StackRadar

CVE-2026-102633

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
778
of 17,957 indexed, latest versions
Container images
648
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 778 of 17,957 indexed charts deploy, on 648 images.

Affected packageAffected versionsFixed inImages
expatdeb2.5.0-1, 2.5.0-1+deb12u1, 2.5.0-1+deb12u2, 2.5.0-1+deb12u3+6 moreno fix listed648
OSV records
DEBIAN-CVE-2026-102633
Trending
Rank 32 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

778 by stars
ChartLatestAffected imagesRadar Score
jenkinsjenkinsciOfficialVerified publisher5.9.641 of 2See more

jenkins jenkinsci 5.9.64

1 of the 2 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-jdk21c1e4c349365f
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

2,821
nextcloudnextcloud9.3.01 of 1See more

nextcloud nextcloud 9.3.0

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4-apachea5ace30c695a
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

4,310
nginx-ingressnginxVerified publisher2.7.31 of 1See more

nginx-ingress nginx 2.7.3

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
nginx/nginx-ingress:5.6.33e97f06dce1c
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,338
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
expat@2.5.0-1+deb12u3
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

8,785
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

32,872
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
expat@2.5.0-1
no fix listed

Open the chart page →

11,951
netdatanetdataVerified publisher3.7.1741 of 1See more

netdata netdata 3.7.174

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.121970e176031
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

2,607
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
boky/postfix:v5.1.0aafc77238423
expat@2.7.1-2
no fix listed

Open the chart page →

6,129
zammadzammadOfficialVerified publisher19.1.11 of 5See more

zammad zammad 19.1.1

1 of the 5 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
ghcr.io/zammad/zammad:7.2.0-0011f7b62c718bce
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

5,692
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

6,967
csi-driver-nfscsi-driver-nfsVerified publisher4.13.41 of 6See more

csi-driver-nfs csi-driver-nfs 4.13.4

1 of the 6 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

3,611
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

11,045
penpotpenpotOfficialVerified publisher1.10.01 of 5See more

penpot penpot 1.10.0

1 of the 5 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
penpotapp/exporter:2.18.0beb2c2bd9660
expat@2.8.3-1~deb13u1+dhi2
no fix listed

Open the chart page →

5,731
dragonflydragonflyVerified publisher1.8.51 of 3See more

dragonfly dragonfly 1.8.5

1 of the 3 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

4,344
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
expat@2.5.0-1
no fix listed

Open the chart page →

7,195
difydify-helmVerified publisher0.38.04 of 11See more

dify dify-helm 0.38.0

4 of the 11 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
expat@2.5.0-1+deb12u2
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
expat@2.5.0-1+deb12u2
no fix listed
langgenius/dify-sandbox:0.2.15750e1111426e
expat@2.7.5-1
no fix listed
library/nginx:latestabe47724e466
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

71,885
oktetooktetoOfficialVerified publisher0.0.0-2026-08-311 of 10See more

okteto okteto 0.0.0-2026-08-31

1 of the 10 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-313e56bdd1b90d
expat@2.7.1-2
no fix listed

Open the chart page →

5,779
yourlsyourlsOfficialVerified publisher8.10.41 of 2See more

yourls yourls 8.10.4

1 of the 2 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.62f2879125903
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

2,121
openprojectopenproject-helm-chartsOfficialVerified publisher13.12.02 of 5See more

openproject openproject-helm-charts 13.12.0

2 of the 5 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
expat@2.5.0-1+deb12u1
no fix listed
openproject/openproject:17.8.0-slim48952034215d
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

21,702
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

12,133
csi-driver-smbcsi-driver-smbVerified publisher1.20.31 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

1 of the 6 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

3,190
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
expat@2.5.0-1
no fix listed

Open the chart page →

4,509
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
expat@2.5.0-1
no fix listed

Open the chart page →

6,856
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

8,376
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

6,478
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
library/golang:latest3680233e3204
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

8,638
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
expat@2.8.2-1~deb13u1
no fix listed

Open the chart page →

11,900
oneuptimeoneuptimeOfficialVerified publisher14.0.92 of 7See more

oneuptime oneuptime 14.0.9

2 of the 7 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
oneuptime/probe:release2a170032aee8
expat@2.5.0-1+deb12u3
no fix listed
oneuptime/runner:release86060743a718
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

8,770
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
expat@2.7.1-2
no fix listed
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

6,318
prefect-serverprefectVerified publisher2026.9.262342031 of 2See more

prefect-server prefect 2026.9.26234203

1 of the 2 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
prefecthq/prefect:3.8.7-python3.11b3cdfebebff0
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

5,959
codefreshcodefresh-onpremOfficialVerified publisher2.12.181 of 42See more

codefresh codefresh-onprem 2.12.18

1 of the 42 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

16,399
apim3graviteeioVerified publisher4.12.202 of 4See more

apim3 graviteeio 4.12.20

2 of the 4 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.20-debian8f1a14449381
expat@2.8.3-1~deb13u1
no fix listed
graviteeio/apim-management-api:4.12.20-debiand30d085395ca
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

