StackRadar

CVE-2026-66046

High

Advisory

Published 18 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,770
of 17,787 indexed, latest versions
Container images
1,632
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-66046 affecting package expat for versions less than 2.8.3-2

Carried by container images the latest versions of 1,770 of 17,787 indexed charts deploy, on 1,632 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+36 more2.8.4-11,224
expatapk2.6.4-r0, 2.7.0-r0, 2.7.1-r0, 2.7.2-r0+7 more2.8.4-r0406
expatrpm2.8.2-1.azl32.8.3-22
OSV records
ALPINE-CVE-2026-66046DEBIAN-CVE-2026-66046UBUNTU-CVE-2026-66046AZL-96605ECHO-38c1-1304-759b

Charts affected

1,770 by stars
ChartLatestAffected imagesRadar Score
platform-apiappscodeVerified publisher2026.9.111 of 3See more

platform-api appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
expat@2.7.1-2
no fix listed

Open the chart page →

37,268
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
expat@2.4.7-1ubuntu0.3
no fix listed

Open the chart page →

3,270
websiteappscodeVerified publisher2026.9.111 of 1See more

website appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
ghcr.io/appscode/website:v2026.9.1170d9d1b78d39
expat@2.8.2-r0
2.8.4-r0

Open the chart page →

370
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
expat@2.7.4-r0
2.8.4-r0

Open the chart page →

9,847
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
expat@2.7.1-2
no fix listed

Open the chart page →

7,489
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

7,300
aias-servicesarlas-stackVerified publisher28.8.04 of 5See more

aias-services arlas-stack 28.8.0

4 of the 5 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
gisaia/agate:0.18.198213fa403ae
expat@2.8.3-r0
2.8.4-r0
gisaia/airs:0.18.15abfe00317bf
expat@2.8.3-r0
2.8.4-r0
gisaia/aproc-service:0.18.1ac6564921994
expat@2.8.3-r0
2.8.4-r0
gisaia/fam:0.18.1ae525930b4b6
expat@2.8.3-r0
2.8.4-r0

Open the chart page →

1,001
arlas-aiasarlas-stackVerified publisher28.8.05 of 22See more

arlas-aias arlas-stack 28.8.0

5 of the 22 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
gisaia/agate:0.18.198213fa403ae
expat@2.8.3-r0
2.8.4-r0
gisaia/airs:0.18.15abfe00317bf
expat@2.8.3-r0
2.8.4-r0
gisaia/aproc-service:0.18.1ac6564921994
expat@2.8.3-r0
2.8.4-r0
gisaia/fam:0.18.1ae525930b4b6
expat@2.8.3-r0
2.8.4-r0
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

40,238
titilerarlas-stackVerified publisher28.8.01 of 1See more

titiler arlas-stack 28.8.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:latest0f31f8b0441b
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,445
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

23,353
keystonearzu0.2.293 of 4See more

keystone arzu 0.2.29

3 of the 4 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
library/rabbitmq:3.7-managementb6dd45cc35b3
expat@2.2.5-3ubuntu0.2
no fix listed
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
expat@2.2.9-1ubuntu0.6
no fix listed
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

22,568
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
expat@2.1.0-7ubuntu0.16.04.3
no fix listed

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
expat@2.1.0-7ubuntu0.16.04.3
no fix listed

Open the chart page →

77,706
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
expat@2.4.7-1
no fix listed

Open the chart page →

10,061
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

18,277
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

7,936
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
expat@2.5.0-1
no fix listed
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
expat@2.5.0-1
no fix listed
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
expat@2.5.0-1
no fix listed

Open the chart page →

45,363
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
expat@2.2.9-1ubuntu0.6
no fix listed
library/nginx:latest05b8cb60c354
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

13,913
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
expat@2.4.7-1ubuntu0.2
no fix listed
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
expat@2.5.0-1
no fix listed

Open the chart page →

32,501
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
expat@2.5.0-1
no fix listed

Open the chart page →

9,412
bamboo-agentatlassian-data-centerVerified publisher2.0.151 of 1See more

bamboo-agent atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,581
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
expat@2.5.0-1
no fix listed

Open the chart page →

6,297
nas-appsawesomeVerified publisher2.0.03 of 8See more

nas-apps awesome 2.0.0

3 of the 8 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
expat@2.8.3-1~deb13u1
no fix listed
linuxserver/qbittorrent:latesta00b6a597a38
expat@2.8.3-r0
2.8.4-r0
wettyoss/wetty:latest7423b3d40ba2
expat@2.8.2-r0
2.8.4-r0

Open the chart page →

7,152
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
expat@2.5.0-1+deb12u1
no fix listed
kuzwolka/aws9:news3e8880fbbb96
expat@2.5.0-1+deb12u1
no fix listed
kuzwolka/aws9:blog4a7707410bf1
expat@2.5.0-1+deb12u1
no fix listed
kuzwolka/aws9:shop84a9d9766345
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

18,344
aws-web-service-proxifiedaws-web-service-proxified1.8.01 of 2See more

aws-web-service-proxified aws-web-service-proxified 1.8.0

1 of the 2 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
library/httpd:latest979c38c2228d
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,009
axosyslogaxosyslogVerified publisher0.21.01 of 1See more

axosyslog axosyslog 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
ghcr.io/axoflow/axosyslog:4.27.00379598e9ad2
expat@2.8.2-r0
2.8.4-r0

Open the chart page →

394
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
expat@2.4.7-1ubuntu0.5
no fix listed

Open the chart page →

3,268
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
expat@2.5.0-1
no fix listed

Open the chart page →

6,297
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
expat@2.2.9-1ubuntu0.4
no fix listed
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
expat@2.2.9-1ubuntu0.4
no fix listed
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

