StackRadar

CVE-2026-56409

Medium

Advisory

Published 21 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,394
of 17,787 indexed, latest versions
Container images
1,380
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,394 of 17,787 indexed charts deploy, on 1,380 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+32 more2.5.0-1+deb12u3, 2.8.2-1~deb13u11,126
expatapk2.5.0-r4, 2.6.4-r0, 2.6.4-r1, 2.7.0-r0+9 more2.8.2-r0254
OSV records
ALPINE-CVE-2026-56409CGA-j2m5-28h2-3hvmDEBIAN-CVE-2026-56409UBUNTU-CVE-2026-56409
Also known as
CGA-pmhc-mmwh-hrg6, CGA-v5r8-jc5r-v5v8, CGA-xvmf-jgc5-3w6g

Charts affected

1,394 by stars
ChartLatestAffected imagesRadar Score
passboltpassbolt2.1.11 of 6See more

passbolt passbolt 2.1.1

1 of the 6 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

13,455
reposilitereposilite1.4.21 of 1See more

reposilite reposilite 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.6.390de4c8e6c0e
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,028
selenium-gridselenium-grid0.59.13 of 4See more

selenium-grid selenium-grid 0.59.1

3 of the 4 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
selenium/hub:4.48.0-20260905d47c27474cb4
expat@2.6.1-2ubuntu0.4
no fix listed
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
expat@2.6.1-2ubuntu0.4
no fix listed
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

7,168
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

2,927
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

14,266
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

7,935
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
expat@2.7.4-1
no fix listed

Open the chart page →

8,907
openvpn-asas-helm-chartOfficialVerified publisher0.2.11 of 1See more

openvpn-as as-helm-chart 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
openvpn/openvpn-as:latest2253c10ec652
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

2,716
bambooatlassian-data-centerVerified publisher2.0.151 of 2See more

bamboo atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
atlassian/bamboo:12.1.114af4bb6c8d46
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

2,079
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
expat@2.2.9-1build1
no fix listed
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
expat@2.2.9-1build1
no fix listed

Open the chart page →

53,012
headwind-mdmchristianhuthVerified publisher5.10.11 of 2See more

headwind-mdm christianhuth 5.10.1

1 of the 2 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
headwindmdm/hmdm:0.1.93550b4840840
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

5,915
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
dolibarr/dolibarr:22.0.47ad88fc9b13c
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

9,154
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
expat@2.4.7-1ubuntu0.6
no fix listed

Open the chart page →

27,358
jellyfindjjudas21Verified publisher4.0.81 of 1See more

jellyfin djjudas21 4.0.8

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

2,615
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
redocly/redoc:latest2e26bb660574
expat@2.7.5-r0
2.8.2-r0

Open the chart page →

3,282
geonode-k8sgeonode-k8sVerified publisher2.0.02 of 10See more

geonode-k8s geonode-k8s 2.0.0

2 of the 10 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
expat@2.4.7-1ubuntu0.7
no fix listed
geopython/pycsw:3.0.0-beta284662ea6b78b
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

14,043
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

12,270
dolibarrhelmforgeVerified publisher1.2.181 of 3See more

dolibarr helmforge 1.2.18

1 of the 3 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
dolibarr/dolibarr:24.0.069ec52e3b7ef
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

4,136
karakeephelmforgeVerified publisher1.2.92 of 3See more

karakeep helmforge 1.2.9

2 of the 3 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
expat@2.6.1-2ubuntu0.4
no fix listed
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

9,535
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
expat@2.6.1-2ubuntu0.3
no fix listed
apache/hertzbeat-collector:1.8.0a2bab1be574c
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

14,109
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

6,354
kubeflowkubeflow1.6.22 of 45See more

kubeflow kubeflow 1.6.2

2 of the 45 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
expat@2.2.5-3ubuntu0.2
no fix listed
library/python:3.7eedf63967cdb
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

97,040
testkubekubeshop2.13.21 of 5See more

testkube kubeshop 2.13.2

1 of the 5 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

5,012
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

4,050
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

7,968
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

8,767
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

10,536
topolvmtopolvmVerified publisher17.2.01 of 1See more

topolvm topolvm 17.2.0

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

2,364
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

19,363
unboundunbound-helmchartVerified publisher0.2.21 of 1See more

unbound unbound-helmchart 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
expat@2.7.4-r0
2.8.2-r0

Open the chart page →

1,495
athens-proxyvolker-raschekVerified publisher2.0.31 of 1See more

athens-proxy volker-raschek 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
gomods/athens:v0.17.10f61d1e62359
expat@2.7.5-r0
2.8.2-r0

Open the chart page →

2,040
reposilitevolker-raschekVerified publisher1.0.01 of 1See more

reposilite volker-raschek 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.5.264128c2d7a6ba
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

2,996
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

9,753
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

8,251
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
expat@2.7.4-1
no fix listed

Open the chart page →

1,245
bookstackbookstack-mgVerified publisher0.3.11 of 2See more

bookstack bookstack-mg 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
linuxserver/bookstack:26.05.202605282ebf97852661
expat@2.7.5-r0
2.8.2-r0

