StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,598
of 17,792 indexed, latest versions
Container images
1,645
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,598 of 17,792 indexed charts deploy, on 1,645 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,130
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0309
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,598 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,645 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/python:3.8-alpine3d93b1f77efc
expat@2.6.3-r0
2.8.1-r0
1
library/python:3.8d41127070014
expat@2.5.0-1+deb12u1
no fix listed
1
library/python:3.9da5aee29682d
expat@2.7.1-2
2.8.2-1~deb13u1
1
library/rabbitmq:3.12-management-alpine0b44fbcc3a4b
expat@2.6.3-r0
2.8.1-r0
1
library/rabbitmq:3.11.5-management1b0f675d2f24
expat@2.2.9-1ubuntu0.6
no fix listed
1
library/rabbitmq:3.7-managementb6dd45cc35b3
expat@2.2.5-3ubuntu0.2
no fix listed
1
library/redmine:6.1.204ac44a2595b
expat@2.7.1-2
2.8.2-1~deb13u1
1
library/sonarqube:10.7.0-community0842dcd4c8f8
expat@2.4.7-1ubuntu0.4
no fix listed
1
library/sonarqube:10.0.0-communityef9723cf4fe4
expat@2.4.7-1ubuntu0.2
no fix listed
1
library/tomcat:11.0.25-jdk17-temurin-noble9e1d2afa6898
expat@2.6.1-2ubuntu0.4
no fix listed
1
library/varnish:7.5.04d0bb287d87b
expat@2.5.0-1+deb12u1
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
expat@2.5.0-1
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
expat@2.7.1-2
2.8.2-1~deb13u1
1
library/wordpress:php8.1-apachef73396626d2f
expat@2.7.1-2
2.8.2-1~deb13u1
1
library/xwiki:lts-postgres-tomcat56490ac14a31
expat@2.6.1-2ubuntu0.4
no fix listed
1
library/znc:1.10.1c731c6a9b8b6
expat@2.7.5-r0
2.8.1-r0
1
library/zookeeper:3.8-temurin55d1e5b2e601
expat@2.4.7-1ubuntu0.2
no fix listed
1
library/zookeeper:3.9.5cab8944a33a1
expat@2.4.7-1ubuntu0.7
no fix listed
1
library/zookeeper:3.9.4dfa9ba46d14b
expat@2.4.7-1ubuntu0.7
no fix listed
1
linkstackorg/linkstack:latest1c8b05399ee4
expat@2.7.4-r0
2.8.1-r0
1
linuxserver/bookstack:26.05.202605282ebf97852661
expat@2.7.5-r0
2.8.1-r0
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
expat@2.2.5-3ubuntu0.2
no fix listed
1
linuxserver/calibre-web:0.6.24241009026e6f
expat@2.6.1-2ubuntu0.3
no fix listed
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
expat@2.2.9-1build1
no fix listed
1
linuxserver/cloud9:latest45c5fe102ff3
expat@2.2.5-3ubuntu0.7
no fix listed
1
linuxserver/code-server:4.10.1a5e43a05ae79
expat@2.4.7-1ubuntu0.2
no fix listed
1
linuxserver/codimd:latestb801bbcf6386
expat@2.2.5-3ubuntu0.2
no fix listed
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
expat@2.7.0-r0
2.8.1-r0
1
linuxserver/deluge:18.04.10ac871624394
expat@2.2.5-3ubuntu0.2
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
expat@2.2.5-3ubuntu0.2
no fix listed
1
linuxserver/foldingathome:8.5.67477f6455f47
expat@2.6.1-2ubuntu0.4
no fix listed
1
linuxserver/heimdall:2.6.371597f4461e4
expat@2.7.0-r0
2.8.1-r0
1
linuxserver/jellyfin:10.7.72427dde159a2
expat@2.2.9-1ubuntu0.4
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
expat@2.2.5-3ubuntu0.2
no fix listed
1
linuxserver/smokeping:2.8.2b7f906899cd3
expat@2.7.0-r0
2.8.1-r0
1
linuxserver/unifi-controller:8.0.240ae315a3a456
expat@2.2.9-1ubuntu0.6
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
expat@2.2.9-1ubuntu0.6
no fix listed
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
expat@2.7.4-r4
2.8.1-r0
1
livekit/ingress:v1.2.21ab01641b366
expat@2.4.7-1ubuntu0.2
no fix listed
1
localstack/localstack:3.19d278167f2b7
expat@2.5.0-1
no fix listed
1
locustio/locust:2.24.151d866285170
expat@2.5.0-1
no fix listed
1
loeken/home-assistant:2026.5.14ce6abc553b3
expat@2.7.5-r0
2.8.1-r0
1
loeken/jellyfin:10.11.87efbc24e47b0
expat@2.7.5-r0
2.8.1-r0
1
logiqai/flash:v3.10.265b996bc7bdc
expat@2.5.0-1+deb12u1
no fix listed
1
longhornio/longhorn-manager:v1.2.3dca34321452c
expat@2.2.9-1build1
no fix listed
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
expat@2.2.5-3ubuntu0.2
no fix listed
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
expat@2.5.0-1+deb12u2
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
expat@2.5.0-1+deb12u2
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
expat@2.5.0-1+deb12u2
no fix listed
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
expat@2.5.0-1+deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.