CVE-2026-45186
HighAdvisory
Published 10 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 39th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,598
- of 17,792 indexed, latest versions
- Container images
- 1,645
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: expat security update
Carried by container images the latest versions of 1,598 of 17,792 indexed charts deploy, on 1,645 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| expatdeb | 2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more | 2.8.2-1~deb13u1 | 1,130 |
| expatapk | 2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more | 2.8.1-r0 | 309 |
| expatrpm | 2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more | 0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1 | 206 |
- OSV records
- ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
- Also known as
- CGA-6x8g-rx24-rm2q
Charts affected
1,598 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
1,645 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.