StackRadar

CVE-2026-41080

Low

Advisory

Published 16 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.9
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,454
of 17,790 indexed, latest versions
Container images
1,457
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,454 of 17,790 indexed charts deploy, on 1,457 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.1.0-7ubuntu0.16.04.5+esm12, 2.8.2-1~deb13u11,144
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.0-r0, 2.8.1-r0313
OSV records
ALPINE-CVE-2026-41080CGA-f542-4m97-5v2vDEBIAN-CVE-2026-41080UBUNTU-CVE-2026-41080
Also known as
CGA-h7ph-x4mx-672f, USN-8520-1

Charts affected

1,454 by stars
ChartLatestAffected imagesRadar Score
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-41080.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
expat@2.4.7-1ubuntu0.3
no fix listed

Open the chart page →

14,173
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-41080.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

7,697
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-41080.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

13,783
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-41080.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

7,929

Container images carrying it

1,457 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jupyterhub/jupyterhub:5.4.63974ba945e65
expat@2.6.1-2ubuntu0.4
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
expat@2.2.9-1build1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
expat@2.2.9-1build1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
expat@2.2.9-1build1
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
expat@2.6.1-2ubuntu0.1
no fix listed
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
expat@2.4.7-1ubuntu0.2
no fix listed
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
expat@2.4.7-1ubuntu0.2
no fix listed
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
expat@2.4.7-1ubuntu0.2
no fix listed
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
expat@2.7.5-r0
2.8.1-r0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
expat@2.7.5-r0
2.8.1-r0
1
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
expat@2.7.4-r0
2.8.1-r0
1
kennethreitz/httpbin:latest599fe5e50731
expat@2.2.5-3
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
expat@2.2.9-1ubuntu0.6
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
expat@2.5.0-1+deb12u2
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
expat@2.5.0-1+deb12u2
no fix listed
1
kiwigrid/k8s-sidecar:1.27.6db85bd553253
expat@2.6.2-r0
2.8.1-r0
1
knspar/phronetis:0.1.4609499d2dc91a
expat@2.6.1-2ubuntu0.3
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
expat@2.5.0-1
no fix listed
1
kong/httpbin:latesta6ac46531193
expat@2.4.7-1ubuntu0.5
no fix listed
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
expat@2.4.7-1ubuntu0.7
no fix listed
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
expat@2.2.9-1ubuntu0.6
no fix listed
1
krontechnology/aapm-service:1.1.39dd602db8baa
expat@2.4.7-1ubuntu0.7
no fix listed
1
kserve/models-web-app:v0.13.073486345a602
expat@2.5.0-1
no fix listed
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
expat@2.2.5-3ubuntu0.2
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
expat@2.6.1-2ubuntu0.3
no fix listed
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
expat@2.6.1-2ubuntu0.4
no fix listed
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
expat@2.7.0-r0
2.8.1-r0
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
expat@2.7.4-r0
2.8.1-r0
1
kusionstack/kusion:v0.14.0126c8f0b0976
expat@2.4.7-1ubuntu0.5
no fix listed
1
kuzwolka/aws9:main1ad759b961b1
expat@2.5.0-1+deb12u1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
expat@2.5.0-1+deb12u1
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
expat@2.5.0-1+deb12u1
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
expat@2.5.0-1+deb12u1
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
expat@2.4.7-1ubuntu0.3
no fix listed
1
labs64/auditflowc7b26d3ca11c
expat@2.7.4-1
no fix listed
1
labs64/payment-gateway:0.0.10c66feefca17
expat@2.7.4-1
no fix listed
1
laly9999/node-app:1dd0e503913e1
expat@2.5.0-1+deb12u1
no fix listed
1
lancachenet/monolithic:latest37f28b362c93
expat@2.6.1-2ubuntu0.4
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
expat@2.5.0-1+deb12u2
no fix listed
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
expat@2.5.0-1+deb12u2
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
expat@2.5.0-1+deb12u1
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
expat@2.5.0-1+deb12u2
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
expat@2.5.0-1
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
expat@2.6.1-2ubuntu0.4
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
expat@2.6.1-2ubuntu0.3
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
expat@2.6.1-2ubuntu0.4
no fix listed
1
langgenius/dify-sandbox:0.2.15750e1111426e
expat@2.7.5-1
2.8.2-1~deb13u1
1
lbenicio/stremio-web:latest732f9003de33
expat@2.7.5-r0
2.8.1-r0
1
leantime/leantime:3.3.3ad4bfb0699d3
expat@2.6.4-r0
2.8.1-r0
1
lib42/jackett:latesta55596cda383
expat@2.5.0-1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.