StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,611
of 17,790 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,611 of 17,790 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,144
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0313
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,611 by stars
ChartLatestAffected imagesRadar Score
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

5,483
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

9,320
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

6,326
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
expat@2.5.0-1
no fix listed

Open the chart page →

5,559
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,640
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
expat@2.4.7-1ubuntu0.3
no fix listed

Open the chart page →

14,173
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
expat@2.2.5-4.el8_5.3
0:2.5.0-2.el8_10

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

7,697
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

13,783
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10

Open the chart page →

6,016
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

7,929

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
folioci/mod-permissions:latest5363e98c6299
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-pubsub:latest0a4fa4ad5d72
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-search:latest44d7ee9acdf6
expat@2.7.1-r0
2.8.1-r0
1
folioci/mod-serials-management:latest571fa1ffe8c9
expat@2.6.2-r0
2.8.1-r0
1
folioci/mod-service-interaction:latestf53c327a48e8
expat@2.6.2-r0
2.8.1-r0
1
folioci/mod-user-import:latest1807734472bd
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-users-bl:latest4e2d96c9340d
expat@2.7.5-r0
2.8.1-r0
1
folioci/mod-z3950:latest2493041ce880
expat@2.7.1-2
2.8.2-1~deb13u1
1
fosrl/pangolin:1.13.0c32ad797ab96
expat@2.7.3-r0
2.8.1-r0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
expat@2.2.5-3ubuntu0.9
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
expat@2.2.5-3ubuntu0.7
no fix listed
1
frankescobar/allure-docker-service:latestdc171ec796d5
expat@2.6.1-2ubuntu0.4
no fix listed
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
expat@2.4.7-1ubuntu0.6
no fix listed
1
galaxy/cloudman-server:lateste5c265fe9fcd
expat@2.2.9-1ubuntu0.4
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
expat@2.1.0-4ubuntu1.4
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
expat@2.1.0-4ubuntu1.4
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
expat@2.5.0-1+deb12u1
no fix listed
1
gchq/accumulo:2.0.1c460bb587d6d
expat@2.6.1-2ubuntu0.2
no fix listed
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
expat@2.7.3-r0
2.8.1-r0
1
gdrocha/togglr-frontend:1.0.0ffbc1571c234
expat@2.7.3-r0
2.8.1-r0
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
expat@2.2.5-3ubuntu0.9
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
expat@2.4.7-1ubuntu0.7
no fix listed
1
geopython/pycsw:3.0.0-beta284662ea6b78b
expat@2.5.0-1+deb12u2
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
expat@2.2.5-3ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
expat@2.2.9-1build1
no fix listed
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
expat@2.7.4-1
no fix listed
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
expat@2.7.4-1
no fix listed
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
expat@2.7.4-1
no fix listed
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
expat@2.2.9-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
expat@2.2.9-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
expat@2.7.4-1
no fix listed
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
expat@2.2.9-1build1
no fix listed
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
expat@2.7.4-1
no fix listed
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
expat@2.7.4-1
no fix listed
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
expat@2.2.9-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
expat@2.2.9-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
expat@2.7.4-1
no fix listed
1
gethue/hue:4.11.011b649636e68
expat@2.2.9-1ubuntu0.6
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
expat@2.2.5-3ubuntu0.2
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
expat@2.4.7-1ubuntu0.6
no fix listed
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
expat@2.6.3-r0
2.8.1-r0
1
gitea/act_runner:nightly7940221bcfc9
expat@2.7.5-r0
2.8.1-r0
1
gitea/act_runner:latestb5c35d6bdbb9
expat@2.7.5-r0
2.8.1-r0
1
gitea/act_runner:0.3.1c2a169c5e998
expat@2.7.5-r0
2.8.1-r0
1
gitea/act_runner:0.2.11c57233403eff
expat@2.6.3-r0
2.8.1-r0
1
gitea/gitea:1.22.376f516a1a8c2
expat@2.6.3-r0
2.8.1-r0
1
gitea/gitea:1.26.27d13848af126
expat@2.7.5-r0
2.8.1-r0
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
expat@2.2.9-1ubuntu0.4
no fix listed
1
glasskube/operator:0.12.2be5133100d63
expat@2.4.7-1ubuntu0.2
no fix listed
1
goccx/go-file-server-ui:latest784b35910d52
expat@2.6.3-r0
2.8.1-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.