StackRadar

CVE-2026-0989

Low

Advisory

Published 15 Jan 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
651
of 17,787 indexed, latest versions
Container images
634
deployed by those charts
Fix available
2 of 2
affected packages

libxml2-16-2.14.5-2.1 on GA media

Carried by container images the latest versions of 651 of 17,787 indexed charts deploy, on 634 images.

Affected packageAffected versionsFixed inImages
libxml2rpm2.9.7-lp151.5.3.12.14.5-2.12
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+47 more2.9.1+dfsg1-3ubuntu4.13+esm11, 2.9.3+dfsg1-1ubuntu0.7+esm12, 2.9.4+dfsg1-6.1ubuntu1.9+esm7, 2.9.10+dfsg-5ubuntu0.20.04.10+esm4+5 more632
OSV records
DEBIAN-CVE-2026-0989UBUNTU-CVE-2026-0989openSUSE-SU-2026:10085-1
Also known as
USN-7974-1

Charts affected

651 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-0989.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

7,685

Container images carrying it

634 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
escaping/core-keeper-dedicated:latest87fa79255962
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
espocrm/espocrm:9.3.101b5a24504ed9
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
falcosecurity/event-generator:latest932956d86c99
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6
1
felipecs8/app-db-connection-test:v129e06c9c6385
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
fireflyiii/core:version-6.6.6ae69fdd95cde
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
fluent/fluent-bit:4.0-debuge76397ef3983
libxml2@2.9.14+dfsg-1.3~deb12u4
2.9.14+dfsg-1.3~deb12u6
1
fnzv/dump1090:latestb3079b95c336
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.11
1
folioci/mod-z3950:latest2493041ce880
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
galaxy/galaxy-init:v18.010267bad550e6
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm11
1
galaxy/galaxy-stable:v18.018e577a626dfd
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm11
1
gchq/accumulo:2.0.1c460bb587d6d
libxml2@2.9.14+dfsg-1.3ubuntu3.1
2.9.14+dfsg-1.3ubuntu3.7
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm7
1
gethue/hue:4.11.011b649636e68
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
gethue/hue:4.10.05702b2c37ff9
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm7
1
gethue/hue:latest7d5c1b9f8a79
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.11
1
gotenberg/gotenberg:8.30206a6c708fc6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
gotenberg/gotenberg:8.3467097317623a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
guacamole/guacamole:1.5.50f62f6d17ab3
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.11
1
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u6
1
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
haveagitgat/tdarr:2.00.181256348872ce
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
hazegoodlife/haaze:milksite8d4c63169e14
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm12
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm12
1
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm7
1
inseefrlab/shelly:cloudshell31f04ca7436b
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.11
1
instill/artifact-backend:b28766ac4a393e601ed
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
ispras/svacer:11-2-042aa9fa9f189
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.11
1
ixsystems/truecommand:3.2.019c218455cd2
libxml2@2.12.7+dfsg+really2.9.14-2.1
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
jaedb/iris:latest048cfbf58d57
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
jakowenko/double-take:1.6.0b858bac9e32a
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
1
jellyfin/jellyfin:10.11.81694ff069f0c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
jellyfin/jellyfin:10.11.717285f9cce63
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
jellyfin/jellyfin:10.11.6333b64771663
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
jellyfin/jellyfin:10.10.77ae36aab93ef
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
jellyfin/jellyfin:10.10.696b09723b22f
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.