StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,611
of 17,792 indexed, latest versions
Container images
1,662
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,611 of 17,792 indexed charts deploy, on 1,662 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,143
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0313
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,611 by stars
ChartLatestAffected imagesRadar Score
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
expat@2.2.5-11.el8
0:2.5.0-2.el8_10

Open the chart page →

13,089
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
expat@2.5.0-1
no fix listed

Open the chart page →

12,998
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

9,227
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
expat@2.5.0-1
no fix listed

Open the chart page →

6,587
Practica_4_helmpr04helm0.1.03 of 7See more

Practica_4_helm pr04helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10
codeurjc/toposervice:v1.09fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

27,697
practica-helmpractica-helm0.1.02 of 7See more

practica-helm practica-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
expat@2.7.3-r0
2.8.1-r0
slagattollas/weatherservice-practica:latest68e7f56393fc
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

28,537
pagesprasanthi1.0.02 of 3See more

pages prasanthi 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,262
prefect-agentprefectVerified publisher2024.8.301638221 of 1See more

prefect-agent prefect 2024.8.30163822

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
expat@2.5.0-1
no fix listed

Open the chart page →

5,534
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
expat@2.4.7-1ubuntu0.4
no fix listed

Open the chart page →

3,328
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
expat@2.5.0-1
no fix listed

Open the chart page →

8,233
prismeai-appsprismeai0.7.11 of 4See more

prismeai-apps prismeai 0.7.1

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
expat@2.7.3-r0
2.8.1-r0

Open the chart page →

2,756
prismeai-coreprismeai1.12.11 of 7See more

prismeai-core prismeai 1.12.1

1 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
expat@2.7.3-r0
2.8.1-r0

Open the chart page →

3,275
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

4,449
prompt-dbprompt-dbVerified publisher1.0.71 of 3See more

prompt-db prompt-db 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

3,366
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
postgis/postgis:17-3.4-alpine5a1dbedac34e
expat@2.6.3-r0
2.8.1-r0

Open the chart page →

2,856
game-serverpvillaverdeVerified publisher1.0.61 of 1See more

game-server pvillaverde 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/itzg/minecraft-server:latest46919d151d39
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

4,162
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
expat@2.5.0-1
no fix listed

Open the chart page →

14,624
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
expat@2.5.0-1
no fix listed

Open the chart page →

12,652
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
expat@2.5.0-1
no fix listed

Open the chart page →

12,652
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

4,408
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

7,702
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

4,497
rada-platformrada-platform0.1.03 of 7See more

rada-platform rada-platform 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
expat@2.5.0-1+deb12u1
no fix listed
trinodb/trino:45038c6f24ab1a4
expat@2.5.0-2.el9_4
0:2.5.0-6.el9_8.1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
expat@2.5.0-2.el9_4
0:2.5.0-6.el9_8.1

Open the chart page →

21,287
app-configradar-baseVerified publisher1.7.21 of 1See more

app-config radar-base 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

2,090
app-config-frontendradar-baseVerified publisher2.4.11 of 1See more

app-config-frontend radar-base 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
expat@2.6.4-r0
2.8.1-r0

Open the chart page →

807
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

2,471
data-dashboard-backendradar-baseVerified publisher0.6.21 of 1See more

data-dashboard-backend radar-base 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

2,073
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
expat@2.5.0-3.el9_5.1
0:2.5.0-6.el9_8.1

Open the chart page →

9,418
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
expat@2.7.4-1
no fix listed

Open the chart page →

3,232
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
expat@2.2.5-11.el8
0:2.5.0-2.el8_10

Open the chart page →

5,269
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

2,337
radar-homeradar-baseVerified publisher0.5.51 of 1See more

radar-home radar-base 0.5.5

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
expat@2.6.4-r0
2.8.1-r0

Open the chart page →

807
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

2,909
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
expat@2.5.0-3.el9_5.3
0:2.5.0-6.el9_8.1

Open the chart page →

4,237
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

2,519
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

3,072
radar-rest-sources-authorizerradar-baseVerified publisher2.3.41 of 1See more

radar-rest-sources-authorizer radar-base 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
expat@2.6.4-r0
2.8.1-r0

