StackRadar

CVE-2026-11979

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,253
of 17,790 indexed, latest versions
Container images
1,104
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 1,253 of 17,790 indexed charts deploy, on 1,104 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 more2.12.7+dfsg+really2.9.14-2.1+deb13u2+e7860
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+25 more0:2.9.7-21.el8_10.7, 0:2.12.5-10.el10_2.3, 2.12.10-150700.4.14.1, 2.15.3-2.1244
OSV records
DEBIAN-CVE-2026-11979UBUNTU-CVE-2026-11979RHSA-2026:60394RHSA-2026:61248RLSA-2026:60394RLSA-2026:61248ECHO-eb03-65da-1e8copenSUSE-SU-2026:11258-1SUSE-SU-2026:3097-1

Charts affected

1,253 by stars
ChartLatestAffected imagesRadar Score
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.7

Open the chart page →

29,564
longhornrelease-longhorn1.12.03 of 3See more

longhorn release-longhorn 1.12.0

3 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.12.0fd245bae2e82
libxml2@2.12.10-150700.4.11.1
2.12.10-150700.4.14.1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
libxml2@2.12.10-150700.4.11.1
2.12.10-150700.4.14.1
longhornio/longhorn-ui:v1.12.03870d52a2b0a
libxml2@2.12.10-150700.4.11.1
2.12.10-150700.4.14.1

Open the chart page →

1,579
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,315
my-nginx-apprepo-for-helm-nginx-app0.1.01 of 1See more

my-nginx-app repo-for-helm-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,849
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,273
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

7,116
kresusrm3lVerified publisher0.2.12 of 3See more

kresus rm3l 0.2.1

2 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
bnjbvr/kresus:0.22.137e216b182c8
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

15,681
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

9,327
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.7

Open the chart page →

5,430
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

9,299
reviewboardrock8sVerified publisher0.0.12 of 3See more

reviewboard rock8s 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

6,159
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

9,685
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
libxml2@2.9.13+dfsg-1ubuntu0.2
no fix listed

Open the chart page →

13,011
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.7

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

68,695
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

33,180
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

3,908
rosette-serverrosette-serverOfficialVerified publisher3.6.01 of 3See more

rosette-server rosette-server 3.6.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
rosette/root-rli:7.23.21.c82.0a4467d3bb211
libxml2@2.9.7-21.el8_10.5
0:2.9.7-21.el8_10.7

Open the chart page →

189
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

6,954
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
libxml2@2.9.13+dfsg-1ubuntu0.11
no fix listed

Open the chart page →

7,527
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

10,638
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

27,554
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,626
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

7,440
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,528
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed

Open the chart page →

6,303
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,659
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

30,517
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libxml2@2.9.13+dfsg-1ubuntu0.6
no fix listed

Open the chart page →

8,733
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed

Open the chart page →

9,631
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
libxml2@2.9.13+dfsg-1ubuntu0.11
no fix listed

Open the chart page →

7,403
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
no fix listed

Open the chart page →

19,707
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
no fix listed

Open the chart page →

16,739
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

10,237
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

4,127
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

9,853
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,377
postgresqlsb-helm-charts0.4.01 of 1See more

postgresql sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:16.11468e1f126ca5
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,397
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,618
postgresscalified-postgresVerified publisher18.4.01 of 1See more

postgres scalified-postgres 18.4.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,684
s3-backupschichtelVerified publisher0.10.01 of 1See more

s3-backup schichtel 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,372
wordpressschichtelVerified publisher0.10.102 of 2See more

wordpress schichtel 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

8,275
otterwikischmitzis0.1.01 of 1See more

otterwiki schmitzis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
redimp/otterwiki:2778bf30da3da
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

3,246
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
libxml2@2.9.14+dfsg-1.3ubuntu3.4
no fix listed

Open the chart page →

6,167
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

3,022
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libxml2@2.15.2+dfsg-0.1
no fix listed

Open the chart page →

10,445
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

4,916
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.7

Open the chart page →

22,349
postgresself-hosters-by-nightVerified publisher0.14.31 of 1See more

postgres self-hosters-by-night 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,397
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

5,500

Container images carrying it

1,104 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
libxml2@2.9.7-12.el8_5
0:2.9.7-21.el8_10.7
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
libxml2@2.12.5-10.el10_2.2
0:2.12.5-10.el10_2.3
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
libxml2@2.12.5-10.el10_2.2
0:2.12.5-10.el10_2.3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.