StackRadar

CVE-2026-24515

Low

Advisory

Published 23 Jan 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.9
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,208
of 17,790 indexed, latest versions
Container images
1,176
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,208 of 17,790 indexed charts deploy, on 1,176 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+30 more2.1.0-4ubuntu1.4+esm11, 2.1.0-7ubuntu0.16.04.5+esm11, 2.2.5-3ubuntu0.9+esm3, 2.2.9-1ubuntu0.8+esm1+4 more978
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+6 more2.7.4-r0198
OSV records
ALPINE-CVE-2026-24515CGA-7rqm-52vp-qcqqDEBIAN-CVE-2026-24515UBUNTU-CVE-2026-24515
Also known as
CGA-8crp-j9g8-89r5, USN-8022-1, USN-8022-2

Charts affected

1,208 by stars
ChartLatestAffected imagesRadar Score
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1

Open the chart page →

15,288
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
expat@2.7.1-r0
2.7.4-r0

Open the chart page →

15,044
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
expat@2.4.7-1ubuntu0.2
2.4.7-1ubuntu0.7

Open the chart page →

9,320
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
expat@2.2.9-1ubuntu0.8
2.2.9-1ubuntu0.8+esm1

Open the chart page →

6,326
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
expat@2.5.0-1
no fix listed

Open the chart page →

5,559
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
expat@2.4.7-1ubuntu0.3
2.4.7-1ubuntu0.7

Open the chart page →

14,173
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

7,697
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-24515.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
expat@2.6.3-r0
2.7.4-r0

Open the chart page →

13,783

Container images carrying it

1,176 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
xeladock/nginx2:latestc259a67b1dff
expat@2.4.7-1
2.4.7-1ubuntu0.7
1
xeotek/kadeck:6.3.439a3b37a17c5
expat@2.4.7-1ubuntu0.6
2.4.7-1ubuntu0.7
1
xeotek/kadeck:4.2.94c6b04d9ce55
expat@2.2.9-1ubuntu0.6
2.2.9-1ubuntu0.8+esm1
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
expat@2.5.0-1
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
expat@2.5.0-1
no fix listed
1
ymuski/geo-checker:5.0.05ba7fd8c7bdc
expat@2.7.3-r0
2.7.4-r0
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
expat@2.7.3-r0
2.7.4-r0
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
expat@2.7.3-r0
2.7.4-r0
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
expat@2.7.3-r0
2.7.4-r0
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
expat@2.7.3-r0
2.7.4-r0
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
expat@2.6.1-2ubuntu0.2
2.6.1-2ubuntu0.4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
expat@2.2.9-1build1
2.2.9-1ubuntu0.8+esm1
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
expat@2.4.7-1
2.4.7-1ubuntu0.7
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
expat@2.4.7-1
2.4.7-1ubuntu0.7
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
expat@2.7.1-r0
2.7.4-r0
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.9+esm3
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm11
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm11
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
expat@2.5.0-1
no fix listed
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
expat@2.7.3-r0
2.7.4-r0
1
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
expat@2.5.0-1+deb12u3
no fix listed
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
expat@2.6.1-2ubuntu0.3
2.6.1-2ubuntu0.4
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
expat@2.4.7-1ubuntu0.4
2.4.7-1ubuntu0.7
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
expat@2.6.4-r0
2.7.4-r0
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
expat@2.4.7-1ubuntu0.2
2.4.7-1ubuntu0.7
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
expat@2.7.0-r0
2.7.4-r0
1
ghcr.io/appscode/marketplace-ui:0.3.1d52177072013
expat@2.6.4-r0
2.7.4-r0
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
expat@2.4.7-1ubuntu0.3
2.4.7-1ubuntu0.7
1
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
expat@2.5.0-1
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
expat@2.4.7-1ubuntu0.5
2.4.7-1ubuntu0.7
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
expat@2.4.7-1ubuntu0.2
2.4.7-1ubuntu0.7
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
expat@2.7.1-r3
2.7.4-r0
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
expat@2.2.9-1ubuntu0.6
2.2.9-1ubuntu0.8+esm1
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
expat@2.5.0-1
no fix listed
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
expat@2.4.7-1ubuntu0.2
2.4.7-1ubuntu0.7
1
ghcr.io/caninehq/canine:latesta058034ca006
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
expat@2.5.0-1+deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.