StackRadar

CVE-2026-11979

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,246
of 17,790 indexed, latest versions
Container images
1,091
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 1,246 of 17,790 indexed charts deploy, on 1,091 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 more2.12.7+dfsg+really2.9.14-2.1+deb13u2+e7847
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+25 more0:2.9.7-21.el8_10.7, 0:2.12.5-10.el10_2.3, 2.12.10-150700.4.14.1, 2.15.3-2.1244
OSV records
DEBIAN-CVE-2026-11979UBUNTU-CVE-2026-11979RHSA-2026:60394RHSA-2026:61248RLSA-2026:60394RLSA-2026:61248ECHO-eb03-65da-1e8copenSUSE-SU-2026:11258-1SUSE-SU-2026:3097-1

Charts affected

1,246 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,091 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
mbround18/valheim:3.1.070bd4da591cd
libxml2@2.9.13+dfsg-1ubuntu0.6
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
middlewareeng/middleware:0.3.1747d880812f1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mindsdb/mindsdb:latest163011c09299
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
minio/kes:v0.22.255f3aef5803e
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.7
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.7
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.7
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.7
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.7
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.7
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.7
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
libxml2@2.9.7-15.el8
0:2.9.7-21.el8_10.7
1
minio/operator:v5.0.9170b154d2c61
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.7
1
minio/operator:v4.1.02adc5be088f5
libxml2@2.9.7-9.el8
0:2.9.7-21.el8_10.7
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/camera-viewer:lateste418cc694bd5
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
moreillon/group-manager-front:latest5f0a38498271
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
moreillon/user-manager-front:v5.1.06597e6b98d21
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
no fix listed
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed
1
netdata/netdata:v2.11.0c45c71eb23ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libxml2@2.9.3+dfsg1-1ubuntu0.6
no fix listed
1
nginxinc/nginx-unprivileged:latest4210a3296e7c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
nginx/nginx-ingress:edge520d439f9a9a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
nirmalnaveen/supermario:latest8541a39162f3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
nutanix/cn-rwx-operator:1.1.00082e0cebd42
libxml2@2.12.5-10.el10_2.1
0:2.12.5-10.el10_2.3
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
no fix listed
1
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
libxml2@2.9.3+dfsg1-1ubuntu0.5
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.