StackRadar

CVE-2026-11979

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,253
of 17,787 indexed, latest versions
Container images
1,102
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 1,253 of 17,787 indexed charts deploy, on 1,102 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 more2.12.7+dfsg+really2.9.14-2.1+deb13u2+e7858
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+25 more0:2.9.7-21.el8_10.7, 0:2.12.5-10.el10_2.3, 2.12.10-150700.4.14.1, 2.15.3-2.1244
OSV records
DEBIAN-CVE-2026-11979UBUNTU-CVE-2026-11979RHSA-2026:60394RHSA-2026:61248RLSA-2026:60394RLSA-2026:61248ECHO-eb03-65da-1e8copenSUSE-SU-2026:11258-1SUSE-SU-2026:3097-1

Charts affected

1,253 by stars
ChartLatestAffected imagesRadar Score
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

7,466
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,252
reportportalreportportal-ioOfficialVerified publisher26.8.121 of 15See more

reportportal reportportal-io 26.8.12

1 of the 15 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

11,943
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
libxml2@2.9.13+dfsg-1ubuntu0.6
no fix listed

Open the chart page →

7,487
retyc-csiretyc-csi0.2.01 of 3See more

retyc-csi retyc-csi 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,306
atuinrm3lVerified publisher0.11.01 of 3See more

atuin rm3l 0.11.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,548
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

9,885
mac-ouirm3lVerified publisher1.25.01 of 1See more

mac-oui rm3l 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
rm3l/mac-oui:1.8.03a5e1f95c132
libxml2@2.9.7-18.el8_9
0:2.9.7-21.el8_10.7

Open the chart page →

1,975
kimai2robjuz5.0.141 of 2See more

kimai2 robjuz 5.0.14

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
kimai/kimai2:2.67.03084f1e5ecdc
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

4,508
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

5,508
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

7,767
postgresromanow-helm-chartsVerified publisher1.7.11 of 1See more

postgres romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,638
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed

Open the chart page →

13,028
rstudio-pmrstudioVerified publisher0.20.51 of 1See more

rstudio-pm rstudio 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,368
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

5,321
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
no fix listed

Open the chart page →

13,562
kyoorubxkubeVerified publisher0.1.102 of 9See more

kyoo rubxkube 0.1.10

2 of the 9 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

30,310
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

38,115
teamcityscalified-teamcityVerified publisher2026.2.01 of 3See more

teamcity scalified-teamcity 2026.2.0

1 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,638
securosecuroVerified publisher0.15.11 of 4See more

securo securo 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
pgvector/pgvector:pg16ccc6e83d6e35
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

3,350
immichsecustorVerified publisher2.0.51 of 1See more

immich secustor 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,011
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.683dbca3efd2a
libxml2@2.9.7-19.el8_10
0:2.9.7-21.el8_10.7
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

16,194
mssqlserver-2019simcube1.2.31 of 1See more

mssqlserver-2019 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
no fix listed

Open the chart page →

6,864
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

4,920
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.7
altinity/metrics-exporter:0.20.01a46d104406d
libxml2@2.9.7-16.el8
0:2.9.7-21.el8_10.7

Open the chart page →

6,420
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed

Open the chart page →

46,028
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed

Open the chart page →

14,504
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

7,157
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

4,390
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,688
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

10,405
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
libxml2@2.9.13+dfsg-1ubuntu0.10
no fix listed

Open the chart page →

2,622
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
libxml2@2.9.7-13.el8_6.1
0:2.9.7-21.el8_10.7

Open the chart page →

11,459
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed

Open the chart page →

13,532
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
libxml2@2.9.10+dfsg-5
no fix listed

Open the chart page →

24,984
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

3,253
mumblesyntaxerror404Verified publisher1.0.41 of 1See more

mumble syntaxerror404 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

2,138
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,402
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

3,804
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

3,804
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

12,137
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

26,843
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
opennode/waldur-mastermind:8.1.24c82b15d9042
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,870
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed

Open the chart page →

15,984
cockroachdbwenerme22.0.32 of 3See more

cockroachdb wenerme 22.0.3

2 of the 3 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v26.3.1204f131510c7
libxml2@2.12.5-10.el10_2.2
0:2.12.5-10.el10_2.3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
libxml2@2.9.7-21.el8_10.4
0:2.9.7-21.el8_10.7

Open the chart page →

763
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
libxml2@2.9.1+dfsg1-3ubuntu4.3
no fix listed

Open the chart page →

41,455
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libxml2@2.9.10+dfsg-5ubuntu0.20.04.9
no fix listed

Open the chart page →

7,883
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

7,728

Container images carrying it

1,102 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
libxml2@2.12.5-10.el10_2.2
0:2.12.5-10.el10_2.3
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
libxml2@2.12.5-10.el10_2.2
0:2.12.5-10.el10_2.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.