StackRadar

CVE-2025-9714

Medium

Advisory

Published 4 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
955
of 17,790 indexed, latest versions
Container images
1,038
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 955 of 17,790 indexed charts deploy, on 1,038 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+49 more2.9.1+dfsg1-3ubuntu4.13+esm9, 2.9.3+dfsg1-1ubuntu0.7+esm10, 2.9.4+dfsg1-6.1ubuntu1.9+esm5, 2.9.10+dfsg-5ubuntu0.20.04.10+esm2+5 more714
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+30 more0:2.9.1-6.el7_9.14, 0:2.9.7-21.el8_10.4, 0:2.9.13-3.el9_2.10, 0:2.9.13-13.el9_4+1 more324
OSV records
DEBIAN-CVE-2025-9714RHSA-2025:22162RHSA-2025:22163RHSA-2025:22376RHSA-2026:11349RHSA-2026:22420RLSA-2025:22376RLSA-2026:11349UBUNTU-CVE-2025-9714DLA-4319-1
Also known as
RHSA-2025:22377, RHSA-2026:14832, RHSA-2026:14858, RHSA-2026:15967, USN-7743-1

Charts affected

955 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.4

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5

Open the chart page →

7,685
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.4

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4

Open the chart page →

3,697

Container images carrying it

1,038 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/app-nav-controller:1.0.1ee4624ba513d
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.4
1
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
libxml2@2.9.7-7.el8
0:2.9.7-21.el8_10.4
1
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.4
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm10
1
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
libxml2@2.9.7-5.el8
0:2.9.7-21.el8_10.4
1
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
inseefrlab/shelly:cloudshell31f04ca7436b
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.9
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
ispras/svacer:11-2-042aa9fa9f189
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.9
1
ixsystems/truecommand:3.2.019c218455cd2
libxml2@2.12.7+dfsg+really2.9.14-2.1
2.12.7+dfsg+really2.9.14-2.1+deb13u2
1
jaedb/iris:latest048cfbf58d57
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
jakowenko/double-take:1.6.0b858bac9e32a
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
jellyfin/jellyfin:10.8.1305a9734d7e83
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
jellyfin/jellyfin:10.10.77ae36aab93ef
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
jellyfin/jellyfin:10.10.696b09723b22f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
jellyfin/jellyfin:10.8.1ee24f4459a40
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
josh5/unmanic:0.2.64d49c4816260
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.9
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
kennethreitz/httpbin:latest599fe5e50731
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1
kinseii/wazuh-agent:4.14.17160eb143728
libxml2@2.9.14+dfsg-1.3~deb12u4
2.9.14+dfsg-1.3~deb12u5
1
knspar/phronetis-operator:0.1.60c4f0543ee58
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
kobotoolbox/kobocat:2.022.24ab15679454415
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.