StackRadar

CVE-2026-41650

Medium

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
118
deployed by those charts
Fix available
1 of 1
affected package

fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 118 images.

Affected packageAffected versionsFixed inImages
fast-xml-parsernpm3.19.0, 3.21.1, 4.0.11, 4.1.2+20 more5.7.0118
OSV records
GHSA-gh4j-gqv2-49f6

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
fast-xml-parser@3.21.1
5.7.0

Open the chart page →

3,118
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
fast-xml-parser@4.2.5
5.7.0

Open the chart page →

4,285
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
fast-xml-parser@4.0.11
5.7.0

Open the chart page →

2,267
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
fast-xml-parser@4.4.0
5.7.0

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
fast-xml-parser@4.4.0
5.7.0

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
fast-xml-parser@4.2.6
5.7.0

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
fast-xml-parser@4.4.0
5.7.0

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
fast-xml-parser@4.2.6
5.7.0

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
fast-xml-parser@4.2.6
5.7.0

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
fast-xml-parser@4.4.0
5.7.0

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
fast-xml-parser@4.4.0
5.7.0

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
fast-xml-parser@4.4.0
5.7.0

Open the chart page →

11,100
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
thingsboard/tb-js-executor:3.4.113e1eadf8ace
fast-xml-parser@3.19.0
5.7.0

Open the chart page →

25,394
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
fast-xml-parser@3.21.1
5.7.0

Open the chart page →

5,535
saleor-appstrieb-work0.6.01 of 5See more

saleor-apps trieb-work 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
fast-xml-parser@4.1.2
5.7.0

Open the chart page →

6,994
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
fast-xml-parser@5.2.1
5.7.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
fast-xml-parser@4.5.3
5.7.0

Open the chart page →

3,746
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
fast-xml-parser@5.5.8
5.7.0

Open the chart page →

2,076
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
fast-xml-parser@3.21.1
5.7.0

Open the chart page →

3,118
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
fast-xml-parser@4.4.1
5.7.0

Open the chart page →

6,285
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2026-41650.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
fast-xml-parser@3.21.1
5.7.0
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
fast-xml-parser@4.2.5
5.7.0

Open the chart page →

16,083

Container images carrying it

118 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
fast-xml-parser@5.5.9
5.7.0
3
agoldis/sorry-cypress-director:2.5.1110228ecd353b
fast-xml-parser@4.2.5
5.7.0
2
library/mongo-express:1.0.2:latest1b23d7976f02
fast-xml-parser@4.0.11
5.7.0
2
louislam/uptime-kuma:2.3.29aeb4e51d038
fast-xml-parser@5.2.5
5.7.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-xml-parser@4.5.3
5.7.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-xml-parser@4.5.3
5.7.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-xml-parser@4.5.3
5.7.0
2
rajnandan1/kener:3.2.1930407afca731
fast-xml-parser@5.2.1
5.7.0
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
fast-xml-parser@3.21.1
5.7.0
2
activepieces/activepieces:0.90.430c10a04fe3d
fast-xml-parser@5.2.5
5.7.0
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
fast-xml-parser@5.5.8
5.7.0
1
automatischio/automatisch:0.15.03bace7a12d5f
fast-xml-parser@4.5.0
5.7.0
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
fast-xml-parser@4.0.11
5.7.0
1
budibase/apps:3.41.344fe6feab985
fast-xml-parser@5.5.8
5.7.0
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
fast-xml-parser@4.2.5
5.7.0
1
chocobozzz/peertube:v8.1.5052712130691
fast-xml-parser@5.3.6
5.7.0
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
fast-xml-parser@4.5.7
5.7.0
1
countly/api:25.05.4f4cc7447c4f5
fast-xml-parser@4.3.6
5.7.0
1
countly/countly-server:25.05.4e3c238248f99
fast-xml-parser@4.3.6
5.7.0
1
countly/frontend:25.05.42acbc11499b6
fast-xml-parser@4.3.6
5.7.0
1
cryptexlabs/authf:0.12.11189c07411d7c
fast-xml-parser@4.4.1
5.7.0
1
directus/directus:11.1.0e3c8bb975350
fast-xml-parser@4.2.5
5.7.0
1
documenso/documenso:v1.8.17f16a9449f18
fast-xml-parser@4.2.5
5.7.0
1
drumsergio/genieacs:1.2.16.028244054e1bf
fast-xml-parser@5.5.8
5.7.0
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
fast-xml-parser@3.21.1
5.7.0
1
ethpandaops/blobscan:latest7a9ab6370657
fast-xml-parser@4.0.11
5.7.0
1
ethpandaops/blobscan-indexer:latestc58eb9ffe446
fast-xml-parser@4.0.11
5.7.0
1
evoapicloud/evolution-api:latest966625532d90
fast-xml-parser@4.5.3
5.7.0
1
fallenbagel/jellyseerr:latest4538137bc5af
fast-xml-parser@4.5.3
5.7.0
1
fosrl/pangolin:1.13.0c32ad797ab96
fast-xml-parser@5.2.5
5.7.0
1
ianw/quickchart:v1.7.1dc49dd460c37
fast-xml-parser@3.21.1
5.7.0
1
joplin/server:latest3f7b852959aa
fast-xml-parser@3.21.1
5.7.0
1
joplin/server:3.0-beta52af57880c0e
fast-xml-parser@4.1.2
5.7.0
1
joplin/server:2.14.2-betab87564ef34e9
fast-xml-parser@4.1.2
5.7.0
1
library/ghost:6.25.12654b1e90413
fast-xml-parser@5.2.5
5.7.0
1
library/ghost:4.37.0767230c0f263
fast-xml-parser@3.19.0
5.7.0
1
library/ghost:5.79.083f7bf209844
fast-xml-parser@4.0.11
5.7.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
fast-xml-parser@5.2.5
5.7.0
1
library/kibana:8.18.004c0fc150f3a
fast-xml-parser@4.4.1
5.7.0
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
fast-xml-parser@4.0.11
5.7.0
1
lobehub/lobe-chat:1.96.9da0c21fefcd3
fast-xml-parser@4.4.1
5.7.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
fast-xml-parser@5.2.5
5.7.0
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
fast-xml-parser@4.2.5
5.7.0
1
louislam/uptime-kuma:13d632903e6af
fast-xml-parser@5.2.5
5.7.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
fast-xml-parser@5.2.5
5.7.0
1
louislam/uptime-kuma:1.23.1396510915e6be
fast-xml-parser@4.2.5
5.7.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
fast-xml-parser@5.2.5
5.7.0
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
fast-xml-parser@4.2.5
5.7.0
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
fast-xml-parser@4.0.11
5.7.0
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
fast-xml-parser@4.4.1
5.7.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.