StackRadar

CVE-2026-26278

High

Advisory

Published 17 Feb 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
79
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
1 of 1
affected package

fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)

Carried by container images the latest versions of 79 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
fast-xml-parsernpm4.2.5, 4.2.6, 4.3.5, 4.3.6+8 more4.5.4, 5.3.679
OSV records
GHSA-jmr7-xgp7-cmfj

Charts affected

79 by stars
ChartLatestAffected imagesRadar Score
finance-portalmojaloop5.1.42 of 11See more

finance-portal mojaloop 5.1.4

2 of the 11 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-xml-parser@4.5.3
4.5.4
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

2,318
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

2,457
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
fast-xml-parser@4.4.1
4.5.4

Open the chart page →

11,643
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
fast-xml-parser@5.2.5
5.3.6

Open the chart page →

4,960
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
fast-xml-parser@4.2.5
4.5.4

Open the chart page →

6,982
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
fast-xml-parser@5.2.5
5.3.6

Open the chart page →

2,383
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
fast-xml-parser@4.5.0
4.5.4

Open the chart page →

4,219
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
fast-xml-parser@5.2.5
5.3.6

Open the chart page →

1,811
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
fast-xml-parser@5.2.5
5.3.6

Open the chart page →

4,600
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
fast-xml-parser@4.4.1
4.5.4

Open the chart page →

5,338
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fast-xml-parser@5.2.5
5.3.6

Open the chart page →

5,819
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
fast-xml-parser@4.2.5
4.5.4

Open the chart page →

4,744
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
fast-xml-parser@4.2.5
4.5.4

Open the chart page →

4,285
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
fast-xml-parser@4.2.6
4.5.4

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
fast-xml-parser@4.2.6
4.5.4

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
fast-xml-parser@4.2.6
4.5.4

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
fast-xml-parser@4.4.0
4.5.4

Open the chart page →

11,100
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
fast-xml-parser@5.2.5
5.3.6

Open the chart page →

5,535
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
fast-xml-parser@5.2.1
5.3.6

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
fast-xml-parser@4.5.3
4.5.4

Open the chart page →

3,746
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
fast-xml-parser@4.4.1
4.5.4

Open the chart page →

6,285
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-26278.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
fast-xml-parser@4.2.5
4.5.4

Open the chart page →

16,083

Container images carrying it

79 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
supabase/storage-api:v1.12.0f983fb50bd95
fast-xml-parser@4.4.1
4.5.4
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
fast-xml-parser@4.2.5
4.5.4
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
fast-xml-parser@4.4.1
4.5.4
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
fast-xml-parser@5.3.4
5.3.6
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
fast-xml-parser@5.2.5
5.3.6
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
fast-xml-parser@4.4.1
4.5.4
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
fast-xml-parser@5.0.9
5.3.6
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
fast-xml-parser@4.4.1
4.5.4
1
ghcr.io/data-fair/notify:3c739b74dabb0
fast-xml-parser@4.5.3
4.5.4
1
ghcr.io/data-fair/processings:15a9216989707
fast-xml-parser@4.2.5
4.5.4
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
fast-xml-parser@4.5.3
4.5.4
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
fast-xml-parser@4.4.1
4.5.4
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
fast-xml-parser@5.2.5
5.3.6
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
fast-xml-parser@5.2.5
5.3.6
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
fast-xml-parser@5.2.5
5.3.6
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
fast-xml-parser@4.4.1
4.5.4
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
fast-xml-parser@4.4.1
4.5.4
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
fast-xml-parser@4.2.5
4.5.4
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
fast-xml-parser@4.2.5
4.5.4
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
fast-xml-parser@4.2.5
4.5.4
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
fast-xml-parser@5.2.1
5.3.6
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fast-xml-parser@5.2.5
5.3.6
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
fast-xml-parser@5.2.5
5.3.6
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
fast-xml-parser@5.2.5
5.3.6
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
fast-xml-parser@4.5.3
4.5.4
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
fast-xml-parser@4.2.5
4.5.4
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
fast-xml-parser@4.2.5
4.5.4
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
fast-xml-parser@4.2.5
4.5.4
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
fast-xml-parser@4.2.5
4.5.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.