StackRadar

CVE-2026-41080

Low

Advisory

Published 16 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.9
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,454
of 17,792 indexed, latest versions
Container images
1,456
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,454 of 17,792 indexed charts deploy, on 1,456 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.1.0-7ubuntu0.16.04.5+esm12, 2.8.2-1~deb13u11,143
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.0-r0, 2.8.1-r0313
OSV records
ALPINE-CVE-2026-41080CGA-f542-4m97-5v2vDEBIAN-CVE-2026-41080UBUNTU-CVE-2026-41080
Also known as
CGA-h7ph-x4mx-672f, USN-8520-1

Charts affected

1,454 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-41080.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

7,714
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-41080.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

13,813
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2026-41080.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

2,630
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-41080.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

7,936

Container images carrying it

1,456 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
expat@2.5.0-1
no fix listed
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
expat@2.7.3-r0
2.8.1-r0
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
expat@2.5.0-1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
expat@2.7.3-r0
2.8.1-r0
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
expat@2.6.1-2ubuntu0.1
no fix listed
1
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
expat@2.6.1-2ubuntu0.3
no fix listed
1
ghcr.io/openunison/openunison-k8s:1.0.51128081dae281
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
expat@2.4.7-1ubuntu0.6
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
expat@2.2.9-1ubuntu0.4
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
expat@2.5.0-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
expat@2.2.5-3ubuntu0.7
no fix listed
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
expat@2.7.4-r0
2.8.1-r0
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
expat@2.5.0-1+deb12u3
no fix listed
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
expat@2.7.0-r0
2.8.1-r0
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
expat@2.6.4-r0
2.8.1-r0
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
expat@2.6.3-r0
2.8.1-r0
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
expat@2.4.7-1ubuntu0.2
no fix listed
1
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
expat@2.6.4-r0
2.8.1-r0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
expat@2.7.4-1
no fix listed
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
expat@2.6.4-r0
2.8.1-r0
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
expat@2.6.4-r0
2.8.1-r0
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
expat@2.6.4-r0
2.8.1-r0
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
expat@2.6.1-2ubuntu0.3
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.