StackRadar

CVE-2025-9714

Medium

Advisory

Published 4 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
955
of 17,790 indexed, latest versions
Container images
1,038
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 955 of 17,790 indexed charts deploy, on 1,038 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+49 more2.9.1+dfsg1-3ubuntu4.13+esm9, 2.9.3+dfsg1-1ubuntu0.7+esm10, 2.9.4+dfsg1-6.1ubuntu1.9+esm5, 2.9.10+dfsg-5ubuntu0.20.04.10+esm2+5 more714
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+30 more0:2.9.1-6.el7_9.14, 0:2.9.7-21.el8_10.4, 0:2.9.13-3.el9_2.10, 0:2.9.13-13.el9_4+1 more324
OSV records
DEBIAN-CVE-2025-9714RHSA-2025:22162RHSA-2025:22163RHSA-2025:22376RHSA-2026:11349RHSA-2026:22420RLSA-2025:22376RLSA-2026:11349UBUNTU-CVE-2025-9714DLA-4319-1
Also known as
RHSA-2025:22377, RHSA-2026:14832, RHSA-2026:14858, RHSA-2026:15967, USN-7743-1

Charts affected

955 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.4

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5

Open the chart page →

7,697
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.4

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4

Open the chart page →

3,697

Container images carrying it

1,038 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
emberstack/sftp:5.1.711d81a5df909b
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
emqx/ecp-ui:2.5.1e33e9816f147
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
engrmth/bnkr:2.1.06d8464e6f0e8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
erlangsolutions/wombatoam:4.1.284680c990147a
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
fanzynoodle/smeejas:0.0.15f9916c1a287
libxml2@2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u9
1
felipecs8/app-db-connection-test:v129e06c9c6385
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
filegator/filegator:latestce163db220d4
libxml2@2.9.10+dfsg-6.7+deb11u8
2.9.10+dfsg-6.7+deb11u9
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
fiware/mintaka:0.7.092a3c5cf43c0
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.4
1
fiware/mintaka:latestefc6793388cc
libxml2@2.9.7-13.el8
0:2.9.7-21.el8_10.4
1
fiware/orion-ld:1.10.03c490a746f65
libxml2@2.9.7-21.el8_10.3
0:2.9.7-21.el8_10.4
1
fluent/fluent-bit:4.0-debuge76397ef3983
libxml2@2.9.14+dfsg-1.3~deb12u4
2.9.14+dfsg-1.3~deb12u5
1
fnzv/dump1090:latestb3079b95c336
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.9
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
libxml2@2.9.13-6.el9_4
0:2.9.13-14.el9_7
1
galaxy/galaxy-init:v18.010267bad550e6
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm9
1
galaxy/galaxy-stable:v18.018e577a626dfd
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm9
1
gchq/accumulo:2.0.1c460bb587d6d
libxml2@2.9.14+dfsg-1.3ubuntu3.1
2.9.14+dfsg-1.3ubuntu3.5
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
gethue/hue:4.11.011b649636e68
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
gethue/hue:4.10.05702b2c37ff9
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
gethue/hue:latest7d5c1b9f8a79
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.9
1
golenski/db-init:1.0.086ca17cd3063
libxml2@2.9.10+dfsg-6.7+deb11u5
2.9.10+dfsg-6.7+deb11u9
1
guacamole/guacamole:1.5.50f62f6d17ab3
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.9
1
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u5
1
gurolakman/oam:4.0.0ed8fd2062548
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.4
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
gurolakman/ussigw-core:1.0.48739565c3ea2
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.4
1
ha33ona/python:test6affdfc644d0
libxml2@2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u9
1
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_7
1
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
haveagitgat/tdarr:2.00.181256348872ce
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
hazegoodlife/haaze:milksite8d4c63169e14
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
hazelcast/management-center:5.3.2f9d34300d330
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.4
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
helga09/php_shoes_ukr:v1.1.1e283539bcb8c
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
heywood8/redisinsight:2.28.00bc9ab313d37
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.