StackRadar

CVE-2026-11979

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,253
of 17,787 indexed, latest versions
Container images
1,102
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 1,253 of 17,787 indexed charts deploy, on 1,102 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 more2.12.7+dfsg+really2.9.14-2.1+deb13u2+e7858
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+25 more0:2.9.7-21.el8_10.7, 0:2.12.5-10.el10_2.3, 2.12.10-150700.4.14.1, 2.15.3-2.1244
OSV records
DEBIAN-CVE-2026-11979UBUNTU-CVE-2026-11979RHSA-2026:60394RHSA-2026:61248RLSA-2026:60394RLSA-2026:61248ECHO-eb03-65da-1e8copenSUSE-SU-2026:11258-1SUSE-SU-2026:3097-1

Charts affected

1,253 by stars
ChartLatestAffected imagesRadar Score
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-21.el8_10.7

Open the chart page →

3,697
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-11979.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed

Open the chart page →

7,916

Container images carrying it

1,102 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jbtronics/part-db1:latest5db71f6db59d
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jodogne/orthanc-plugins:latest6ff510aa29c2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
kixote/typemill4e9dff179519
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
kixote/typemill628f79a08cc7
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
kong/kong-ai-gateway:2.0.3367ed5985b76
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
kubeflow/model-registry:v0.2.95783f6db428f
libxml2@2.9.7-18.el8_10.1
0:2.9.7-21.el8_10.7
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed
1
kuberay/operator:v1.0.04e6ac8a3a2c4
libxml2@2.9.7-16.el8_8.1
0:2.9.7-21.el8_10.7
1
kuzwolka/aws9:main1ad759b961b1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
laly9999/node-app:1dd0e503913e1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
lancachenet/monolithic:latest37f28b362c93
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libxml2@2.9.14+dfsg-1.3ubuntu3.6
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
library/httpd:2.4.631ae8051591a5
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
1
library/matomo:5.1.2-apache2415789e1602
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
library/matomo:5.13.0-apache8e6bdd396496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
library/nextcloud:34.0.4-apachede4ad9389386
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
library/nginx:1.27.409369da6b103
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
library/nginx:1.291881968aff6f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
library/nginx:1.276784fb0834aa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.