StackRadar

CVE-2026-25896

Critical

Advisory

Published 20 Feb 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
79
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
1 of 1
affected package

fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

Carried by container images the latest versions of 79 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
fast-xml-parsernpm4.2.5, 4.2.6, 4.3.5, 4.3.6+8 more4.5.4, 5.3.579
OSV records
GHSA-m7jm-9gc2-mpf2

Charts affected

79 by stars
ChartLatestAffected imagesRadar Score
finance-portalmojaloop5.1.42 of 11See more

finance-portal mojaloop 5.1.4

2 of the 11 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-xml-parser@4.5.3
4.5.4
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

2,318
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

2,457
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
fast-xml-parser@4.4.1
4.5.4

Open the chart page →

11,643
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
fast-xml-parser@5.2.5
5.3.5

Open the chart page →

4,960
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
fast-xml-parser@4.2.5
4.5.4

Open the chart page →

6,982
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
fast-xml-parser@5.2.5
5.3.5

Open the chart page →

2,383
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
fast-xml-parser@4.5.0
4.5.4

Open the chart page →

4,219
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
fast-xml-parser@5.2.5
5.3.5

Open the chart page →

1,811
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
fast-xml-parser@5.2.5
5.3.5

Open the chart page →

4,600
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
fast-xml-parser@4.4.1
4.5.4

Open the chart page →

5,338
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fast-xml-parser@5.2.5
5.3.5

Open the chart page →

5,819
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
fast-xml-parser@4.2.5
4.5.4

Open the chart page →

4,744
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
fast-xml-parser@4.2.5
4.5.4

Open the chart page →

4,285
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
fast-xml-parser@4.2.6
4.5.4

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
fast-xml-parser@4.2.6
4.5.4

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
fast-xml-parser@4.2.6
4.5.4

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

11,100
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
fast-xml-parser@5.2.5
5.3.5

Open the chart page →

5,535
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
fast-xml-parser@5.2.1
5.3.5

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

3,746
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
fast-xml-parser@4.4.1
4.5.4

Open the chart page →

6,285
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-25896.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
fast-xml-parser@4.2.5
4.5.4

Open the chart page →

16,083

Container images carrying it

79 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
agoldis/sorry-cypress-director:2.5.1110228ecd353b
fast-xml-parser@4.2.5
4.5.4
2
louislam/uptime-kuma:2.3.29aeb4e51d038
fast-xml-parser@5.2.5
5.3.5
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-xml-parser@4.5.3
4.5.4
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-xml-parser@4.5.3
4.5.4
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-xml-parser@4.5.3
4.5.4
2
rajnandan1/kener:3.2.1930407afca731
fast-xml-parser@5.2.1
5.3.5
2
activepieces/activepieces:0.90.430c10a04fe3d
fast-xml-parser@5.2.5
5.3.5
1
automatischio/automatisch:0.15.03bace7a12d5f
fast-xml-parser@4.5.0
4.5.4
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
fast-xml-parser@4.2.5
4.5.4
1
countly/api:25.05.4f4cc7447c4f5
fast-xml-parser@4.3.6
4.5.4
1
countly/countly-server:25.05.4e3c238248f99
fast-xml-parser@4.3.6
4.5.4
1
countly/frontend:25.05.42acbc11499b6
fast-xml-parser@4.3.6
4.5.4
1
cryptexlabs/authf:0.12.11189c07411d7c
fast-xml-parser@4.4.1
4.5.4
1
directus/directus:11.1.0e3c8bb975350
fast-xml-parser@4.2.5
4.5.4
1
documenso/documenso:v1.8.17f16a9449f18
fast-xml-parser@4.2.5
4.5.4
1
evoapicloud/evolution-api:latest966625532d90
fast-xml-parser@4.5.3
4.5.4
1
fallenbagel/jellyseerr:latest4538137bc5af
fast-xml-parser@4.5.3
4.5.4
1
fosrl/pangolin:1.13.0c32ad797ab96
fast-xml-parser@5.2.5
5.3.5
1
joplin/server:latest3f7b852959aa
fast-xml-parser@5.2.5
5.3.5
1
library/ghost:6.25.12654b1e90413
fast-xml-parser@5.2.5
5.3.5
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
fast-xml-parser@5.2.5
5.3.5
1
library/kibana:8.18.004c0fc150f3a
fast-xml-parser@4.4.1
4.5.4
1
lobehub/lobe-chat:1.96.9da0c21fefcd3
fast-xml-parser@4.4.1
4.5.4
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
fast-xml-parser@5.2.5
5.3.5
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
fast-xml-parser@4.2.5
4.5.4
1
louislam/uptime-kuma:13d632903e6af
fast-xml-parser@5.2.5
5.3.5
1
louislam/uptime-kuma:2.0.24c364ef96aad
fast-xml-parser@5.2.5
5.3.5
1
louislam/uptime-kuma:1.23.1396510915e6be
fast-xml-parser@4.2.5
4.5.4
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
fast-xml-parser@5.2.5
5.3.5
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
fast-xml-parser@4.2.5
4.5.4
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
fast-xml-parser@4.4.1
4.5.4
1
moreillon/camera-proxy:latestce60056b50c2
fast-xml-parser@4.4.1
4.5.4
1
moreillon/food-manager:lateste8fd856e593d
fast-xml-parser@4.4.1
4.5.4
1
n8nio/n8n:1.86.08b39ed5a2de9
fast-xml-parser@4.4.1
4.5.4
1
n8nio/n8n:1.33.1dd171d45102a
fast-xml-parser@4.3.5
4.5.4
1
neoskop/papergirl:3.2.67f52b5949f03
fast-xml-parser@4.2.5
4.5.4
1
nocodb/nocodb:0.258.06779a4ddedf2
fast-xml-parser@4.5.0
4.5.4
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
fast-xml-parser@4.4.0
4.5.4
1
outlinewiki/outline:0.82.0494dfb9249a6
fast-xml-parser@4.4.1
4.5.4
1
soulteary/cronicle:0.9.80ac2512fa6e39
fast-xml-parser@4.4.1
4.5.4
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
fast-xml-parser@4.2.6
4.5.4
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
fast-xml-parser@4.4.0
4.5.4
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
fast-xml-parser@4.4.0
4.5.4
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
fast-xml-parser@4.4.0
4.5.4
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
fast-xml-parser@4.4.0
4.5.4
1
speckle/speckle-server:2.26.379f14a2bf931
fast-xml-parser@4.5.3
4.5.4
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
fast-xml-parser@4.2.6
4.5.4
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
fast-xml-parser@4.4.0
4.5.4
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
fast-xml-parser@4.2.6
4.5.4
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
fast-xml-parser@4.4.0
4.5.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.