Open the chart page →

807
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

2,587
radar-upload-connect-frontendradar-baseVerified publisher0.8.11 of 1See more

radar-upload-connect-frontend radar-base 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

939
s3-proxyradar-baseVerified publisher0.6.01 of 1See more

s3-proxy radar-base 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
expat@2.6.1-2ubuntu0.1
no fix listed

Open the chart page →

2,792
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
expat@2.5.0-3.el9_5.3
0:2.5.0-6.el9_8.1

Open the chart page →

1,969
pagesranjinigogga1.0.02 of 3See more

pages ranjinigogga 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,262
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

15,552
pagesrebecca-pages1.0.02 of 3See more

pages rebecca-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,262
ibm-mongodb-enterprise-helmredhat0.3.01 of 1See more

ibm-mongodb-enterprise-helm redhat 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
expat@2.2.5-4.el8
0:2.5.0-2.el8_10

Open the chart page →

12,383
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
expat@2.2.5-4.el8_4.4
0:2.5.0-2.el8_10

Open the chart page →

15,299
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
expat@2.2.5-4.el8_4.4
0:2.5.0-2.el8_10

Open the chart page →

15,299
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
expat@2.2.5-3.el8_2.3
0:2.5.0-2.el8_10

Open the chart page →

11,446
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
expat@2.4.7-1ubuntu0.4
no fix listed

Open the chart page →

4,254
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
expat@2.2.5-8.el8_6.4
0:2.5.0-2.el8_10

Open the chart page →

16,389

Container images carrying it

1,662 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
expat@2.5.0-1+deb12u3
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
expat@2.5.0-1+deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
expat@2.5.0-1+deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
expat@2.5.0-1+deb12u3
no fix listed
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
expat@2.2.5-10.el8
0:2.5.0-2.el8_10
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
expat@2.2.5-10.el8
0:2.5.0-2.el8_10
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
expat@2.5.0-5.el9_6
0:2.5.0-6.el9_8.1
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
expat@2.5.0-6.el9
0:2.5.0-6.el9_8.1
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
expat@2.5.0-6.el9
0:2.5.0-6.el9_8.1
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
expat@2.5.0-3.el9_5.1
0:2.5.0-6.el9_8.1
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
expat@2.5.0-3.el9_5.1
0:2.5.0-6.el9_8.1
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
expat@2.2.5-4.el8_5.3
0:2.5.0-2.el8_10
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
expat@2.2.5-3.el8
0:2.5.0-2.el8_10
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
quay.io/minio/directpv:v4.0.84560083eb77d
expat@2.2.5-11.el8
0:2.5.0-2.el8_10
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
expat@2.5.0-1+deb12u1
no fix listed
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
quay.io/openshift/origin-cli:4.66722d5041b47
expat@2.2.5-3.el8_2.3
0:2.5.0-2.el8_10
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
expat@2.2.5-3.el8_2.3
0:2.5.0-2.el8_10
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
expat@2.2.5-8.el8_6.4
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
no fix listed
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
expat@2.7.3-r0
2.8.1-r0
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
expat@2.7.3-r0
2.8.1-r0
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
expat@2.7.3-r0
2.8.1-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
expat@2.7.3-r0
2.8.1-r0
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
expat@2.7.4-1
no fix listed
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
expat@2.5.0-2.el9_4
0:2.5.0-6.el9_8.1
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
expat@2.5.0-1.el9
0:2.5.0-6.el9_8.1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
expat@2.2.5-16.el8_10
0:2.5.0-2.el8_10
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
expat@2.5.0-3.el9_5.1
0:2.5.0-6.el9_8.1
1
quay.io/strimzi/operator:0.45.158c727cd2e68
expat@2.5.0-5.el9_6
0:2.5.0-6.el9_8.1
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
expat@2.2.5-11.el8
0:2.5.0-2.el8_10
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
expat@2.7.0-r0
2.8.1-r0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
expat@2.5.0-1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
expat@2.6.1-2ubuntu0.4
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.