StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,611
of 17,792 indexed, latest versions
Container images
1,662
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,611 of 17,792 indexed charts deploy, on 1,662 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,143
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0313
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,611 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

9,340
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

6,336
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
expat@2.5.0-1
no fix listed

Open the chart page →

5,566
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,635
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
expat@2.4.7-1ubuntu0.3
no fix listed

Open the chart page →

14,218
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
expat@2.2.5-4.el8_5.3
0:2.5.0-2.el8_10

Open the chart page →

11,622
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

7,714
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

13,813
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10

Open the chart page →

6,017
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

2,630
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

7,936

Container images carrying it

1,662 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
expat@2.7.2-r0
2.8.1-r0
1
ghcr.io/gchq/cyberchef:11.0.045082a0ac41d
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/getsentry/snuba:26.7.210f8d164109b
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
expat@2.5.0-1
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/grycap/im:latest06a16d4f279f
expat@2.6.1-2ubuntu0.3
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
expat@2.2.9-1ubuntu0.4
no fix listed
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
expat@2.5.0-1
no fix listed
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
expat@2.6.4-r0
2.8.1-r0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
expat@2.7.3-r0
2.8.1-r0
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
expat@2.7.1-r0
2.8.1-r0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
expat@2.7.4-r0
2.8.1-r0
1
ghcr.io/home-operations/lidarr:3.1.29df1e14c8e09
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
expat@2.7.3-r0
2.8.1-r0
1
ghcr.io/hotio/qbittorrent:release-5.2.007198d49e5b4
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/huscker/townsquare-frontend:2.15.2dc6384d10cc8
expat@2.7.0-r0
2.8.1-r0
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
expat@2.4.7-1ubuntu0.6
no fix listed
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
expat@2.5.0-5.el9_6
0:2.5.0-6.el9_8.1
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
expat@2.5.0-5.el9_6
0:2.5.0-6.el9_8.1
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
expat@2.5.0-1.el9
0:2.5.0-6.el9_8.1
1
ghcr.io/itzg/minecraft-server:latest46919d151d39
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
expat@2.7.0-r0
2.8.1-r0
1
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
expat@2.2.5-3.el8
0:2.5.0-2.el8_10
1
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
expat@2.7.3-r0
2.8.1-r0
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
expat@2.6.1-2ubuntu0.1
no fix listed
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
expat@2.2.5-3ubuntu0.9
no fix listed
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
expat@2.6.1-2ubuntu0.2
no fix listed
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
expat@2.6.1-2ubuntu0.2
no fix listed
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
expat@2.2.9-1build1
no fix listed
1
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
expat@2.2.9-1ubuntu0.4
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.