StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,611
of 17,787 indexed, latest versions
Container images
1,664
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,611 of 17,787 indexed charts deploy, on 1,664 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,144
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0314
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,611 by stars
ChartLatestAffected imagesRadar Score
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

5,472
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

6,323
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
expat@2.5.0-1
no fix listed

Open the chart page →

5,548
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,640
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
expat@2.4.7-1ubuntu0.3
no fix listed

Open the chart page →

14,172
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
expat@2.2.5-4.el8_5.3
0:2.5.0-2.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

7,685
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10

Open the chart page →

6,016
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

7,916

Container images carrying it

1,664 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
expat@2.5.0-1+deb12u2
no fix listed
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
expat@2.2.5-8.el8_6.3
0:2.5.0-2.el8_10
3
alpine/git:2.47.2062a01ad7a0e
expat@2.7.0-r0
2.8.1-r0
2
alpine/k8s:1.32.12048f8d9c8cc7
expat@2.7.4-r0
2.8.1-r0
2
amaraiheanacho/nginx-site:latest5c86fccf5daa
expat@2.7.0-r0
2.8.1-r0
2
apache/druid:37.0.00116fb802786
expat@2.5.0-1+deb12u2
no fix listed
2
apache/kafka:4.3.177e3df905404
expat@2.7.5-r0
2.8.1-r0
2
apache/nifi-registry:1.26.07cdfd8deec92
expat@2.4.7-1ubuntu0.3
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
expat@2.6.1-2ubuntu0.4
no fix listed
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
expat@2.5.0-5.el9_6
0:2.5.0-6.el9_8.1
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
expat@2.6.1-2build1
no fix listed
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
expat@2.5.0-1
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
expat@2.7.1-2
2.8.2-1~deb13u1
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
expat@2.2.5-11.el8
0:2.5.0-2.el8_10
2
confluentinc/cp-zookeeper:latest7610a50b13e7
expat@2.2.5-17.el8_10
0:2.5.0-2.el8_10
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
expat@2.2.5-11.el8
0:2.5.0-2.el8_10
2
cribl/cribl:4.19.2044f9a5fac9a
expat@2.6.1-2ubuntu0.4
no fix listed
2
excalidraw/excalidraw:latestf7ee194addd6
expat@2.7.0-r0
2.8.1-r0
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
expat@2.7.1-2
2.8.2-1~deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
expat@2.7.1-2
2.8.2-1~deb13u1
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
expat@2.2.5-3ubuntu0.2
no fix listed
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
expat@2.2.9-1build1
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
expat@2.5.0-1
no fix listed
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
expat@2.5.0-1
no fix listed
2
homebridge/homebridge:latest77c685a40911
expat@2.6.1-2ubuntu0.4
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
expat@2.2.9-1build1
no fix listed
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
expat@2.2.9-1ubuntu0.4
no fix listed
2
istio/kubectl:1.5.10dbb7726d1bf0
expat@2.2.5-3ubuntu0.2
no fix listed
2
istio/proxyv2:1.10.3a78b7a165744
expat@2.2.5-3ubuntu0.2
no fix listed
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
expat@2.5.0-1
no fix listed
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
expat@2.7.1-2
2.8.2-1~deb13u1
2
jlesage/jdownloader-2:v26.03.13d6cb102bd9b
expat@2.7.4-r0
2.8.1-r0
2
kurento/kurento-media-server:latest03c0d34d0828
expat@2.6.1-2ubuntu0.3
no fix listed
2
langgenius/dify-sandbox:0.2.009b7e8705673
expat@2.5.0-1
no fix listed
2
library/cassandra:3.11.65aa8400b4b3b
expat@2.2.5-3ubuntu0.2
no fix listed
2
library/cassandra:4.1.37cbcec0086ac
expat@2.4.7-1ubuntu0.2
no fix listed
2
library/nginx:latest6e23479198b9
expat@2.7.1-2
2.8.2-1~deb13u1
2
library/nginx:1.27.098f8ec75657d
expat@2.5.0-1
no fix listed
2
library/nginx:1.29.49dd288848f44
expat@2.7.1-2
2.8.2-1~deb13u1
2
library/phpmyadmin:5.2.16e75aa8f767c
expat@2.5.0-1+deb12u1
no fix listed
2
library/python:3.7eedf63967cdb
expat@2.5.0-1
no fix listed
2
library/rabbitmq:3.13.6-management-alpine611107e29cce
expat@2.6.2-r0
2.8.1-r0
2
library/rabbitmq:4.1.0-management935b3f84c1e4
expat@2.6.1-2ubuntu0.3
no fix listed
2
library/rabbitmq:3.12.1-managementf020c06da226
expat@2.4.7-1ubuntu0.2
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
expat@2.7.1-2
2.8.2-1~deb13u1
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.