StackRadar

CVE-2026-32313

High

Advisory

Published 13 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

Carried by container images the latest versions of 21 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
robrichards/xmlseclibscomposer3.0.1, 3.1.1, 3.1.33.1.515
OSV records
GHSA-4v26-v6cg-g6f9

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
zabbixzabbix-communityVerified publisher7.1.01 of 5See more

zabbix zabbix-community 7.1.0

1 of the 5 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

13,664
zabbixcetic3.1.31 of 5See more

zabbix cetic 3.1.3

1 of the 5 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

33,725
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

18,509
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
mautic/mautic:v4-apache94ea4acf4049
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

2,667
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
robrichards/xmlseclibs@3.1.3
3.1.5

Open the chart page →

2,811
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

9,724
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

7,779
zabbix-server-mysqlfermosit3.0.21 of 4See more

zabbix-server-mysql fermosit 3.0.2

1 of the 4 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

12,840
opencatalogiopencatalogi1.0.61 of 8See more

opencatalogi opencatalogi 1.0.6

1 of the 8 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

14,838
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

7,871
commonground-gatewaycommonground-gateway-frontend0.1.51 of 4See more

commonground-gateway commonground-gateway-frontend 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

2,825
mauticdevtron0.1.31 of 3See more

mautic devtron 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
robrichards/xmlseclibs@3.0.1
3.1.5

Open the chart page →

2,939
mauticdevtron-labs0.1.31 of 3See more

mautic devtron-labs 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
robrichards/xmlseclibs@3.0.1
3.1.5

Open the chart page →

2,939
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

20,933
bookstackgeek-cookbookVerified publisher5.2.01 of 1See more

bookstack geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

1,269
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

9,724
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
robrichards/xmlseclibs@3.0.1
3.1.5

Open the chart page →

2,939
bookstackschmitzis0.1.11 of 1See more

bookstack schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
solidnerd/bookstack:21.12762ffd5c51d3
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

2,751
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
robrichards/xmlseclibs@3.1.3
3.1.5

Open the chart page →

6,094
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2026-32313.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
robrichards/xmlseclibs@3.1.1
3.1.5

Open the chart page →

2,825

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
robrichards/xmlseclibs@3.1.1
3.1.5
5
mautic/mautic:2.13-apachea954c5868d76
robrichards/xmlseclibs@3.0.1
3.1.5
3
mautic/mautic:v4-apache94ea4acf4049
robrichards/xmlseclibs@3.1.1
3.1.5
1
snipe/snipe-it:v8.3.1141ebf2386fe
robrichards/xmlseclibs@3.1.3
3.1.5
1
snipe/snipe-it:v6.0.1455fb7636a98c
robrichards/xmlseclibs@3.1.1
3.1.5
1
solidnerd/bookstack:21.12762ffd5c51d3
robrichards/xmlseclibs@3.1.1
3.1.5
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
robrichards/xmlseclibs@3.1.1
3.1.5
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
robrichards/xmlseclibs@3.1.1
3.1.5
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
robrichards/xmlseclibs@3.1.1
3.1.5
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
robrichards/xmlseclibs@3.1.1
3.1.5
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
robrichards/xmlseclibs@3.1.1
3.1.5
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
robrichards/xmlseclibs@3.1.1
3.1.5
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
robrichards/xmlseclibs@3.1.3
3.1.5
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
robrichards/xmlseclibs@3.1.1
3.1.5
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
robrichards/xmlseclibs@3.1.1
3.1.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.