CVE-2026-45186
HighAdvisory
Published 10 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 39th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,609
- of 17,797 indexed, latest versions
- Container images
- 1,657
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: expat security update
Carried by container images the latest versions of 1,609 of 17,797 indexed charts deploy, on 1,657 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| expatdeb | 2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more | 2.8.2-1~deb13u1 | 1,139 |
| expatapk | 2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more | 2.8.1-r0 | 312 |
| expatrpm | 2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more | 0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1 | 206 |
- OSV records
- ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
- Also known as
- CGA-6x8g-rx24-rm2q
Charts affected
1,609 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| marge-botwiremindVerified publisher | 1.4.4 | 1 of 1See more | 5,566 |
| metabasewiremindVerified publisher | 2.27.5-wiremind0 | 1 of 1See more | 1,635 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,218 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,622 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,714 |
| xkopsxkops | 0.1.0 | 2 of 5See more | 13,813 |
| keycloakxzaks | 2.2.0 | 1 of 1See more | 6,017 |
| changedetection-iozekker6Verified publisher | 1.101.0 | 1See more | — |
| zoo-project-druzoo-projectOfficialVerified publisher | 0.10.4 | 1 of 6See more | 7,936 |
Container images carrying it
1,657 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.