StackRadar

CVE-2026-45071

Medium

Advisory

Published 27 May 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
61
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
2 of 2
affected packages

Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true

Carried by container images the latest versions of 61 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
symfony/dom-crawlercomposerv2.7.51, v2.8.34, v4.4.8, v4.4.45+13 more5.4.52, 6.4.4055
symfony/symfonycomposerv3.4.475.4.521
OSV records
GHSA-x6g4-fwcc-jj8w

Charts affected

61 by stars
ChartLatestAffected imagesRadar Score
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
symfony/dom-crawler@v6.4.16
6.4.40

Open the chart page →

2,811
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
symfony/dom-crawler@v5.4.40
5.4.52

Open the chart page →

12,170
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,830
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
symfony/dom-crawler@v5.4.6
5.4.52

Open the chart page →

7,303
tasmo-admincrystalnetVerified publisher3.0.111 of 1See more

tasmo-admin crystalnet 3.0.11

1 of the 1 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/tasmoadmin/tasmoadmin:v3.3.205aeefbdac2b
symfony/dom-crawler@v6.4.0
6.4.40

Open the chart page →

891
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
symfony/dom-crawler@v5.4.0
5.4.52

Open the chart page →

7,779
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
symfony/dom-crawler@v5.4.0
5.4.52

Open the chart page →

7,303
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,871
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,429
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,447
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
symfony/dom-crawler@v5.1.10
5.4.52

Open the chart page →

7,209
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,561
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
symfony/dom-crawler@v5.1.10
5.4.52

Open the chart page →

8,408
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
symfony/dom-crawler@v5.4.6
5.4.52

Open the chart page →

7,342
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
symfony/dom-crawler@v5.1.10
5.4.52

Open the chart page →

8,408
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ajanvier/polr:2.3.091ac61b88c85
symfony/dom-crawler@v2.7.51
5.4.52

Open the chart page →

5,904
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
symfony/dom-crawler@v4.4.8
5.4.52

Open the chart page →

7,572
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
symfony/dom-crawler@v5.1.11
5.4.52

Open the chart page →

12,907
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
symfony/dom-crawler@v5.1.10
5.4.52

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
symfony/dom-crawler@v5.1.8
5.4.52

Open the chart page →

8,408
mauticdevtron0.1.31 of 3See more

mautic devtron 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
symfony/dom-crawler@v2.8.34
5.4.52

Open the chart page →

2,939
mauticdevtron-labs0.1.31 of 3See more

mautic devtron-labs 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
symfony/dom-crawler@v2.8.34
5.4.52

Open the chart page →

2,939
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
symfony/dom-crawler@v5.1.10
5.4.52

Open the chart page →

8,408
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
symfony/dom-crawler@v5.4.6
5.4.52

Open the chart page →

7,255
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
symfony/dom-crawler@v5.4.6
5.4.52

Open the chart page →

7,327
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
bookstackgeek-cookbookVerified publisher5.2.01 of 1See more

bookstack geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
symfony/dom-crawler@v5.4.0
5.4.52

Open the chart page →

1,269
wallabaggeek-cookbookVerified publisher7.2.01 of 1See more

wallabag geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
wallabag/wallabag:2.4.25e4c26a7fb4a
symfony/symfony@v3.4.47
5.4.52

Open the chart page →

4,358
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
symfony/dom-crawler@v5.4.40
5.4.52

Open the chart page →

12,170
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
symfony/dom-crawler@v4.4.45
5.4.52

Open the chart page →

2,762
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
symfony/dom-crawler@v4.4.45
5.4.52

Open the chart page →

1,136
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
symfony/dom-crawler@v5.1.7
5.4.52

Open the chart page →

8,534
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,492
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,499
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
symfony/dom-crawler@v5.4.6
5.4.52

Open the chart page →

7,327
memo-componentmemo-component1.0.01 of 3See more

memo-component memo-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,527
orderregistratiecomponentorderregistratiecomponent1.0.01 of 3See more

orderregistratiecomponent orderregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,492
procestypecatalogusprocestypecatalogus1.1.01 of 4See more

procestypecatalogus procestypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,429
productenendienstencatalogusproductenendienstencatalogus1.0.01 of 3See more

productenendienstencatalogus productenendienstencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
symfony/dom-crawler@v5.1.10
5.4.52

Open the chart page →

8,725
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
symfony/dom-crawler@v5.3.4
5.4.52

Open the chart page →

7,491
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
symfony/dom-crawler@v5.3.7
5.4.52

Open the chart page →

2,972
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
symfony/dom-crawler@v2.8.34
5.4.52

Open the chart page →

2,939

Container images carrying it

56 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
symfony/dom-crawler@v5.3.0
5.4.52
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
symfony/dom-crawler@v5.3.0
5.4.52
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
symfony/dom-crawler@v5.4.6
5.4.52
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
symfony/dom-crawler@v6.4.16
6.4.40
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
symfony/dom-crawler@v5.4.0
5.4.52
1
ghcr.io/tasmoadmin/tasmoadmin:v3.3.205aeefbdac2b
symfony/dom-crawler@v6.4.0
6.4.40
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.