Open the chart page →

1,896
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

8,007
geoservercloudcamptocamp23.0.17 of 7See more

geoservercloud camptocamp2 3.0.1

7 of the 7 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
expat@2.7.4-1
no fix listed

Open the chart page →

10,819
thingsboardcetic0.1.21 of 2See more

thingsboard cetic 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
thingsboard/tb-postgres:latest2d17e4e36edc
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

5,243
collabora-codechrisingenhaag2.6.01 of 1See more

collabora-code chrisingenhaag 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
collabora/code:23.05.10.1.105299b452f7f
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

4,184
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
expat@2.7.5-r0
2.8.2-r0

Open the chart page →

2,126
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

17,475
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

27,984
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
expat@2.7.1-2
2.8.2-1~deb13u1

Open the chart page →

9,348
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
expat@2.6.1-2ubuntu0.1
no fix listed

Open the chart page →

4,194
healthchecksgabe565Verified publisher0.17.01 of 1See more

healthchecks gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
expat@2.7.0-r0
2.8.2-r0

Open the chart page →

2,285
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

22,812
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
expat@2.2.9-1build1
no fix listed

Open the chart page →

10,652
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
expat@2.2.9-1ubuntu0.2
no fix listed

Open the chart page →

10,202
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-56409.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
expat@2.2.9-1build1
no fix listed

Open the chart page →

10,676

Container images carrying it

1,380 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
stackstorm/st2stream:3.81c8904a3bf67
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
expat@2.2.9-1ubuntu0.6
no fix listed
1
stashapp/stash:latest24dbd7607174
expat@2.2.9-1build1
no fix listed
1
stashapp/stash:v0.31.1df744af5a0c9
expat@2.7.5-r0
2.8.2-r0
1
stashapp/stash-box:latesta534c8afdf39
expat@2.6.1-2ubuntu0.3
no fix listed
1
statcan/ckan:2.93921305425b8
expat@2.2.9-1build1
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
expat@2.2.9-1build1
no fix listed
1
structurizr/onpremises:2025.11.094b5ffb5119c8
expat@2.6.1-2ubuntu0.3
no fix listed
1
substratusai/verba:v0.4.0-baseURL261695be635eb
expat@2.5.0-1
2.5.0-1+deb12u3
1
supabase/realtime:v2.102.3aa1c92c0cf32
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
supabase/realtime:latestd3aa0c86c7b3
expat@2.7.1-2
2.8.2-1~deb13u1
1
supabase/storage-api:v1.60.4c8eb9858eafe
expat@2.7.5-r0
2.8.2-r0
1
supabase/studio:20241021-9f9b08326d8070c55e9
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
svcosti/cidrapp:latest8428d87bc5d0
expat@2.7.0-r0
2.8.2-r0
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
expat@2.4.7-1ubuntu0.3
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
expat@2.2.9-1ubuntu0.6
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
expat@2.5.0-1
2.5.0-1+deb12u3
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
expat@2.2.9-1ubuntu0.6
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
expat@2.4.7-1ubuntu0.7
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
tchiotludo/akhq:0.28.0c2824dc2ae44
expat@2.7.4-1
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
expat@2.5.0-1
2.5.0-1+deb12u3
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
expat@2.7.1-r0
2.8.2-r0
1
temporalio/admin-tools:1.28cfde8170c92f
expat@2.7.4-r0
2.8.2-r0
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
tenureai/tenure:v1.0.285f5b222df9a5
expat@2.7.1-2+dhi4
2.8.2-1~deb13u1
1
theradius/loggia:0.463ba348546ec
expat@2.5.0-1
2.5.0-1+deb12u3
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
expat@2.7.1-2
2.8.2-1~deb13u1
1
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
expat@2.7.1-2
2.8.2-1~deb13u1
1
thingsboard/tb-postgres:latest2d17e4e36edc
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
thmmniii/fbs-core:v1.27.15438517d9fc2
expat@2.4.7-1
no fix listed
1
thongngo3301/stakefish:latesta341af5976e3
expat@2.5.0-1
2.5.0-1+deb12u3
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
expat@2.4.7-1ubuntu0.2
no fix listed
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
expat@2.4.7-1ubuntu0.2
no fix listed
1
timescale/timescaledb-ha:pg16d7db8f1085a3
expat@2.4.7-1ubuntu0.7
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
expat@2.4.7-1ubuntu0.5
no fix listed
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
expat@2.4.7-1
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
expat@2.7.1-2
2.8.2-1~deb13u1
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
expat@2.7.1-2
2.8.2-1~deb13u1
1
tombursch/kitchenowl-web:v0.7.8517f808eee66
expat@2.7.5-r0
2.8.2-r0
1
tomsquest/docker-radicale:3.6.1.0a594c624c5a6
expat@2.7.4-r0
2.8.2-r0
1
tpdock/freeradius:2.2.93da600c95a49
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
treskon/portrait:DEV-latest88e813f22347
expat@2.7.4-1
no fix listed
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
trinodb/trino:405ee80ab5eeab2
expat@2.4.7-1ubuntu0.2
no fix listed
1
trueosiris/vrising:latest9356f98ad561
expat@2.4.7-1ubuntu0.7
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.