StackRadar

CVE-2026-56405

Medium

Advisory

Published 21 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,394
of 17,787 indexed, latest versions
Container images
1,380
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,394 of 17,787 indexed charts deploy, on 1,380 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+32 more2.5.0-1+deb12u3, 2.8.2-1~deb13u11,126
expatapk2.5.0-r4, 2.6.4-r0, 2.6.4-r1, 2.7.0-r0+9 more2.8.2-r0254
OSV records
ALPINE-CVE-2026-56405CGA-2r65-39hv-c468DEBIAN-CVE-2026-56405UBUNTU-CVE-2026-56405
Also known as
CGA-6mc4-rw6m-8pjc, CGA-v7hc-v7f3-2f43, CGA-vxhx-gmqq-f3g8

Charts affected

1,394 by stars
ChartLatestAffected imagesRadar Score
camel-kcamel-kVerified publisher2.11.01 of 1See more

camel-k camel-k 2.11.0

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
apache/camel-k:2.11.0d173e7efe258
expat@2.7.4-1
no fix listed

Open the chart page →

1,265
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

11,971
milvusmilvus-helm5.0.281 of 4See more

milvus milvus-helm 5.0.28

1 of the 4 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
expat@2.4.7-1ubuntu0.4
no fix listed

Open the chart page →

10,764
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

6,385
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

18,570
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,492
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

2,963
codefreshcodefresh-onpremOfficialVerified publisher2.12.131 of 42See more

codefresh codefresh-onprem 2.12.13

1 of the 42 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

14,615
memgraphmemgraphVerified publisher1.0.71 of 2See more

memgraph memgraph 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.1bd3fe13228f4
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,208
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2api:3.86f56d239d280
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2auth:3.833ecfda16608
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2notifier:3.8f190a6212195
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
expat@2.2.9-1ubuntu0.6
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.02 of 14See more

supabase tokens-studio 1.0.0

2 of the 14 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
library/kong:3.8.0712e407b20ea
expat@2.4.7-1ubuntu0.7
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

23,263
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

8,530
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,749
budibasebudibase0.0.0-master2 of 7See more

budibase budibase 0.0.0-master

2 of the 7 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
budibase/proxy:3.41.38d780b6ee602
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

10,810
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
expat@2.7.3-r0
2.8.2-r0
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
expat@2.7.3-r0
2.8.2-r0
yuzutech/kroki-excalidraw:0.29.157917319ea70
expat@2.7.3-r0
2.8.2-r0
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
expat@2.7.3-r0
2.8.2-r0

Open the chart page →

6,743
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

3,818
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
expat@2.7.3-r0
2.8.2-r0

Open the chart page →

1,110
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

7,896
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
expat@2.7.4-1
no fix listed

Open the chart page →

1,490
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
expat@2.7.4-1
no fix listed

Open the chart page →

1,255
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
expat@2.7.4-1
no fix listed

Open the chart page →

3,128
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

3,050
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
expat@2.2.9-1build1
no fix listed

Open the chart page →

11,453
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

4,281
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

4,604
devtron-operatordevtron0.23.32 of 11See more

devtron-operator devtron 0.23.3

2 of the 11 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
quay.io/devtron/dashboard:c7b89667-690-39290c63823af3835
expat@2.8.1-r0
2.8.2-r0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

3,645
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
expat@2.6.1-2ubuntu0.2
no fix listed

Open the chart page →

5,396
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,112
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
expat@2.6.1-2ubuntu0.1
no fix listed

Open the chart page →

3,434
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

5,665
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

4,344
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
expat@2.7.3-r0
2.8.2-r0

Open the chart page →

30,481
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
openmined/syft-backend:0.9.5b72f74a68b32
expat@2.6.4-r1
2.8.2-r0

Open the chart page →

17,306
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
expat@2.4.7-1ubuntu0.3
no fix listed
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
expat@2.4.7-1ubuntu0.3
no fix listed

Open the chart page →

14,276
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
expat@2.2.9-1build1
no fix listed

Open the chart page →

11,831
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

7,333
zabbix-serveraekondratievVerified publisher1.0.61 of 4See more

zabbix-server aekondratiev 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
expat@2.2.9-1build1
no fix listed

Open the chart page →

30,811
home-assistantalekcVerified publisher2.11.21 of 1See more

home-assistant alekc 2.11.2

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
expat@2.8.1-r0
2.8.2-r0

Open the chart page →

2,139
home-assistantandrenarchyVerified publisher14.103.01 of 1See more

home-assistant andrenarchy 14.103.0

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.1612d76760b54
expat@2.8.1-r0
2.8.2-r0

Open the chart page →

2,139
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,463
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

6,484
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

12,163
emqx-operatoremqx-operator2.3.21 of 2See more

emqx-operator emqx-operator 2.3.2

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
alpine/k8s:1.31.49c4976d47656
expat@2.6.4-r0
2.8.2-r0

Open the chart page →

4,532
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
expat@2.6.4-r0
2.8.2-r0

Open the chart page →

2,811
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,539
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

4,951
jellyfinloeken-at-homeVerified publisher10.11.81 of 1See more

jellyfin loeken-at-home 10.11.8

1 of the 1 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
loeken/jellyfin:10.11.87efbc24e47b0
expat@2.7.5-r0
2.8.2-r0

Open the chart page →

882
meshery-operatormesheryOfficialVerified publisher1.0.701 of 2See more

meshery-operator meshery 1.0.70

1 of the 2 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
alpine/k8s:1.35.6b7a12c5ddf26
expat@2.8.1-r0
2.8.2-r0

Open the chart page →

2,416
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-56405.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

8,685

Container images carrying it

1,380 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/thoroslives/zilean:v3.10.1bce6aca0f6ca
expat@2.7.0-r0
2.8.2-r0
1
ghcr.io/topolvm/pie:0.18.0aa467443e407
expat@2.4.7-1ubuntu0.7
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
expat@2.4.7-1ubuntu0.7
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
expat@2.4.7-1ubuntu0.4
no fix listed
1
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
expat@2.7.4-r0
2.8.2-r0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
expat@2.4.7-1ubuntu0.3
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
expat@2.4.7-1ubuntu0.3
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
expat@2.4.7-1ubuntu0.5
no fix listed
1
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
expat@2.7.5-r0
2.8.2-r0
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
expat@2.5.0-1
2.5.0-1+deb12u3
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
expat@2.5.0-1
2.5.0-1+deb12u3
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/zazukoians/qlever-server:v0.10.0f10fd24b2290
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
expat@2.7.1-r0
2.8.2-r0
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
expat@2.2.5-3ubuntu0.9
no fix listed
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
expat@2.2.9-1ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
expat@2.6.1-2ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
expat@2.4.7-1ubuntu0.7
no fix listed
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
expat@2.6.1-2ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
expat@2.2.5-3ubuntu0.9
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
expat@2.6.1-2ubuntu0.3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
expat@2.7.5-r0
2.8.2-r0
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
expat@2.7.5-r0
2.8.2-r0
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
expat@2.2.9-1build1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
expat@2.5.0-1
2.5.0-1+deb12u3
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
expat@2.7.4-1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
expat@2.4.7-1
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
expat@2.4.7-1ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.