StackRadar

CVE-2026-0990

Medium

Advisory

Published 15 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
648
of 17,781 indexed, latest versions
Container images
631
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 648 of 17,781 indexed charts deploy, on 631 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+47 more2.9.1+dfsg1-3ubuntu4.13+esm11, 2.9.3+dfsg1-1ubuntu0.7+esm12, 2.9.4+dfsg1-6.1ubuntu1.9+esm7, 2.9.10+dfsg-5ubuntu0.20.04.10+esm4+5 more631
OSV records
DEBIAN-CVE-2026-0990UBUNTU-CVE-2026-0990
Also known as
USN-7974-1

Charts affected

648 by stars
ChartLatestAffected imagesRadar Score
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
cybrarist/discount-bandit:v4.0.4e9e2447ac666
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Open the chart page →

29,817
immichhelmforgeVerified publisher1.2.83 of 5See more

immich helmforge 1.2.8

3 of the 5 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
libxml2@2.9.14+dfsg-1.3~deb12u4
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

11,042
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

5,341
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

9,653
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Open the chart page →

4,751
text-embeddings-inferencehelmforgeVerified publisher1.0.01 of 2See more

text-embeddings-inference helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

2,541
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

30,099
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

12,607
jellyfinhelm-l3st86Verified publisher0.1.81 of 1See more

jellyfin helm-l3st86 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
jellyfin/jellyfin:latestaefb67e6a7ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Open the chart page →

2,604
openaevhelm-openbasVerified publisher2.0.51 of 7See more

openaev helm-openbas 2.0.5

1 of the 7 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

7,437
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

25,017
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
libxml2@2.9.13+dfsg-1ubuntu0.7
2.9.13+dfsg-1ubuntu0.11

Open the chart page →

6,015
samplehelmapphelmtraining3.0.01 of 1See more

samplehelmapp helmtraining 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
praravind1801/helmimages:3.0.0f29d637b9ce1
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

5,973
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.11

Open the chart page →

14,290
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

16,384
paperlesshpVerified publisher0.1.11 of 5See more

paperless hp 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.3467097317623a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Open the chart page →

26,612
hydrahydraVerified publisher0.9.51 of 2See more

hydra hydra 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

9,011
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

7,733
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.9+esm7

Open the chart page →

12,611
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm12

Open the chart page →

25,160
ibm-ucv-prodibm-helm5.2.61 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

1 of the 16 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

12,105
tolgeeicoretechVerified publisher0.46.11 of 3See more

tolgee icoretech 0.46.1

1 of the 3 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Open the chart page →

2,744
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.7

Open the chart page →

8,967
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm4

Open the chart page →

37,671
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

3,571
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

6,254
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

11,812
plausible-analyticsimioVerified publisher0.4.23 of 5See more

plausible-analytics imio 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

10,418
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
libxml2@2.9.4+dfsg1-6.1ubuntu1.8
2.9.4+dfsg1-6.1ubuntu1.9+esm7

Open the chart page →

16,212
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.11

Open the chart page →

5,320
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

5,062
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.11

Open the chart page →

10,494
gmaintelVerified publisher0.1.01 of 1See more

gma intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm4

Open the chart page →

7,650
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm4

Open the chart page →

18,066
map5gintelVerified publisher1.0.01 of 1See more

map5g intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm4

Open the chart page →

7,650
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.10+esm4

Open the chart page →

11,069
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

17,852
daveit-at-mOfficialVerified publisher0.2.152 of 11See more

dave it-at-m 0.2.15

2 of the 11 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

15,089
opencloudjacobcolvinVerified publisher0.2.37 of 13See more

opencloud jacobcolvin 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.7
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

45,239
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

10,780
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

4,489
jellyfinjellyfin--jellyfin-helm3.0.01 of 1See more

jellyfin jellyfin--jellyfin-helm 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.717285f9cce63
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Open the chart page →

