CVE-2026-25210
HighAdvisory
Published 30 Jan 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.8
- base score, highest
- EPSS
- 0.002
- 10th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,208
- of 17,790 indexed, latest versions
- Container images
- 1,176
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 1,208 of 17,790 indexed charts deploy, on 1,176 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| expatdeb | 2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+30 more | 2.1.0-4ubuntu1.4+esm11, 2.1.0-7ubuntu0.16.04.5+esm11, 2.2.5-3ubuntu0.9+esm3, 2.2.9-1ubuntu0.8+esm1+4 more | 978 |
| expatapk | 2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+6 more | 2.7.4-r0 | 198 |
- OSV records
- ALPINE-CVE-2026-25210DEBIAN-CVE-2026-25210CGA-5v3h-h3q3-xg43UBUNTU-CVE-2026-25210
- Also known as
- CGA-mf53-85qx-vr2x, USN-8022-1, USN-8022-2
Charts affected
1,208 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| longhornwenerme | 1.2.3 | 1 of 2See more | 15,288 |
| wexa-studiowexa-studio | 1.2.0 | 1 of 15See more | 15,044 |
| jaegerwikimedia | 3.1.2 | 1 of 4See more | 9,320 |
| kibanawiremindVerified publisher | 8.5.23 | 1 of 2See more | 6,326 |
| marge-botwiremindVerified publisher | 1.4.4 | 1 of 1See more | 5,559 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,173 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,697 |
| xkopsxkops | 0.1.0 | 2 of 5See more | 13,783 |
Container images carrying it
1,176 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.