StackRadar

CVE-2026-45071

Medium

Advisory

Published 27 May 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
61
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
2 of 2
affected packages

Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true

Carried by container images the latest versions of 61 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
symfony/dom-crawlercomposerv2.7.51, v2.8.34, v4.4.8, v4.4.45+13 more5.4.52, 6.4.4055
symfony/symfonycomposerv3.4.475.4.521
OSV records
GHSA-x6g4-fwcc-jj8w

Charts affected

61 by stars
ChartLatestAffected imagesRadar Score
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
symfony/dom-crawler@v6.4.4
6.4.40

Open the chart page →

9,755
bookstackschmitzis0.1.11 of 1See more

bookstack schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
solidnerd/bookstack:21.12762ffd5c51d3
symfony/dom-crawler@v5.4.0
5.4.52

Open the chart page →

2,751
wallabagsebtiz13-chartsVerified publisher0.6.01 of 1See more

wallabag sebtiz13-charts 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
symfony/dom-crawler@v4.4.45
5.4.52

Open the chart page →

1,136
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
symfony/dom-crawler@v5.3.4
5.4.52

Open the chart page →

7,480
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
symfony/dom-crawler@v6.4.4
6.4.40

Open the chart page →

10,086
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
symfony/dom-crawler@v5.3.0
5.4.52

Open the chart page →

7,429
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-45071.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
symfony/dom-crawler@v5.4.6
5.4.52

Open the chart page →

7,552

Container images carrying it

56 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
symfony/dom-crawler@v5.3.0
5.4.52
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
symfony/dom-crawler@v5.3.0
5.4.52
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
symfony/dom-crawler@v5.4.6
5.4.52
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
symfony/dom-crawler@v6.4.16
6.4.40
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
symfony/dom-crawler@v5.4.0
5.4.52
1
ghcr.io/tasmoadmin/tasmoadmin:v3.3.205aeefbdac2b
symfony/dom-crawler@v6.4.0
6.4.40
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.