StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,598
of 17,790 indexed, latest versions
Container images
1,647
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,598 of 17,790 indexed charts deploy, on 1,647 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,131
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0310
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,598 by stars
ChartLatestAffected imagesRadar Score
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

17,475
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

27,984
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

9,348
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
expat@2.6.1-2ubuntu0.1
no fix listed

Open the chart page →

4,194
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
expat@2.2.5-8.el8_6.3
0:2.5.0-2.el8_10

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
expat@2.2.5-8.el8_6.3
0:2.5.0-2.el8_10

Open the chart page →

14,545
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
expat@2.2.5-8.el8_6.3
0:2.5.0-2.el8_10

Open the chart page →

13,874
flowableflowable-oss7.1.01 of 2See more

flowable flowable-oss 7.1.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
flowable/flowable-rest:7.1.0b7ae287502cd
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

2,784
healthchecksgabe565Verified publisher0.17.01 of 1See more

healthchecks gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

2,285
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

22,812
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
expat@2.2.9-1build1
no fix listed

Open the chart page →

10,652
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
expat@2.2.9-1ubuntu0.2
no fix listed

Open the chart page →

10,202
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
expat@2.2.9-1build1
no fix listed

Open the chart page →

10,676
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
expat@2.2.5-3ubuntu0.9
no fix listed

Open the chart page →

11,873
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
expat@2.7.4-1
no fix listed

Open the chart page →

1,820
terrariahalkeye0.4.21 of 2See more

terraria halkeye 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ryshe/terraria:latestb1c89f7f359a
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

4,154
coreinstill-aiOfficialVerified publisher0.1.754 of 15See more

core instill-ai 0.1.75

4 of the 15 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
expat@2.7.1-2
2.8.2-1~deb13u1
instill/mgmt-backend:d0933d4ebe12f77a3f9
expat@2.7.1-2
2.8.2-1~deb13u1
instill/model-backend:611f0f2e980125e5ba5
expat@2.7.1-2
2.8.2-1~deb13u1
temporalio/admin-tools:1.28cfde8170c92f
expat@2.7.4-r0
2.8.1-r0

Open the chart page →

30,920
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
expat@2.6.1-2ubuntu0.1
no fix listed

Open the chart page →

4,357
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

4,546
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
expat@2.7.4-r0
2.8.1-r0

Open the chart page →

4,634
mysqldumpkokuwa7.0.31 of 1See more

mysqldump kokuwa 7.0.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

847
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

11,630
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

2,004
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
expat@2.1.0-7ubuntu0.16.04.3
no fix listed

Open the chart page →

15,345
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

7,940
memgraph-high-availabilitymemgraphVerified publisher1.4.11 of 2See more

memgraph-high-availability memgraph 1.4.1

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.1bd3fe13228f4
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,208
kubecostmesosphere-stable0.37.52 of 9See more

kubecost mesosphere-stable 0.37.5

2 of the 9 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
expat@2.5.0-1+deb12u1
no fix listed
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

17,755
helm-ai-kernelmindburn-labsOfficialVerified publisher0.8.51 of 2See more

helm-ai-kernel mindburn-labs 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
expat@2.6.2-r0
2.8.1-r0

Open the chart page →

2,160
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.672 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

2 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
alpine/git:2.47.2062a01ad7a0e
expat@2.7.0-r0
2.8.1-r0
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

5,224
oesopsmxVerified publisher4.0.328 of 25See more

oes opsmx 4.0.32

8 of the 25 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
expat@2.6.1-2ubuntu0.3
no fix listed
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
no fix listed
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10

Open the chart page →

107,899
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

3,334
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
expat@2.7.1-r0
2.8.1-r0

Open the chart page →

2,867
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
expat@2.2.5-11.el8
0:2.5.0-2.el8_10

Open the chart page →

2,994
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,079
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
expat@2.4.7-1ubuntu0.6
no fix listed

Open the chart page →

13,615
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

8,760
rocketmq-clusterrocketmq12.6.02 of 2See more

rocketmq-cluster rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
expat@2.6.1-2ubuntu0.4
no fix listed
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
expat@2.5.0-5.el9_6
0:2.5.0-6.el9_8.1

Open the chart page →

6,385
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
expat@2.2.9-1build1
no fix listed

Open the chart page →

24,549
plausiblesinextraVerified publisher1.1.21 of 1See more

plausible sinextra 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v3.2.133e60bfb40f2
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

859
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

5,889
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
expat@2.4.7-1ubuntu0.6
no fix listed

Open the chart page →

5,814
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

15,525
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

7,064
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

9,825
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
expat@2.4.7-1
no fix listed

Open the chart page →

28,579
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

10,355
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

18,149
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

4,428
argo-cdwenerme10.9.11 of 3See more

argo-cd wenerme 10.9.1

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
expat@2.7.4-1
no fix listed

Open the chart page →

2,989
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
expat@2.2.5-4.el8
0:2.5.0-2.el8_10

Open the chart page →

6,085

Container images carrying it

1,647 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
expat@2.2.9-1ubuntu0.8
no fix listed
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
expat@2.7.1-r0
2.8.1-r0
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
expat@2.7.1-r0
2.8.1-r0
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
expat@2.7.4-r0
2.8.1-r0
1
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
expat@2.2.5-3ubuntu0.9
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
expat@2.2.9-1ubuntu0.8
no fix listed
1
ghcr.io/kubelauncher/cassandrab66aba320083
expat@2.7.4-1
no fix listed
1
ghcr.io/kubelauncher/kubectl7280594a2f18
expat@2.7.4-1
no fix listed
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
expat@2.2.9-1ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
expat@2.2.9-1build1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
expat@2.2.9-1build1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
expat@2.2.9-1build1
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
expat@2.2.9-1build1
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
expat@2.2.9-1build1
no fix listed
1
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
expat@2.5.0-1
no fix listed
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
expat@2.5.0-1+deb12u3
no fix listed
1
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
expat@2.2.5-16.el8_10
0:2.5.0-2.el8_10
1
ghcr.io/linuxoid69/webdav:1.26.2-r065bacf19caa7
expat@2.6.4-r0
2.8.1-r0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
expat@2.2.5-3ubuntu0.2
no fix listed
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
expat@2.6.4-r0
2.8.1-r0
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/linuxserver/duplicati:latesta792931146b4
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
expat@2.7.0-r0
2.8.1-r0
1
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
expat@2.5.0-5.el9_6
0:2.5.0-6.el9_8.1
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
expat@2.6.2-r0
2.8.1-r0
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
expat@2.6.1-2ubuntu0.3
no fix listed
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
expat@2.7.4-r0
2.8.1-r0
1
ghcr.io/marcuwynu23/vite-app-sample:latest21247f2b97c4
expat@2.7.5-r0
2.8.1-r0
1
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
expat@2.7.4-1
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
expat@2.5.0-1+deb12u1
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
expat@2.5.0-1
no fix listed
1
ghcr.io/microboxlabs/miot-calendar:latest-jvm7157cdc0bf5b
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
expat@2.6.1-2ubuntu0.2
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
expat@2.7.1-2
2.8.2-1~deb13u1
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
expat@2.5.0-1+deb12u2
no fix listed
1
ghcr.io/mydecisive/octant-ui:0.0.1-testing61e4066b22fb
expat@2.7.5-r0
2.8.1-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.