20,671
my-nginx-appbassant-nginx-app0.1.01 of 1See more

my-nginx-app bassant-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,827
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
expat@2.8.2-r0
2.8.4-r0

Open the chart page →

1,722
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

4,028
wyoming-piperbdclark-helm-chartsVerified publisher0.1.41 of 1See more

wyoming-piper bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
rhasspy/wyoming-piper:2.5.27d39aafac409
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,170
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,190
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
expat@2.4.7-1ubuntu0.4
no fix listed

Open the chart page →

7,190
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

5,059
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

7,956
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

10,145
bdbablackduck2026.6.31 of 9See more

bdba blackduck 2026.6.3

1 of the 9 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

9,521
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

13,459
bluespacebluespace0.3.01 of 1See more

bluespace bluespace 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,827
colosseumbook-k8sinfra-v21.0.183 of 5See more

colosseum book-k8sinfra-v2 1.0.18

3 of the 5 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
expat@2.4.7-1ubuntu0.7
no fix listed
sysnet4admin/colosseum-cms:loge74b43c7f492
expat@2.5.0-1+deb12u1
no fix listed
sysnet4admin/colosseum-prm:log5802bfcd7fed
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

26,996
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

6,220
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
expat@2.4.7-1ubuntu0.2
no fix listed
library/cassandra:3.11.65aa8400b4b3b
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

19,229
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
expat@2.5.0-1
no fix listed

Open the chart page →

8,323
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

27,274
qbittorrentbrandan-schmitz-helm-chartsVerified publisher2.2.01 of 1See more

qbittorrent brandan-schmitz-helm-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
linuxserver/qbittorrent:5.2.2dd24a5f3db32
expat@2.8.2-r0
2.8.4-r0

Open the chart page →

956
tenantsbrbarmex-tenant2.0.01 of 1See more

tenants brbarmex-tenant 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,827
pagesbrian-pages1.0.02 of 3See more

pages brian-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-66046.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,190

Container images carrying it

1,632 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
3
prompve/prometheus-pve-exporter:3.10.04867684c0a93
expat@2.8.2-r0
2.8.4-r0
3
selenium/hub:3.141.5902f251d48d5f
expat@2.2.9-1build1
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
expat@2.5.0-1
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
expat@2.5.0-1+deb12u1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
expat@2.4.7-1ubuntu0.2
no fix listed
3
quay.io/devtron/dashboard:0d8f6cf4-60e17132-931-39393aa61fffb8ae8
expat@2.8.1-r0
2.8.4-r0
3
quay.io/devtron/dashboard:c7b89667-690-39290c63823af3835
expat@2.8.1-r0
2.8.4-r0
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
expat@2.6.1-2ubuntu0.4
no fix listed
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
expat@2.8.2-r0
2.8.4-r0
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
expat@2.8.2-r0
2.8.4-r0
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
expat@2.5.0-1+deb12u2
no fix listed
3
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
expat@2.8.2-r0
2.8.4-r0
3
alpine/git:2.47.2062a01ad7a0e
expat@2.7.0-r0
2.8.4-r0
2
alpine/git:latest4f9488b7295b
expat@2.8.3-r0
2.8.4-r0
2
alpine/k8s:1.32.12048f8d9c8cc7
expat@2.7.4-r0
2.8.4-r0
2
apache/druid:37.0.00116fb802786
expat@2.5.0-1+deb12u2
no fix listed
2
apache/kafka:4.3.177e3df905404
expat@2.7.5-r0
2.8.4-r0
2
apache/nifi-registry:1.26.07cdfd8deec92
expat@2.4.7-1ubuntu0.3
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
expat@2.6.1-2ubuntu0.4
no fix listed
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
expat@2.6.1-2build1
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
expat@2.8.3-1~deb13u1
no fix listed
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
expat@2.5.0-1
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
expat@2.7.1-2
no fix listed
2
cribl/cribl:4.19.2044f9a5fac9a
expat@2.6.1-2ubuntu0.4
no fix listed
2
epam/ai-dial-core:0.47.0:latest00fab0cf9c78
expat@2.8.3-r0
2.8.4-r0
2
excalidraw/excalidraw:latestf7ee194addd6
expat@2.7.0-r0
2.8.4-r0
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
expat@2.7.1-2
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
expat@2.7.1-2
no fix listed
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
expat@2.2.5-3ubuntu0.2
no fix listed
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
expat@2.2.9-1build1
no fix listed
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
expat@2.2.9-1build1
no fix listed
2
gisaia/agate:0.18.198213fa403ae
expat@2.8.3-r0
2.8.4-r0
2
gisaia/airs:0.18.15abfe00317bf
expat@2.8.3-r0
2.8.4-r0
2
gisaia/aproc-service:0.18.1ac6564921994
expat@2.8.3-r0
2.8.4-r0
2
gisaia/fam:0.18.1ae525930b4b6
expat@2.8.3-r0
2.8.4-r0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
expat@2.5.0-1
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
expat@2.8.2-1~deb13u1
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
expat@2.8.3-1~deb13u1
no fix listed
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
expat@2.8.3-1~deb13u1
no fix listed
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
expat@2.8.3-1~deb13u1
no fix listed
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
expat@2.5.0-1
no fix listed
2
homebridge/homebridge:latest77c685a40911
expat@2.6.1-2ubuntu0.4
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
expat@2.2.9-1build1
no fix listed
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
expat@2.2.9-1ubuntu0.4
no fix listed
2
infisical/infisical:latest:v0.165.602082bf13163
expat@2.8.3-1~deb13u1
no fix listed
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.