StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,598
of 17,790 indexed, latest versions
Container images
1,647
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,598 of 17,790 indexed charts deploy, on 1,647 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,131
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0310
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,598 by stars
ChartLatestAffected imagesRadar Score
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,716
jdownloader2jdownloader2Verified publisher1.10.01 of 1See more

jdownloader2 jdownloader2 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jlesage/jdownloader-2:v26.03.13d6cb102bd9b
expat@2.7.4-r0
2.8.1-r0

Open the chart page →

539
jellyfinjellyfinVerified publisher0.3.301 of 1See more

jellyfin jellyfin 0.3.30

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

2,571
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
expat@2.2.5-8.el8_6.3
0:2.5.0-2.el8_10

Open the chart page →

9,318
chronoreaperjfwenischVerified publisher1.1.101 of 1See more

chronoreaper jfwenisch 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,022
jenkinsjkimVerified publisher5.5.142 of 2See more

jenkins jkim 5.5.14

2 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
expat@2.5.0-1
no fix listed
kiwigrid/k8s-sidecar:1.27.6db85bd553253
expat@2.6.2-r0
2.8.1-r0

Open the chart page →

7,393
qbittorrentk8s-chartsVerified publisher3.1.01 of 2See more

qbittorrent k8s-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/hotio/qbittorrent:release-5.2.007198d49e5b4
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,271
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.321 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

1 of the 17 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

15,459
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
expat@2.4.7-1ubuntu0.2
no fix listed
kafkakraft/kafka-controller:3.7.0f261ad288fce
expat@2.4.7-1ubuntu0.2
no fix listed
kafkakraft/kafkakraft:3.7.02e4b593b878b
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

14,250
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

5,515
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,795
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
expat@2.5.0-2.el9_4
0:2.5.0-6.el9_8.1

Open the chart page →

12,063
nginx-php-fpmkokuwa0.1.41 of 2See more

nginx-php-fpm kokuwa 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
expat@2.7.1-r0
2.8.1-r0

Open the chart page →

1,840
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
expat@2.5.0-1
no fix listed
langgenius/dify-sandbox:0.2.009b7e8705673
expat@2.5.0-1
no fix listed

Open the chart page →

20,424
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

9,975
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

4,101
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

7,749
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
expat@2.2.9-1ubuntu0.2
no fix listed

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
expat@2.2.9-1build1
no fix listed

Open the chart page →

114,025
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
expat@2.7.1-r0
2.8.1-r0

Open the chart page →

5,657
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

3,551
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
expat@2.7.4-1
no fix listed

Open the chart page →

1,487
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
expat@2.7.4-1
no fix listed

Open the chart page →

2,708
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

2,113
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

4,011
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

35,058
fhir-serverlinuxforhealth0.9.11 of 2See more

fhir-server linuxforhealth 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
expat@2.2.5-16.el8_10
0:2.5.0-2.el8_10

Open the chart page →

1,052
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
expat@2.7.1-r3
2.8.1-r0

Open the chart page →

4,390
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

7,216
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,147
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

5,747
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,741
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

13,582
plane-enterprisemakeplaneOfficialVerified publisher3.7.21 of 13See more

plane-enterprise makeplane 3.7.2

1 of the 13 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/rabbitmq:3.13.6-management-alpine611107e29cce
expat@2.6.2-r0
2.8.1-r0

Open the chart page →

4,942
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

3,014
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
expat@2.7.4-1
no fix listed

Open the chart page →

6,994
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

2,764
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
expat@2.6.1-2ubuntu0.2
no fix listed

Open the chart page →

4,184
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
expat@2.2.5-4.el8
0:2.5.0-2.el8_10

Open the chart page →

6,915
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
expat@2.7.1-2
no fix listed

Open the chart page →

11,108
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

13,763
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

7,552
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

2,576
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
expat@2.7.3-r0
2.8.1-r0

Open the chart page →

37,441
dashdotoben01Verified publisher1.5.01 of 1See more

dashdot oben01 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
mauricenino/dashdot:5.9.2236997816917
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

1,237
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,051
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
expat@2.5.0-1
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
expat@2.5.0-1
no fix listed

