StackRadar

CVE-2025-9714

Medium

Advisory

Published 4 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
955
of 17,787 indexed, latest versions
Container images
1,038
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 955 of 17,787 indexed charts deploy, on 1,038 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+49 more2.9.1+dfsg1-3ubuntu4.13+esm9, 2.9.3+dfsg1-1ubuntu0.7+esm10, 2.9.4+dfsg1-6.1ubuntu1.9+esm5, 2.9.10+dfsg-5ubuntu0.20.04.10+esm2+5 more714
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+30 more0:2.9.1-6.el7_9.14, 0:2.9.7-21.el8_10.4, 0:2.9.13-3.el9_2.10, 0:2.9.13-13.el9_4+1 more324
OSV records
DEBIAN-CVE-2025-9714RHSA-2025:22162RHSA-2025:22163RHSA-2025:22376RHSA-2026:11349RHSA-2026:22420RLSA-2025:22376RLSA-2026:11349UBUNTU-CVE-2025-9714DLA-4319-1
Also known as
RHSA-2025:22377, RHSA-2026:14832, RHSA-2026:14858, RHSA-2026:15967, USN-7743-1

Charts affected

955 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.4

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5

Open the chart page →

7,685
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.4

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4

Open the chart page →

3,697

Container images carrying it

1,038 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cleveritcz/opencve:1.5.0c75c1636e0b7
libxml2@2.9.13-5.el9_3
0:2.9.13-14.el9_7
1
cloudve/janis-terminal:latestaf56e77ca587
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
cockroachdb/cockroach:v22.2.91116820f4134
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4
1
cockroachdb/cockroachdb-operator-v2:v1.0.04335d8bcbd3d
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_7
1
cockroachdb/cockroach-operator:v2.1.0983312754620
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.4
1
coderenvs/coder-service:1.44.61deffc4670e6
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
coderenvs/timescale:1.44.676fd37fe6830
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
codetogether/codetogether:latest4348c8a38752
libxml2@2.9.13-6.el9_4
0:2.9.13-13.el9_4
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.4
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.4
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.4
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
libxml2@2.9.7-19.el8_10
0:2.9.7-21.el8_10.4
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.4
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.4
1
confluentinc/cp-kafka:7.5.1dc9b972db002
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.4
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.4
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.4
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.4
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.4
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.4
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.4
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.4
1
countly/api:25.05.4f4cc7447c4f5
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
countly/countly-server:25.05.4e3c238248f99
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
craftypath/sops-operator:v0.8.0402a0024c732
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.4
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
libxml2@2.9.1-6.el7.5
0:2.9.1-6.el7_9.14
1
ctron/hawkbit-operator:0.1.48fdea8f76499
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.4
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
dannielkil/book-frontend:latest937993927694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
danuk/telegram-sender:0.0.1026560388070
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.4
1
datadog/operator:0.3.117f08a860090
libxml2@2.9.1-6.el7.4
0:2.9.1-6.el7_9.14
1
datamate/seafile-professional:11.0.202dd66b722464
libxml2@2.9.13+dfsg-1ubuntu0.8
2.9.13+dfsg-1ubuntu0.9
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.4
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
ddosify/selfhosted_backend:3.2.93c11e3182652
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
deconzcommunity/deconz:2.29.2062de2362641
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.4
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.4
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
libxml2@2.12.7+dfsg+really2.9.14-2.1
2.12.7+dfsg+really2.9.14-2.1+deb13u2
1
domainmod/domainmod:4.23.04017bfe4c597
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
douz/helpdesk:latest4384103d0219
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
duck1123/astral:latestf4d5b6526c2a
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.