5,021
wordpressgroundhog2k0.16.61 of 1See more

wordpress groundhog2k 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
library/wordpress:7.1.2-apachebb209c8ab111
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,219
supabasetokens-studioVerified publisher1.0.01 of 14See more

supabase tokens-studio 1.0.0

1 of the 14 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
supabase/studio:20241021-9f9b08326d8070c55e9
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

24,354
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
expat@2.5.0-1
no fix listed

Open the chart page →

8,927
budibasebudibase0.0.0-master2 of 7See more

budibase budibase 0.0.0-master

2 of the 7 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
expat@2.5.0-1+deb12u2
no fix listed
budibase/proxy:3.41.38d780b6ee602
expat@2.7.1-2
no fix listed

Open the chart page →

11,186
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

4,164
paperless-ngxfmjstudios0.2.82 of 5See more

paperless-ngx fmjstudios 0.2.8

2 of the 5 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
expat@2.5.0-1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
expat@2.5.0-1
no fix listed

Open the chart page →

32,695
devtron-operatordevtron0.23.31 of 11See more

devtron-operator devtron 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
expat@2.5.0-1
no fix listed

Open the chart page →

34,129
nextcloudgroundhog2k0.22.71 of 3See more

nextcloud groundhog2k 0.22.7

1 of the 3 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
library/nextcloud:35.0.0:35.0.0-apache3e9f6eaa5dc8
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

4,328
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
expat@2.7.1-2
no fix listed

Open the chart page →

6,125
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
expat@2.7.1-2
no fix listed

Open the chart page →

4,957
paperless-ngxpaperless-ngxVerified publisher0.3.231 of 3See more

paperless-ngx paperless-ngx 0.3.23

1 of the 3 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

8,353
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache9e915766488a
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

2,391
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

6,941
cortexcortex3.4.01 of 4See more

cortex cortex 3.4.0

1 of the 4 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
library/nginx:1.31abe47724e466
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,510
wordpresshelmforgeVerified publisher3.0.81 of 3See more

wordpress helmforge 3.0.8

1 of the 3 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
library/wordpress:7.1.2-apache8ae73d594a15
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,614
nginx-ingressnginx-ingress-chartVerified publisher0.0.0-edge1 of 1See more

nginx-ingress nginx-ingress-chart 0.0.0-edge

1 of the 1 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
nginx/nginx-ingress:edged127d1013198
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,338
passboltpassbolt2.2.01 of 6See more

passbolt passbolt 2.2.0

1 of the 6 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
passbolt/passbolt:5.16.0-1-ce1768916a04b1
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

12,608
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-102633.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
expat@2.5.0-1
no fix listed

Open the chart page →

14,659

Container images carrying it

648 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/krateoplatformops/kubectl:1.33.1393d2a3f53a5
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/krateoplatformops/oasgen-provider:0.10.0656ec60c6407
expat@2.7.1-2
no fix listed
1
ghcr.io/krateoplatformops/terminal-client:0.1.36c7c965e739c
expat@2.5.0-1
no fix listed
1
ghcr.io/krateoplatformops/terminal-server:0.1.3f5fd8ba6fea3
expat@2.5.0-1
no fix listed
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
expat@2.7.1-2
no fix listed
1
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
expat@2.5.0-1
no fix listed
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/libretime/icecast:latest4bee94ce480c
expat@2.8.3-1~deb13u1
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
expat@2.5.0-1+deb12u3
no fix listed
1
ghcr.io/lloesche/valheim-server:latestc885aa902faf
expat@2.8.3-1~deb13u1
no fix listed
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
expat@2.8.2-1~deb13u1
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
expat@2.7.1-2
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
expat@2.8.3-1~deb13u1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.28.08b02290f4d18
expat@2.8.3-1~deb13u1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
expat@2.5.0-1
no fix listed
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
expat@2.8.3-1~deb13u1
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
expat@2.7.1-2
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
expat@2.8.3-1~deb13u1
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
expat@2.7.1-2
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
expat@2.5.0-1
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
expat@2.8.3-1~deb13u1
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-17:0.0.0-2026-08-24:0.0.0-2026-08-313e56bdd1b90d
expat@2.7.1-2
no fix listed
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
expat@2.5.0-1
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
expat@2.5.0-1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-fraud-detectiona07ee694304b
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-load-generatorb130d6cee6cb
expat@2.5.0-1+deb12u3
no fix listed
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/open-webui/open-terminal:0.14.0-slimba7a67129bba
expat@2.8.3-1~deb13u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
expat@2.7.1-2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
expat@2.7.1-2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
expat@2.7.1-2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
expat@2.5.0-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
expat@2.5.0-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
expat@2.7.1-2
no fix listed
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
expat@2.5.0-1+deb12u3
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
expat@2.7.1-2
no fix listed
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
expat@2.5.0-1
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
expat@2.8.3-1~deb13u1
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.