.9.1-6.el7_9.14
1
anchore/anchore-engine:v0.10.0bde9eedf639d
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.4
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
libxml2@2.9.7-5.el8
0:2.9.7-21.el8_10.4
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.9
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.