StackRadar

CVE-2026-24515

Low

Advisory

Published 23 Jan 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.9
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,199
of 17,787 indexed, latest versions
Container images
1,164
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,199 of 17,787 indexed charts deploy, on 1,164 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+30 more2.1.0-4ubuntu1.4+esm11, 2.1.0-7ubuntu0.16.04.5+esm11, 2.2.5-3ubuntu0.9+esm3, 2.2.9-1ubuntu0.8+esm1+4 more969
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+6 more2.7.4-r0195
OSV records
ALPINE-CVE-2026-24515CGA-7rqm-52vp-qcqqDEBIAN-CVE-2026-24515UBUNTU-CVE-2026-24515
Also known as
CGA-8crp-j9g8-89r5, USN-8022-1, USN-8022-2

Charts affected

1,199 by stars
ChartLatestAffected imagesRadar Score
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1

Open the chart page →

10,598
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
expat@2.2.9-1ubuntu0.2
2.2.9-1ubuntu0.8+esm1

Open the chart page →

10,154
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1

Open the chart page →

10,628
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
expat@2.2.5-3ubuntu0.9
2.2.5-3ubuntu0.9+esm3

Open the chart page →

11,839
terrariahalkeye0.4.21 of 2See more

terraria halkeye 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
ryshe/terraria:latestb1c89f7f359a
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

4,127
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
expat@2.7.1-2
2.8.2-1~deb13u1
instill/mgmt-backend:d0933d4ebe12f77a3f9
expat@2.7.1-2
2.8.2-1~deb13u1
instill/model-backend:611f0f2e980125e5ba5
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

30,816
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
expat@2.6.1-2ubuntu0.1
2.6.1-2ubuntu0.4

Open the chart page →

4,309
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
expat@2.2.9-1ubuntu0.8
2.2.9-1ubuntu0.8+esm1

Open the chart page →

11,582
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm11

Open the chart page →

15,330
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.8+esm1

Open the chart page →

7,901
kubecostmesosphere-stable0.37.52 of 9See more

kubecost mesosphere-stable 0.37.5

2 of the 9 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
expat@2.5.0-1+deb12u1
no fix listed
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
expat@2.6.3-r0
2.7.4-r0

Open the chart page →

17,693
helm-ai-kernelmindburn-labsOfficialVerified publisher0.8.51 of 2See more

helm-ai-kernel mindburn-labs 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
expat@2.6.2-r0
2.7.4-r0

Open the chart page →

2,160
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.672 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

2 of the 3 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
alpine/git:2.47.2062a01ad7a0e
expat@2.7.0-r0
2.7.4-r0
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

5,218
oesopsmxVerified publisher4.0.322 of 25See more

oes opsmx 4.0.32

2 of the 25 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
2.1.0-7ubuntu0.16.04.5+esm11

Open the chart page →

107,811
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

3,327
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
expat@2.7.1-r0
2.7.4-r0

Open the chart page →

2,866
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,435
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
expat@2.4.7-1ubuntu0.6
2.4.7-1ubuntu0.7

Open the chart page →

13,521
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1

Open the chart page →

24,488
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

5,852
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
expat@2.4.7-1ubuntu0.6
2.4.7-1ubuntu0.7

Open the chart page →

5,751
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
expat@2.2.9-1ubuntu0.6
2.2.9-1ubuntu0.8+esm1

Open the chart page →

15,477
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

7,052
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

9,770
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
expat@2.4.7-1
2.4.7-1ubuntu0.7

Open the chart page →

28,534
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
expat@2.4.7-1ubuntu0.2
2.4.7-1ubuntu0.7

Open the chart page →

10,315
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.9+esm3

Open the chart page →

18,137
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4

Open the chart page →

4,378
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
expat@2.4.7-1ubuntu0.2
2.4.7-1ubuntu0.7

Open the chart page →

19,691
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1

Open the chart page →

13,635
agentareaagentareaVerified publisher0.0.181 of 16See more

agentarea agentarea 0.0.18

1 of the 16 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-runner:latestd3c209a5d531
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

14,914
jellyfinalekcVerified publisher0.9.01 of 1See more

jellyfin alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

2,604
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

12,037
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
expat@2.2.5-3ubuntu0.7
2.2.5-3ubuntu0.9+esm3

Open the chart page →

12,046
psonoankra-chartsVerified publisher1.2.01 of 2See more

psono ankra-charts 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
psono/psono-server:5.0.03b974b43ea03
expat@2.6.3-r0
2.7.4-r0

Open the chart page →

2,388
upcloud-csiankra-chartsVerified publisher0.4.01 of 8See more

upcloud-csi ankra-charts 0.4.0

1 of the 8 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
expat@2.7.2-r0
2.7.4-r0

Open the chart page →

14,917
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
expat@2.5.0-1
no fix listed
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
expat@2.5.0-1
no fix listed

Open the chart page →

22,202
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
expat@2.4.7-1ubuntu0.6
2.4.7-1ubuntu0.7

Open the chart page →

7,740
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
expat@2.2.9-1ubuntu0.6
2.2.9-1ubuntu0.8+esm1

Open the chart page →

17,896
dltbrokerassist-iot-distributed-broker0.2.02 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm11
hyperledger/fabric-couchdb:0.4.15f6c724592abf
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm11

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.02 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm11
hyperledger/fabric-couchdb:0.4.15f6c724592abf
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm11

Open the chart page →

77,687
astradnsastradnsVerified publisher0.2.91 of 2See more

astradns astradns 0.2.9

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

2,613
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1

Open the chart page →

13,145
aramid-indexerbiatec-repoVerified publisher3.9.01 of 5See more

aramid-indexer biatec-repo 3.9.0

1 of the 5 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4

Open the chart page →

13,357
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
expat@2.4.7-1ubuntu0.4
2.4.7-1ubuntu0.7

