StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,598
of 17,792 indexed, latest versions
Container images
1,645
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,598 of 17,792 indexed charts deploy, on 1,645 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,130
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0309
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,598 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,645 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
lsstsqre/nublado2:2.0.1b75bf8aaafa4
expat@2.2.9-1ubuntu0.2
no fix listed
1
makersquad/harp-proxy:0.8.1a40dd258c527
expat@2.5.0-1+deb12u1
no fix listed
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
expat@2.2.9-1ubuntu0.8
no fix listed
1
maptiler/server:4.8.07e206140057b
expat@2.2.9-1ubuntu0.8
no fix listed
1
mariadb/maxscale:23.02.256c5e0908148
expat@2.2.5-11.el8
0:2.5.0-2.el8_10
1
martinhelmich/typo3:12.4c83a4f3fd7ae
expat@2.5.0-1+deb12u2
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
expat@2.5.0-1+deb12u2
no fix listed
1
mathieuruellan/piwigo:latest04572c8a1b04
expat@2.6.4-r0
2.8.1-r0
1
mauricenino/dashdot:5.9.2236997816917
expat@2.7.0-r0
2.8.1-r0
1
mautic/mautic:7-apacheeb8cc73d97e1
expat@2.5.0-1+deb12u2
no fix listed
1
mavrick1/kubestellar-b:latest45ca0429a1d4
expat@2.7.0-r0
2.8.1-r0
1
mavrick1/kubestellar-f:latest56bd8eaa53a4
expat@2.7.0-r0
2.8.1-r0
1
mbround18/valheim:3.1.070bd4da591cd
expat@2.4.7-1ubuntu0.5
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
expat@2.6.1-2ubuntu0.4
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
expat@2.2.9-1ubuntu0.4
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
expat@2.4.7-1ubuntu0.2
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
expat@2.5.0-1+deb12u1
no fix listed
1
metabase/metabase:v0.53.4.17807bc5cad17
expat@2.6.4-r0
2.8.1-r0
1
middlewareeng/middleware:0.3.1747d880812f1
expat@2.5.0-1+deb12u1
no fix listed
1
mindsdb/mindsdb:latest163011c09299
expat@2.7.1-2
2.8.2-1~deb13u1
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10
1
minio/operator:v4.1.02adc5be088f5
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
expat@2.5.0-1+deb12u1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
expat@2.4.7-1ubuntu0.4
no fix listed
1
moby/buildkit:v0.31.0a095b3d11ce1
expat@2.7.5-r0
2.8.1-r0
1
mockserver/mockserver:mockserver-8.0.0b8426e0b3c80
expat@2.5.0-1+deb12u2
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
expat@2.5.0-1+deb12u2
no fix listed
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
expat@2.6.2-r0
2.8.1-r0
1
moreillon/api-proxy:latestd7d4a5463525
expat@2.5.0-1+deb12u1
no fix listed
1
moreillon/camera-viewer:lateste418cc694bd5
expat@2.5.0-1+deb12u1
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
expat@2.5.0-1+deb12u1
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
expat@2.5.0-1+deb12u2
no fix listed
1
moreillon/group-manager-front:latest5f0a38498271
expat@2.7.1-2
2.8.2-1~deb13u1
1
moreillon/user-manager-front:v5.1.06597e6b98d21
expat@2.5.0-1
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
expat@2.5.0-1
no fix listed
1
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
expat@2.7.3-r0
2.8.1-r0
1
mshanley80/httpbin2022:latest5b189a70c0fb
expat@2.2.9-1ubuntu0.6
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
expat@2.5.0-1
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
mvance/unbound:1.20.04bf67b567f39
expat@2.5.0-1
no fix listed
1
mvance/unbound:1.22.076906da36d18
expat@2.5.0-1+deb12u1
no fix listed
1
n8nio/n8n:2.25.7761374d4eb84
expat@2.7.5-r0
2.8.1-r0
1
n8nio/n8n:1.115.1ed16e560c40e
expat@2.7.2-r0
2.8.1-r0
1
netboxcommunity/netbox:v3.2.83d652dca5351
expat@2.4.7-1
no fix listed
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
expat@2.7.4-1
no fix listed
1
nethermind/nethermind:1.14.615517708c3b6
expat@2.4.7-1ubuntu0.1
no fix listed
1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
expat@2.7.3-r0
2.8.1-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.