StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,598
of 17,790 indexed, latest versions
Container images
1,647
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,598 of 17,790 indexed charts deploy, on 1,647 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,131
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0310
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,598 by stars
ChartLatestAffected imagesRadar Score
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,716
jdownloader2jdownloader2Verified publisher1.10.01 of 1See more

jdownloader2 jdownloader2 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jlesage/jdownloader-2:v26.03.13d6cb102bd9b
expat@2.7.4-r0
2.8.1-r0

Open the chart page →

539
jellyfinjellyfinVerified publisher0.3.301 of 1See more

jellyfin jellyfin 0.3.30

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

2,571
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
expat@2.2.5-8.el8_6.3
0:2.5.0-2.el8_10

Open the chart page →

9,318
chronoreaperjfwenischVerified publisher1.1.101 of 1See more

chronoreaper jfwenisch 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,022
jenkinsjkimVerified publisher5.5.142 of 2See more

jenkins jkim 5.5.14

2 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
expat@2.5.0-1
no fix listed
kiwigrid/k8s-sidecar:1.27.6db85bd553253
expat@2.6.2-r0
2.8.1-r0

Open the chart page →

7,393
qbittorrentk8s-chartsVerified publisher3.1.01 of 2See more

qbittorrent k8s-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/hotio/qbittorrent:release-5.2.007198d49e5b4
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,271
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.321 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

1 of the 17 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

15,459
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
expat@2.4.7-1ubuntu0.2
no fix listed
kafkakraft/kafka-controller:3.7.0f261ad288fce
expat@2.4.7-1ubuntu0.2
no fix listed
kafkakraft/kafkakraft:3.7.02e4b593b878b
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

14,250
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

5,515
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,795
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
expat@2.5.0-2.el9_4
0:2.5.0-6.el9_8.1

Open the chart page →

12,063
nginx-php-fpmkokuwa0.1.41 of 2See more

nginx-php-fpm kokuwa 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
expat@2.7.1-r0
2.8.1-r0

Open the chart page →

1,840
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
expat@2.5.0-1
no fix listed
langgenius/dify-sandbox:0.2.009b7e8705673
expat@2.5.0-1
no fix listed

Open the chart page →

20,424
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

9,975
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

4,101
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

7,749
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
expat@2.2.9-1ubuntu0.2
no fix listed

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
expat@2.2.9-1build1
no fix listed

Open the chart page →

114,025
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
expat@2.7.1-r0
2.8.1-r0

Open the chart page →

5,657
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

3,551
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
expat@2.7.4-1
no fix listed

Open the chart page →

1,487
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
expat@2.7.4-1
no fix listed

Open the chart page →

2,708
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

2,113
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

4,011
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

35,058
fhir-serverlinuxforhealth0.9.11 of 2See more

fhir-server linuxforhealth 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
expat@2.2.5-16.el8_10
0:2.5.0-2.el8_10

Open the chart page →

1,052
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
expat@2.7.1-r3
2.8.1-r0

Open the chart page →

4,390
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

7,216
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,147
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

5,747
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,741
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

13,582
plane-enterprisemakeplaneOfficialVerified publisher3.7.21 of 13See more

plane-enterprise makeplane 3.7.2

1 of the 13 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/rabbitmq:3.13.6-management-alpine611107e29cce
expat@2.6.2-r0
2.8.1-r0

Open the chart page →

4,942
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

3,014
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
expat@2.7.4-1
no fix listed

Open the chart page →

6,994
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

2,764
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
expat@2.6.1-2ubuntu0.2
no fix listed

Open the chart page →

4,184
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
expat@2.2.5-4.el8
0:2.5.0-2.el8_10

Open the chart page →

6,915
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
expat@2.7.1-2
no fix listed

Open the chart page →

11,108
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

13,763
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

7,552
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

2,576
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
expat@2.7.3-r0
2.8.1-r0

Open the chart page →

37,441
dashdotoben01Verified publisher1.5.01 of 1See more

dashdot oben01 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
mauricenino/dashdot:5.9.2236997816917
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

1,237
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,051
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
expat@2.5.0-1
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
expat@2.5.0-1
no fix listed

Open the chart page →

14,862
opentelemetry-demoopentelemetry-helmVerified publisher0.41.24See more

opentelemetry-demo opentelemetry-helm 0.41.2

4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
expat@2.7.5-r0
2.8.1-r0
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
expat@2.5.0-1+deb12u2
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
expat@2.7.3-r0
2.8.1-r0
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

