StackRadar

CVE-2025-9714

Medium

Advisory

Published 4 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
955
of 17,790 indexed, latest versions
Container images
1,038
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 955 of 17,790 indexed charts deploy, on 1,038 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+49 more2.9.1+dfsg1-3ubuntu4.13+esm9, 2.9.3+dfsg1-1ubuntu0.7+esm10, 2.9.4+dfsg1-6.1ubuntu1.9+esm5, 2.9.10+dfsg-5ubuntu0.20.04.10+esm2+5 more714
libxml2rpm2.9.1-6.el7_2.3, 2.9.1-6.el7_9.6, 2.9.1-6.el7.4, 2.9.1-6.el7.5+30 more0:2.9.1-6.el7_9.14, 0:2.9.7-21.el8_10.4, 0:2.9.13-3.el9_2.10, 0:2.9.13-13.el9_4+1 more324
OSV records
DEBIAN-CVE-2025-9714RHSA-2025:22162RHSA-2025:22163RHSA-2025:22376RHSA-2026:11349RHSA-2026:22420RLSA-2025:22376RLSA-2026:11349UBUNTU-CVE-2025-9714DLA-4319-1
Also known as
RHSA-2025:22377, RHSA-2026:14832, RHSA-2026:14858, RHSA-2026:15967, USN-7743-1

Charts affected

955 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.4

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5

Open the chart page →

7,685
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.4

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9714.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.4

Open the chart page →

3,697

Container images carrying it

1,038 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kporwit/vinyl_lib_app:v0.1.1217de0302218
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
kubebb/hello-world:0.1.0b746824819f3
libxml2@2.9.10+dfsg-6.7+deb11u1
2.9.10+dfsg-6.7+deb11u9
1
kubedex/helm-controller:v1.0.14f1008c51ef9
libxml2@2.9.1-6.el7_2.3
0:2.9.1-6.el7_9.14
1
kubeflow/model-registry:v0.2.95783f6db428f
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.4
1
kubegems/chatgpt-api:latestf3c492a938ad
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.5
1
kuberay/operator:v1.0.04e6ac8a3a2c4
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.4
1
kuzwolka/aws9:main1ad759b961b1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
kuzwolka/aws9:news3e8880fbbb96
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
kuzwolka/aws9:blog4a7707410bf1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
kuzwolka/aws9:shop84a9d9766345
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
laly9999/node-app:1dd0e503913e1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
langgenius/dify-api:0.6.11fca918260dd6
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/httpd:2.4.631ae8051591a5
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u5
1
library/httpd:2.4.54ee2117e77c35
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
library/logstash:9.1.233eae14f0867
libxml2@2.9.13-12.el9_6
0:2.9.13-14.el9_7
1
library/matomo:5.1.2-apache2415789e1602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/monica:3.7.0-apacheceb1ba4196ab
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
library/nextcloud:31.0.6-apache588609d76b21
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u5
1
library/nginx:1.27.409369da6b103
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/nginx:1.23.03536d368b898
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
library/nginx:1.276784fb0834aa
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/nginx:1.25.167f9a4f10d14
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/nginx:1.25.49ff236ed47fe
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/nginx:1.23.2ab589a3c466e
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
library/nginx:1.23.3f4e3b6489888
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
library/nginx:1.23f5747a42e3ad
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
library/nginx:1.27.3fb197595ebe7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/php:7.3-apacheb9872cd287ef
libxml2@2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u9
1
library/postgres:13.703652c675ae1
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
library/postgres:18.0073e7c8b84e2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
2.12.7+dfsg+really2.9.14-2.1+deb13u2
1
library/postgres:14.32d1e636f0778
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
library/postgres:17.4304ab8135187
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/postgres:16.6557fea37a744
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/postgres:13.11-bullseye5c265bf1fd30
libxml2@2.9.10+dfsg-6.7+deb11u4
2.9.10+dfsg-6.7+deb11u9
1
library/postgres:15.38775adb39f0d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/postgres:17.5aadf2c0696f5
libxml2@2.12.7+dfsg+really2.9.14-2.1
2.12.7+dfsg+really2.9.14-2.1+deb13u2
1
library/postgres:13.12ced3ba927f4c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/postgres:14.0db927beee892
libxml2@2.9.10+dfsg-6.7
2.9.10+dfsg-6.7+deb11u9
1
library/postgres:14.6f565573d74ae
libxml2@2.9.10+dfsg-6.7+deb11u3
2.9.10+dfsg-6.7+deb11u9
1
library/postgres:17.5-bookwormfbcea1bd13b6
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u5
1
library/python:3.8d41127070014
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
library/python:3.9da5aee29682d
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
2.12.7+dfsg+really2.9.14-2.1+deb13u2
1
library/python:3.12.9-bullseyeed4450bab88f
libxml2@2.9.10+dfsg-6.7+deb11u6
2.9.10+dfsg-6.7+deb11u9
1
library/wordpress:6.0.0-php8.0-apache277c6c25980f
libxml2@2.9.10+dfsg-6.7+deb11u2
2.9.10+dfsg-6.7+deb11u9
1
library/wordpress:6.4.3-apache8ae66efb09a2
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u5
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm5
1
linuxserver/calibre-web:0.6.24241009026e6f
libxml2@2.9.14+dfsg-1.3ubuntu3.4
2.9.14+dfsg-1.3ubuntu3.5
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.