Open the chart page →

7,190
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4

Open the chart page →

5,059
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
expat@2.4.7-1ubuntu0.4
2.4.7-1ubuntu0.7

Open the chart page →

7,190
geoserver-cloudcamptocamp20.0.56 of 11See more

geoserver-cloud camptocamp2 0.0.5

6 of the 11 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1

Open the chart page →

84,444
geoserverCloudcamptocamp20.0.66 of 11See more

geoserverCloud camptocamp2 0.0.6

6 of the 11 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1

Open the chart page →

84,444
carbone-eecarboneOfficialVerified publisher1.0.61 of 1See more

carbone-ee carbone 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
carbone/carbone-ee:full-5.11.0518172cbad49
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

1,619

Container images carrying it

1,164 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/codegen:1.058f91683892d
expat@2.5.0-1
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
expat@2.5.0-1
no fix listed
1
opea/codetrans:1.0e2436483b73d
expat@2.5.0-1
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
expat@2.5.0-1
no fix listed
1
opea/docsum:1.03eaa91849512
expat@2.5.0-1
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
expat@2.5.0-1
no fix listed
1
opea/guardrails-tgi:1.0262c6048aab8
expat@2.5.0-1
no fix listed
1
opea/guardrails-tgi:latestf68bec6a1271
expat@2.5.0-1+deb12u1
no fix listed
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
expat@2.5.0-1
no fix listed
1
opea/speecht5:1.0249afad3d268
expat@2.5.0-1
no fix listed
1
opea/tts:1.0257ae94709e9
expat@2.5.0-1
no fix listed
1
opea/web-retriever-chroma:1.0fe08165d7770
expat@2.5.0-1
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
expat@2.5.0-1+deb12u1
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
expat@2.5.0-1+deb12u2
no fix listed
1
opencsghq/csgship-portal:v1.2.1865814dc87a1
expat@2.7.0-r0
2.7.4-r0
1
opencsghq/kubectl:latestb6d87e1048c2
expat@2.5.0-1+deb12u1
no fix listed
1
opendatacube/explorer:latest120457ffcd69
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4
1
opendatacube/pipelines:wofs-1.225d810e8504b8
expat@2.2.5-3
2.2.5-3ubuntu0.9+esm3
1
opendatacube/restcube:latest91870111837c
expat@2.2.5-3
2.2.5-3ubuntu0.9+esm3
1
opendatacube/wms:latest1b90cdf68831
expat@2.2.5-3
2.2.5-3ubuntu0.9+esm3
1
opendatacube/wps:latest80df355a660b
expat@2.4.7-1ubuntu0.6
2.4.7-1ubuntu0.7
1
openelevation/open-elevation:latest82fb21612e86
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
1
openkm/openkm-ce:6.3.113bc465a7461b
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.8+esm1
1
openmined/syft-backend:0.9.5b72f74a68b32
expat@2.6.4-r1
2.7.4-r0
1
openproject/hocuspocus:release-338001b288dc1359dfb5
expat@2.5.0-1+deb12u1
no fix listed
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
expat@2.2.9-1ubuntu0.6
2.2.9-1ubuntu0.8+esm1
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
expat@2.2.9-1ubuntu0.6
2.2.9-1ubuntu0.8+esm1
1
openthread/otbr:latestf307f59f6432
expat@2.2.5-3ubuntu0.9
2.2.5-3ubuntu0.9+esm3
1
openvino/model_server:2025.2.11e7cd1d70cc1
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.9+esm3
1
opsmx11/issuegen:v2.1.05c50ca123d88
expat@2.1.0-4ubuntu1.4
2.1.0-4ubuntu1.4+esm11
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
expat@2.7.0-r0
2.7.4-r0
1
owncloud/ocis:7.1.388e7c854517d
expat@2.7.0-r0
2.7.4-r0
1
owncloud/server:10.15.051d9b74fc2a8
expat@2.2.9-1ubuntu0.6
2.2.9-1ubuntu0.8+esm1
1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
expat@2.7.1-2
2.8.2-1~deb13u1
1
penpotapp/backend:2.2.147853d9bb9dd
expat@2.4.7-1ubuntu0.4
2.4.7-1ubuntu0.7
1
penpotapp/exporter:2.2.15c835ffd87ab
expat@2.4.7-1ubuntu0.4
2.4.7-1ubuntu0.7
1
phan2410/dummy-service:0.0.89c6ed6de26ca
expat@2.5.0-1+deb12u1
no fix listed
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
expat@2.5.0-1+deb12u1
no fix listed
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
expat@2.4.7-1ubuntu0.2
2.4.7-1ubuntu0.7
1
photoprism/photoprism:220629-jammy2954334adbda
expat@2.4.7-1
2.4.7-1ubuntu0.7
1
photoprism/photoprism:251130db16ee6b1ba3
expat@2.7.1-2
2.7.1-2ubuntu0.2
1
photoprism/photoprism:240711-cefc6fd632ca74
expat@2.6.1-2build1
2.6.1-2ubuntu0.4
1
phpipam/phpipam-cron:v1.7.354468713454e
expat@2.6.4-r0
2.7.4-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
expat@2.6.4-r0
2.7.4-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
expat@2.7.1-2
2.8.2-1~deb13u1
1
pk910/powfaucet:v2-stable3dcae6a62896
expat@2.5.0-1+deb12u1
no fix listed
1
platzio/backend:v0.6.5d5e5972f344b
expat@2.7.1-r0
2.7.4-r0
1
pmoscode/excalidraw:v0.18.08ee61554699c
expat@2.7.3-r0
2.7.4-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.