StackRadar

CVE-2026-45186

High

Advisory

Published 10 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,597
of 17,790 indexed, latest versions
Container images
1,645
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 1,597 of 17,790 indexed charts deploy, on 1,645 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+33 more2.8.2-1~deb13u11,130
expatapk2.5.0-r4, 2.6.2-r0, 2.6.3-r0, 2.6.4-r0+10 more2.8.1-r0309
expatrpm2.2.5-3.el8, 2.2.5-3.el8_2.3, 2.2.5-4.el8, 2.2.5-4.el8_4.4+22 more0:2.5.0-2.el8_10, 0:2.5.0-6.el9_8.1206
OSV records
ALPINE-CVE-2026-45186DEBIAN-CVE-2026-45186RHSA-2026:22721RHSA-2026:23230RLSA-2026:22721RLSA-2026:23230CGA-5xh9-v979-7vhcUBUNTU-CVE-2026-45186
Also known as
CGA-6x8g-rx24-rm2q

Charts affected

1,597 by stars
ChartLatestAffected imagesRadar Score
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

10,716
jdownloader2jdownloader2Verified publisher1.10.01 of 1See more

jdownloader2 jdownloader2 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jlesage/jdownloader-2:v26.03.13d6cb102bd9b
expat@2.7.4-r0
2.8.1-r0

Open the chart page →

539
jellyfinjellyfinVerified publisher0.3.301 of 1See more

jellyfin jellyfin 0.3.30

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

2,571
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
expat@2.2.5-8.el8_6.3
0:2.5.0-2.el8_10

Open the chart page →

9,318
chronoreaperjfwenischVerified publisher1.1.101 of 1See more

chronoreaper jfwenisch 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,022
jenkinsjkimVerified publisher5.5.142 of 2See more

jenkins jkim 5.5.14

2 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
expat@2.5.0-1
no fix listed
kiwigrid/k8s-sidecar:1.27.6db85bd553253
expat@2.6.2-r0
2.8.1-r0

Open the chart page →

7,393
qbittorrentk8s-chartsVerified publisher3.1.01 of 2See more

qbittorrent k8s-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/hotio/qbittorrent:release-5.2.007198d49e5b4
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,271
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.321 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

1 of the 17 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

15,459
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
expat@2.4.7-1ubuntu0.2
no fix listed
kafkakraft/kafka-controller:3.7.0f261ad288fce
expat@2.4.7-1ubuntu0.2
no fix listed
kafkakraft/kafkakraft:3.7.02e4b593b878b
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

14,250
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

5,515
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,795
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
expat@2.5.0-2.el9_4
0:2.5.0-6.el9_8.1

Open the chart page →

12,063
nginx-php-fpmkokuwa0.1.41 of 2See more

nginx-php-fpm kokuwa 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
expat@2.7.1-r0
2.8.1-r0

Open the chart page →

1,840
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
expat@2.5.0-1
no fix listed
langgenius/dify-sandbox:0.2.009b7e8705673
expat@2.5.0-1
no fix listed

Open the chart page →

20,424
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

9,975
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

4,101
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

7,749
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
expat@2.2.9-1ubuntu0.2
no fix listed

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
expat@2.2.9-1build1
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
expat@2.2.9-1build1
no fix listed

Open the chart page →

114,025
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
expat@2.7.1-r0
2.8.1-r0

Open the chart page →

5,657
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

3,551
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
expat@2.7.4-1
no fix listed

Open the chart page →

1,487
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
expat@2.7.4-1
no fix listed

Open the chart page →

2,708
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

2,113
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

4,011
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

35,058
fhir-serverlinuxforhealth0.9.11 of 2See more

fhir-server linuxforhealth 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
expat@2.2.5-16.el8_10
0:2.5.0-2.el8_10

Open the chart page →

1,052
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
expat@2.7.1-r3
2.8.1-r0

Open the chart page →

4,390
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

7,216
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

1,147
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

5,747
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,741
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