Open the chart page →

14,862
opentelemetry-demoopentelemetry-helmVerified publisher0.41.24See more

opentelemetry-demo opentelemetry-helm 0.41.2

4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
expat@2.7.5-r0
2.8.1-r0
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
expat@2.5.0-1+deb12u2
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
expat@2.7.3-r0
2.8.1-r0
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

Container images carrying it

1,647 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ubuntu/squid:5.2-22.04_beta723891b5bc74
expat@2.4.7-1ubuntu0.6
no fix listed
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
expat@2.5.0-1+deb12u1
no fix listed
1
vabene1111/recipes:2.3.50f8d061895e9
expat@2.7.3-r0
2.8.1-r0
1
vcnngr/pnfrontend:latest4e4979ab8c41
expat@2.7.1-r0
2.8.1-r0
1
vexorian/dizquetv:1.4.37e2b99844a5c
expat@2.2.5-3ubuntu0.2
no fix listed
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
expat@2.2.5-3ubuntu0.9
no fix listed
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
expat@2.2.5-4.el8_5.3
0:2.5.0-2.el8_10
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
expat@2.2.5-11.el8
0:2.5.0-2.el8_10
1
vlebediantsev/notes-admin-front:latest007c6670ff48
expat@2.5.0-1
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
expat@2.5.0-1
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
expat@2.5.0-1
no fix listed
1
voltha/voltha-cli:1.6.0c4e41e92f046
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
voltha/voltha-envoy:1.6.059ab2a00f712
expat@2.1.0-4ubuntu1.4
no fix listed
1
voltha/voltha-netconf:1.6.037f80524c207
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
voltha/voltha-onos:5.1.8e038acb950d3
expat@2.2.5-3ubuntu0.2
no fix listed
1
voltha/voltha-tester:1.7.0655c3048a602
expat@2.1.0-7ubuntu0.16.04.4
no fix listed
1
voltha/voltha-voltha:1.6.0ff596b62de59
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
expat@2.2.9-1ubuntu0.6
no fix listed
1
wavefronthq/proxy:9.2d1064d28f6eb
expat@2.2.5-3ubuntu0.2
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
expat@2.2.9-1ubuntu0.6
no fix listed
1
wazuh/wazuh-manager:4.4.121994f40e0da
expat@2.2.9-1ubuntu0.6
no fix listed
1
weblate/weblate:2026.9.1.0990720d1737a
expat@2.7.4-1
no fix listed
1
wger/server:2.6997ead43aabd
expat@2.6.1-2ubuntu0.4
no fix listed
1
wiktorn/overpass-api:latest9bb5f4a9b54c
expat@2.5.0-1+deb12u2
no fix listed
1
wistefan/mvf:lateste0887302b2d8
expat@2.4.7-1
no fix listed
1
woojoong/wowza:latestec230db19652
expat@2.2.5-3
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
expat@2.4.7-1ubuntu0.3
no fix listed
1
xeladock/mysql_dns:latest4baf531453f1
expat@2.4.7-1
no fix listed
1
xeladock/nginx2:latestc259a67b1dff
expat@2.4.7-1
no fix listed
1
xeotek/kadeck:6.3.439a3b37a17c5
expat@2.4.7-1ubuntu0.6
no fix listed
1
xeotek/kadeck:4.2.94c6b04d9ce55
expat@2.2.9-1ubuntu0.6
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
expat@2.5.0-1
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
expat@2.5.0-1
no fix listed
1
ymuski/geo-checker:5.0.05ba7fd8c7bdc
expat@2.7.3-r0
2.8.1-r0
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
expat@2.7.3-r0
2.8.1-r0
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
expat@2.7.3-r0
2.8.1-r0
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
expat@2.7.3-r0
2.8.1-r0
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
expat@2.7.3-r0
2.8.1-r0
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
expat@2.6.1-2ubuntu0.2
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
expat@2.2.9-1build1
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
expat@2.6.1-2ubuntu0.3
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
expat@2.4.7-1
no fix listed
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
expat@2.6.1-2ubuntu0.3
no fix listed
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
expat@2.4.7-1
no fix listed
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
expat@2.7.1-r0
2.8.1-r0
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
expat@2.7.4-r0
2.8.1-r0
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
expat@2.4.7-1ubuntu0.7
no fix listed
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
expat@2.2.5-3ubuntu0.2
no fix listed
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.