Container images carrying it

1,647 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
structurizr/onpremises:2025.11.094b5ffb5119c8
expat@2.6.1-2ubuntu0.3
no fix listed
1
substratusai/verba:v0.4.0-baseURL261695be635eb
expat@2.5.0-1
no fix listed
1
supabase/realtime:v2.102.3aa1c92c0cf32
expat@2.5.0-1+deb12u2
no fix listed
1
supabase/realtime:latestd3aa0c86c7b3
expat@2.7.1-2
2.8.2-1~deb13u1
1
supabase/storage-api:v1.60.4c8eb9858eafe
expat@2.7.5-r0
2.8.1-r0
1
supabase/storage-api:v1.12.0f983fb50bd95
expat@2.6.3-r0
2.8.1-r0
1
supabase/studio:20241021-9f9b08326d8070c55e9
expat@2.5.0-1+deb12u1
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
expat@2.5.0-1+deb12u2
no fix listed
1
supabase/studio:latest94a2a9d2906e
expat@2.5.0-1+deb12u3
no fix listed
1
svcosti/cidrapp:latest8428d87bc5d0
expat@2.7.0-r0
2.8.1-r0
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
expat@2.4.7-1ubuntu0.3
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
expat@2.2.9-1ubuntu0.6
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
expat@2.5.0-1
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
expat@2.2.9-1ubuntu0.6
no fix listed
1
swimmwatch/cloakbrowser-mcp:1.13.0d48c705a58c8
expat@2.5.0-1+deb12u3
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
expat@2.4.7-1ubuntu0.7
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
expat@2.5.0-1+deb12u1
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
expat@2.5.0-1+deb12u1
no fix listed
1
tchiotludo/akhq:0.28.0c2824dc2ae44
expat@2.7.4-1
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
expat@2.5.0-1
no fix listed
1
temporalio/admin-tools:1.26.237e2e33dbd7b
expat@2.6.3-r0
2.8.1-r0
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
expat@2.7.1-r0
2.8.1-r0
1
temporalio/admin-tools:1.28cfde8170c92f
expat@2.7.4-r0
2.8.1-r0
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
tenureai/tenure:v1.0.285f5b222df9a5
expat@2.7.1-2+dhi4
2.8.2-1~deb13u1
1
thecloudspark/app-vote:1.0c7da7417a86a
expat@2.6.2-r0
2.8.1-r0
1
thelande/kasa_exporter:v0.2.3a1fdb8baa152
expat@2.6.2-r0
2.8.1-r0
1
theradius/loggia:0.463ba348546ec
expat@2.5.0-1
no fix listed
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
expat@2.7.1-2
2.8.2-1~deb13u1
1
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
expat@2.7.1-2
2.8.2-1~deb13u1
1
thingsboard/tb-postgres:latest2d17e4e36edc
expat@2.5.0-1+deb12u2
no fix listed
1
thmmniii/fbs-core:v1.27.15438517d9fc2
expat@2.4.7-1
no fix listed
1
thongngo3301/stakefish:latesta341af5976e3
expat@2.5.0-1
no fix listed
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
expat@2.4.7-1ubuntu0.2
no fix listed
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
expat@2.4.7-1ubuntu0.2
no fix listed
1
timescale/timescaledb-ha:pg16d7db8f1085a3
expat@2.4.7-1ubuntu0.7
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
expat@2.4.7-1ubuntu0.5
no fix listed
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
expat@2.4.7-1
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
expat@2.7.1-2
2.8.2-1~deb13u1
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
expat@2.7.1-2
2.8.2-1~deb13u1
1
tombursch/kitchenowl-web:v0.7.8517f808eee66
expat@2.7.5-r0
2.8.1-r0
1
tomsquest/docker-radicale:3.6.1.0a594c624c5a6
expat@2.7.4-r0
2.8.1-r0
1
tpdock/freeradius:2.2.93da600c95a49
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
treskon/portrait:DEV-latest88e813f22347
expat@2.7.4-1
no fix listed
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
expat@2.5.0-1+deb12u1
no fix listed
1
trinodb/trino:45038c6f24ab1a4
expat@2.5.0-2.el9_4
0:2.5.0-6.el9_8.1
1
trinodb/trino:405ee80ab5eeab2
expat@2.4.7-1ubuntu0.2
no fix listed
1
trueosiris/vrising:latest9356f98ad561
expat@2.4.7-1ubuntu0.7
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
expat@2.4.7-1ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.