13,582
plane-enterprisemakeplaneOfficialVerified publisher3.7.21 of 13See more

plane-enterprise makeplane 3.7.2

1 of the 13 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/rabbitmq:3.13.6-management-alpine611107e29cce
expat@2.6.2-r0
2.8.1-r0

Open the chart page →

4,942
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

3,014
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
expat@2.7.4-1
no fix listed

Open the chart page →

6,994
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

2,764
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
expat@2.6.1-2ubuntu0.2
no fix listed

Open the chart page →

4,184
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
expat@2.2.5-4.el8
0:2.5.0-2.el8_10

Open the chart page →

6,915
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
expat@2.7.1-2
no fix listed

Open the chart page →

11,108
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

13,763
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

7,552
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
expat@2.7.5-r0
2.8.1-r0

Open the chart page →

2,576
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
expat@2.7.3-r0
2.8.1-r0

Open the chart page →

37,441
dashdotoben01Verified publisher1.5.01 of 1See more

dashdot oben01 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
mauricenino/dashdot:5.9.2236997816917
expat@2.7.0-r0
2.8.1-r0

Open the chart page →

1,237
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

5,051
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
expat@2.5.0-1
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
expat@2.5.0-1
no fix listed

Open the chart page →

14,862
opentelemetry-demoopentelemetry-helmVerified publisher0.41.24See more

opentelemetry-demo opentelemetry-helm 0.41.2

4 container images this version deploys carry CVE-2026-45186.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
expat@2.7.5-r0
2.8.1-r0
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
expat@2.5.0-1+deb12u2
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
expat@2.7.3-r0
2.8.1-r0
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

Container images carrying it

1,645 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
expat@2.2.5-4.el8_5.3
0:2.5.0-2.el8_10
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
expat@2.2.5-3.el8
0:2.5.0-2.el8_10
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
quay.io/minio/directpv:v4.0.84560083eb77d
expat@2.2.5-11.el8
0:2.5.0-2.el8_10
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
expat@2.5.0-1+deb12u1
no fix listed
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
quay.io/openshift/origin-cli:4.66722d5041b47
expat@2.2.5-3.el8_2.3
0:2.5.0-2.el8_10
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
expat@2.2.5-3.el8_2.3
0:2.5.0-2.el8_10
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
expat@2.2.5-8.el8_6.4
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
no fix listed
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
expat@2.5.0-1.el8_10
0:2.5.0-2.el8_10
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
expat@2.7.3-r0
2.8.1-r0
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
expat@2.7.3-r0
2.8.1-r0
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
expat@2.7.3-r0
2.8.1-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
expat@2.7.3-r0
2.8.1-r0
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
expat@2.7.4-1
no fix listed
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
expat@2.5.0-2.el9_4
0:2.5.0-6.el9_8.1
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
expat@2.5.0-1.el9
0:2.5.0-6.el9_8.1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
expat@2.2.5-16.el8_10
0:2.5.0-2.el8_10
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
expat@2.5.0-3.el9_5.1
0:2.5.0-6.el9_8.1
1
quay.io/strimzi/operator:0.45.158c727cd2e68
expat@2.5.0-5.el9_6
0:2.5.0-6.el9_8.1
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
expat@2.2.5-11.el8
0:2.5.0-2.el8_10
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
expat@2.7.0-r0
2.8.1-r0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
expat@2.2.5-10.el8_7.1
0:2.5.0-2.el8_10
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
expat@2.5.0-1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
expat@2.6.1-2ubuntu0.4
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
expat@2.7.4-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
expat@2.7.1-2
2.8.2-1~deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
expat@2.5.0-1+deb12u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
expat@2.2.5-4.el8
0:2.5.0-2.el8_10
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
expat@2.2.9-1build1
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
expat@2.5.0-1+deb12u2
no fix listed
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
expat@2.7.5-r0
2.8.1-r0
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
expat@2.5.0-5.el9_7.1
0:2.5.0-6.el9_8.1
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
expat@2.7.1-2
2.8.2-1~deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
expat@2.5.0-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
expat@2.5.0-1+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
expat@2.5.0-1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.