StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,598
of 17,792 indexed, latest versions
Container images
1,645
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,598 of 17,792 indexed charts deploy, on 1,645 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,130
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0309
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,598 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,645 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
expat@2.4.7-1ubuntu0.7
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
expat@2.7.1-2
2.8.2-1~deb13u1
1
nginxdemos/hello:plain-text751bf8933179
expat@2.7.1-r0
2.8.1-r0
1
nginxdemos/hello:0.4b28d1e16c676
expat@2.7.1-r0
2.8.1-r0
1
nginxinc/nginx-unprivileged:1.27.4-alpine62a904036bfc
expat@2.7.0-r0
2.8.1-r0
1
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
expat@2.7.1-r0
2.8.1-r0
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
expat@2.7.1-2
2.8.2-1~deb13u1
1
nginxinc/nginx-unprivileged:mainline-alpinee93571f3d083
expat@2.7.4-r0
2.8.1-r0
1
nirmalnaveen/supermario:latest8541a39162f3
expat@2.5.0-1
no fix listed
1
nodered/node-red:4.1.2216e7403aab9
expat@2.7.3-r0
2.8.1-r0
1
nodered/node-red:4.1.10-minimald73ae167cb9b
expat@2.7.5-r0
2.8.1-r0
1
novosga/novosga:latest34b9acbe6e51
expat@2.7.5-r0
2.8.1-r0
1
octoboxio/octobox:latestd909041c46eb
expat@2.7.3-r0
2.8.1-r0
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
expat@2.6.3-r0
2.8.1-r0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
expat@2.5.0-1+deb12u2
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
expat@2.5.0-1
no fix listed
1
oled01/automx2:2025.1.105d3e398e675
expat@2.5.0-1+deb12u1
no fix listed
1
olvid/bot-daemon:2.0.1e0e6b165d879
expat@2.6.1-2ubuntu0.4
no fix listed
1
omecproject/c3po-hssdb:master-latest28a90cc26716
expat@2.2.9-1build1
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
expat@2.2.5-3
no fix listed
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
expat@2.2.5-3ubuntu0.2
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
onosproject/onos:2.2.144914a8d4b3f
expat@2.2.5-3ubuntu0.2
no fix listed
1
opea/asr:1.025dd26d9cd09
expat@2.5.0-1
no fix listed
1
opea/chatqna:1.038c51b791efa
expat@2.5.0-1
no fix listed
1
opea/chatqna-conversation-ui:v0.9bdb9ec215872
expat@2.6.2-r0
2.8.1-r0
1
opea/codegen:1.058f91683892d
expat@2.5.0-1
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
expat@2.5.0-1
no fix listed
1
opea/codetrans:1.0e2436483b73d
expat@2.5.0-1
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
expat@2.5.0-1
no fix listed
1
opea/docsum:1.03eaa91849512
expat@2.5.0-1
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
expat@2.5.0-1
no fix listed
1
opea/guardrails-tgi:1.0262c6048aab8
expat@2.5.0-1
no fix listed
1
opea/guardrails-tgi:latestf68bec6a1271
expat@2.5.0-1+deb12u1
no fix listed
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
expat@2.5.0-1
no fix listed
1
opea/speecht5:1.0249afad3d268
expat@2.5.0-1
no fix listed
1
opea/tts:1.0257ae94709e9
expat@2.5.0-1
no fix listed
1
opea/web-retriever-chroma:1.0fe08165d7770
expat@2.5.0-1
no fix listed
1
openaev/platform:3.260904.00a12ce8b3db9
expat@2.6.1-2ubuntu0.4
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
expat@2.5.0-1+deb12u1
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
expat@2.6.1-2ubuntu0.3
no fix listed
1
opencsghq/csgship-portal:v1.2.1865814dc87a1
expat@2.7.0-r0
2.8.1-r0
1
opendatacube/explorer:latest120457ffcd69
expat@2.6.1-2ubuntu0.3
no fix listed
1
opendatacube/pipelines:wofs-1.225d810e8504b8
expat@2.2.5-3
no fix listed
1
opendatacube/restcube:latest91870111837c
expat@2.2.5-3
no fix listed
1
opendatacube/wms:latest1b90cdf68831
expat@2.2.5-3
no fix listed
1
opendatacube/wps:latest80df355a660b
expat@2.4.7-1ubuntu0.6
no fix listed
1
openelevation/open-elevation:latest82fb21612e86
expat@2.2.9-1build1
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
expat@2.2.9-1ubuntu0.4
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.