StackRadar

CVE-2026-11979

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,253
of 17,787 indexed, latest versions
Container images
1,102
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 1,253 of 17,787 indexed charts deploy, on 1,102 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 more2.12.7+dfsg+really2.9.14-2.1+deb13u2+e7858
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+25 more0:2.9.7-21.el8_10.7, 0:2.12.5-10.el10_2.3, 2.12.10-150700.4.14.1, 2.15.3-2.1244
OSV records
DEBIAN-CVE-2026-11979UBUNTU-CVE-2026-11979RHSA-2026:60394RHSA-2026:61248RLSA-2026:60394RLSA-2026:61248ECHO-eb03-65da-1e8copenSUSE-SU-2026:11258-1SUSE-SU-2026:3097-1

Charts affected

1,253 by stars
ChartLatestAffected imagesRadar Score
jellyfinjellyfinVerified publisher0.3.301 of 1See more

jellyfin jellyfin 0.3.30

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,571
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.7

Open the chart page →

9,318
web-chartkbt-ktcloudlab0.1.01 of 1See more

web-chart kbt-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
app-componentkeltio-helm-chartsVerified publisher3.14.01 of 1See more

app-component keltio-helm-charts 3.14.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
kikplatekikplateVerified publisher0.22.01 of 3See more

kikplate kikplate 0.22.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,783
glpikitsune-itopsVerified publisher1.0.71 of 3See more

glpi kitsune-itops 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
glpi/glpi:latest4b681082a79e
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,878
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

20,424
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
libxml2@2.9.13+dfsg-1ubuntu0.11
no fix listed

Open the chart page →

9,975
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

114,025
ohifkylesferrazzaVerified publisher0.1.01 of 2See more

ohif kylesferrazza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
jodogne/orthanc-plugins:latest6ff510aa29c2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,524
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

3,551
checkoutlabs64io-helm-chartsVerified publisher0.8.01 of 3See more

checkout labs64io-helm-charts 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,638
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,708
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

4,011
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

35,058
fhir-serverlinuxforhealth0.9.11 of 2See more

fhir-server linuxforhealth 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.7

Open the chart page →

1,052
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

7,216
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

5,747
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,741
magentomagento3.2.33 of 12See more

magento magento 3.2.3

3 of the 12 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
libxml2@2.12.10-150700.4.6.1
2.12.10-150700.4.14.1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
libxml2@2.12.10-150700.4.6.1
2.12.10-150700.4.14.1
longhornio/longhorn-ui:v1.10.0e60f36161511
libxml2@2.12.10-150700.4.6.1
2.12.10-150700.4.14.1

Open the chart page →

13,582
mcp-orchestratormagertronVerified publisher3.8.231 of 6See more

mcp-orchestrator magertron 3.8.23

1 of the 6 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
curtismager20/mcp-orchestrator:3.8.231f11a1001dab
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,704
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,764
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
libxml2@2.9.14+dfsg-1.3ubuntu3
no fix listed

Open the chart page →

4,184
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-21.el8_10.7

Open the chart page →

6,915
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
libxml2@2.14.5+dfsg-0.2
no fix listed

Open the chart page →

11,108
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,763
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
library/redmine:6.1.204ac44a2595b
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

7,552
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
spring-helmnaveenalla-springboot1.0.01 of 2See more

spring-helm naveenalla-springboot 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,638
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

14,324
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,051
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxml2@2.9.14+dfsg-1.2
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

14,862
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,833
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

22,678
opsopsVerified publisher1.2.01 of 2See more

ops ops 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
shaowenchen/ops-server:latest315444f703f4
libxml2@2.9.13+dfsg-1ubuntu0.9
no fix listed

Open the chart page →

9,049
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,694
paperless-ngxpaperlessVerified publisher0.4.02 of 3See more

paperless-ngx paperless 0.4.0

2 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

8,510
patch-operatorpatch-operator0.1.111 of 2See more

patch-operator patch-operator 0.1.11

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
libxml2@2.9.7-9.el8_4.2
0:2.9.7-21.el8_10.7

Open the chart page →

7,833
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

7,075
playgroundplayground0.1.11 of 1See more

playground playground 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
matomopockostVerified publisher1.3.01 of 3See more

matomo pockost 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
pockost/matomo:5.13.07f5d293cbe4e
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,102
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

31,949
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,638
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

8,203
pzserverpzserver0.1.171 of 2See more

pzserver pzserver 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
lis314/project-zomboid-docker:latestaa2089c37920
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

3,022
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

24,038

Container images carrying it

1,102 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
libxml2@2.12.5-10.el10_2.2
0:2.12.5-10.el10_2.3
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
libxml2@2.12.5-10.el10_2.2
0:2.12.5-10.el10_2.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.