3,001
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.11

Open the chart page →

5,208
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.7

Open the chart page →

6,586
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.7

Open the chart page →

6,568
image-storage-servicejtektVerified publisher0.4.32 of 4See more

image-storage-service jtekt 0.4.3

2 of the 4 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

22,589
shinsei-managerjtektVerified publisher0.2.07 of 8See more

shinsei-manager jtekt 0.2.0

7 of the 8 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
moreillon/group-manager:latest3caa8f710ee0
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6
moreillon/group-manager-front:latest5f0a38498271
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
moreillon/user-manager:v5.0.2e1c9bfab5c16
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
moreillon/user-manager-front:v5.0.3b067dbbbb6af
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

63,461
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6

Open the chart page →

16,600
jupyter-hub-customizationsjupyter-jscVerified publisher0.27.171 of 4See more

jupyter-hub-customizations jupyter-jsc 0.27.17

1 of the 4 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
library/nginx:1.291881968aff6f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Open the chart page →

3,389
jupyter-nginxjupyter-jscVerified publisher0.1.31 of 1See more

jupyter-nginx jupyter-jsc 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-0990.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Open the chart page →

3,508

Container images carrying it

631 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6
11
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm12
11
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
7
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm12
6
quay.io/devtron/postgres:14.91b594392f7cb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
6
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6
5
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
libxml2@2.9.14+dfsg-1.3~deb12u5
2.9.14+dfsg-1.3~deb12u6
5
library/postgres:122f2a8c2a7d10
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
5
artifacthub/postgres:latest4fd34fa635cc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
2.12.7+dfsg+really2.9.14-2.1+deb13u3
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6
4
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
4
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6
4
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm12
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm12
4
library/nginx:1.27.1287ff321f9e3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
4
library/postgres:134689940c6838
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
2.12.7+dfsg+really2.9.14-2.1+deb13u3
4
opea/llm-tgi:1.00c25aab3f106
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
4
bitnamilegacy/kubectl:latestcd354d5b2556
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
3
ciscolabs/rtsp-client:latesta7b60ec88285
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
3
ciscolabs/rtsp-server:latestb59fc10bb821
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
3
gchq/hdfs:3.3.35ec58edbb2db
libxml2@2.9.14+dfsg-1.3ubuntu3.1
2.9.14+dfsg-1.3ubuntu3.7
3
guacamole/guacamole:1.6.0f344085e618b
libxml2@2.9.14+dfsg-1.3ubuntu3.3
2.9.14+dfsg-1.3ubuntu3.7
3
library/nginx:1.25:1.25.5a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm12
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u6
3
quay.io/devtron/ai-agent:0.0.16545dac92173
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
libxml2@2.9.13+dfsg-1ubuntu0.2
2.9.13+dfsg-1ubuntu0.11
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
libxml2@2.9.14+dfsg-1.3~deb12u4
2.9.14+dfsg-1.3~deb12u6
3
apache/nifi-registry:1.26.07cdfd8deec92
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.11
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
libxml2@2.9.14+dfsg-1.3ubuntu3
2.9.14+dfsg-1.3ubuntu3.7
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
libxml2@2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u6
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u6
2
gradiant/ueransim:3.2.6015b30d5fa0f
libxml2@2.9.13+dfsg-1ubuntu0.4
2.9.13+dfsg-1ubuntu0.11
2
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.10+esm4
2
kurento/kurento-media-server:latest03c0d34d0828
libxml2@2.9.14+dfsg-1.3ubuntu3.6
2.9.14+dfsg-1.3ubuntu3.7
2
library/nginx:latest6e23479198b9
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
2
library/nginx:1.27.098f8ec75657d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
2
library/nginx:1.29.49dd288848f44
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
2
library/phpmyadmin:5.2.16e75aa8f767c
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
2
library/postgres:16.109f23e02d766
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
2
library/postgres:18.11090bc3a8ccf
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
2.12.7+dfsg+really2.9.14-2.1+deb13u3
2
library/postgres:16.24aea012537ed
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u6
2
library/postgres:18.06f3e42ad37de
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
2.12.7+dfsg+really2.9.14-2.1+deb13u3
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.