StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,598
of 17,792 indexed, latest versions
Container images
1,645
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,598 of 17,792 indexed charts deploy, on 1,645 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,130
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0309
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,598 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,645 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
jeboehm/mailserver-filter:5.0.92e756949e537d
expat@2.7.0-r0
2.8.1-r0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
expat@2.7.1-r0
2.8.1-r0
1
jedi132000/nextapp:latestdc2a81e92f23
expat@2.2.9-1ubuntu0.4
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
expat@2.7.1-2
2.8.2-1~deb13u1
1
jellyfin/jellyfin:10.11.717285f9cce63
expat@2.7.1-2
2.8.2-1~deb13u1
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
expat@2.5.0-1+deb12u1
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
expat@2.7.1-2
2.8.2-1~deb13u1
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
expat@2.5.0-1
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
expat@2.5.0-1+deb12u1
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
expat@2.5.0-1+deb12u1
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
expat@2.5.0-1
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
expat@2.5.0-1
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
expat@2.2.9-1ubuntu0.8
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
expat@2.5.0-1
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
expat@2.2.9-1ubuntu0.6
no fix listed
1
jlesage/firefox:v25.03.1055c28defe31
expat@2.7.0-r0
2.8.1-r0
1
jmferrer/azure-devops-agent:latest030f68ec6998
expat@2.1.0-7ubuntu0.16.04.5
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
expat@2.5.0-1+deb12u2
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
expat@2.4.7-1ubuntu0.2
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
expat@2.6.1-2ubuntu0.4
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
expat@2.2.9-1build1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
expat@2.2.9-1build1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
expat@2.2.9-1build1
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
expat@2.6.1-2ubuntu0.1
no fix listed
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
expat@2.4.7-1ubuntu0.2
no fix listed
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
expat@2.4.7-1ubuntu0.2
no fix listed
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
expat@2.4.7-1ubuntu0.2
no fix listed
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
expat@2.7.5-r0
2.8.1-r0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
expat@2.7.5-r0
2.8.1-r0
1
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
expat@2.7.4-r0
2.8.1-r0
1
kennethreitz/httpbin:latest599fe5e50731
expat@2.2.5-3
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
expat@2.2.9-1ubuntu0.6
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
expat@2.5.0-1+deb12u2
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
expat@2.5.0-1+deb12u2
no fix listed
1
kiwigrid/k8s-sidecar:1.27.6db85bd553253
expat@2.6.2-r0
2.8.1-r0
1
knspar/phronetis:0.1.4609499d2dc91a
expat@2.6.1-2ubuntu0.3
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
expat@2.5.0-1
no fix listed
1
kong/httpbin:latesta6ac46531193
expat@2.4.7-1ubuntu0.5
no fix listed
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
expat@2.4.7-1ubuntu0.7
no fix listed
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
expat@2.2.9-1ubuntu0.6
no fix listed
1
krontechnology/aapm-service:1.1.39dd602db8baa
expat@2.4.7-1ubuntu0.7
no fix listed
1
kserve/models-web-app:v0.13.073486345a602
expat@2.5.0-1
no fix listed
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
expat@2.2.5-3ubuntu0.2
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
expat@2.6.1-2ubuntu0.3
no fix listed
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
expat@2.6.1-2ubuntu0.4
no fix listed
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
expat@2.7.0-r0
2.8.1-r0
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
expat@2.7.4-r0
2.8.1-r0
1
kusionstack/kusion:v0.14.0126c8f0b0976
expat@2.4.7-1ubuntu0.5
no fix listed
1
kuzwolka/aws9:main1ad759b961b1
expat@2.5.0-1+deb12u1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
expat@2.5.0-1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.