StackRadar

CVE-2026-6732

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
171
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 171 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r0+2 more2.13.9-r1, 2.13.9-r2160
libxml2deb2.14.5+dfsg-0.2, 2.15.2+dfsg-0.12.14.5+dfsg-0.2ubuntu0.2, 2.15.2+dfsg-0.1ubuntu0.12
OSV records
ALPINE-CVE-2026-6732UBUNTU-CVE-2026-6732
Also known as
USN-8460-1

Charts affected

171 by stars
ChartLatestAffected imagesRadar Score
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
libxml2@2.13.4-r3
2.13.9-r1

Open the chart page →

2,817
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,802
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libxml2@2.15.2+dfsg-0.1
2.15.2+dfsg-0.1ubuntu0.1

Open the chart page →

10,348
seed-audio-ai-pwa-toolkitseed-audio-ai-pwa-helm-chartsVerified publisher0.1.01 of 1See more

seed-audio-ai-pwa-toolkit seed-audio-ai-pwa-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
library/nginx:1.27-alpine65645c7bb6a0
libxml2@2.13.4-r5
2.13.9-r1

Open the chart page →

840
return-nginx-chartseture0.1.01 of 1See more

return-nginx-chart seture 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
seyiogunniran/my-nginx:1.03a0ed39e5830
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

1,291
link-uishortlink0.7.51 of 1See more

link-ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,321
uishortlink0.7.51 of 1See more

ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,321
ingress-nginxsoftonic4.15.11 of 2See more

ingress-nginx softonic 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,547
mybbsudermanjr0.1.01 of 3See more

mybb sudermanjr 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
mybb/mybb:1.8f2a54bce31c5
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,157
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,396
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,115
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,043
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,825
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
erenozcan17/react_frontend:v4.56e1b14973f9b
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

6,973
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,109
deep-learning-toolsuninettsigma29.1.21 of 3See more

deep-learning-tools uninettsigma2 9.1.2

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
library/nginx:1.29.3-alpineb3c656d55d7a
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,567
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,620
evolution-apivcnngrVerified publisher1.0.02 of 5See more

evolution-api vcnngr 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
libxml2@2.13.9-r0
2.13.9-r1
evoapicloud/evolution-manager:latestcbfeb314afb9
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

4,768
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
libxml2@2.13.4-r5
2.13.9-r1

Open the chart page →

2,076
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

400

Container images carrying it

162 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
libxml2@2.13.4-r6
2.13.9-r1
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
libxml2@2.13.8-r0
2.13.9-r1
1
jlesage/firefox:v25.03.1055c28defe31
libxml2@2.13.4-r5
2.13.9-r1
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
libxml2@2.13.9-r0
2.13.9-r1
1
library/nginx:1.31.0-alpine2f07d83bf561
libxml2@2.13.9-r0
2.13.9-r1
1
library/nginx:1.29.8-alpine5616878291a2
libxml2@2.13.9-r0
2.13.9-r1
1
library/nginx:1.27-alpine65645c7bb6a0
libxml2@2.13.4-r5
2.13.9-r1
1
library/nginx:1.28-alpinea8b39bd9cf0f
libxml2@2.13.9-r0
2.13.9-r1
1
library/nginx:1.29.3-alpineb3c656d55d7a
libxml2@2.13.9-r0
2.13.9-r1
1
library/php:8.5.2-fpm-alpine3.22a2482c398d60
libxml2@2.13.9-r0
2.13.9-r1
1
library/postgres:18.1-alpine3.2144d837eb4c2e
libxml2@2.13.9-r0
2.13.9-r1
1
library/postgres:18.3-alpine54451ecb8ab3
libxml2@2.13.9-r0
2.13.9-r1
1
library/postgres:17.5-alpine6567bca8d7bc
libxml2@2.13.8-r0
2.13.9-r1
1
library/postgres:17.4-alpine7062a2109c4b
libxml2@2.13.4-r3
2.13.9-r1
1
library/postgres:12-alpine7c8f48705831
libxml2@2.13.4-r3
2.13.9-r1
1
library/postgres:17.2-alpine7e5df973a748
libxml2@2.13.4-r3
2.13.9-r1
1
library/postgres:18.1-alpineaa6eb304ddb6
libxml2@2.13.9-r0
2.13.9-r1
1
library/postgres:17.6-alpineef257d85f76e
libxml2@2.13.9-r0
2.13.9-r1
1
linkstackorg/linkstack:latest1c8b05399ee4
libxml2@2.13.9-r0
2.13.9-r1
1
linuxserver/bookstack:26.05.202605282ebf97852661
libxml2@2.13.9-r0
2.13.9-r1
1
loeken/jellyfin:10.11.87efbc24e47b0
libxml2@2.13.9-r0
2.13.9-r1
1
loeken/radarr:5.27.0-nightlya24409d3846d
libxml2@2.13.4-r6
2.13.9-r1
1
m11s/decap-cms:0.2.11-s30cd6810c9885
libxml2@2.13.9-r0
2.13.9-r1
1
mathnao/certs:2.1.3b900e6b64684
libxml2@2.13.4-r6
2.13.9-r1
1
mavrick1/kubestellar-f:latest56bd8eaa53a4
libxml2@2.13.4-r5
2.13.9-r1
1
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
libxml2@2.13.9-r0
2.13.9-r1
1
mybb/mybb:1.8f2a54bce31c5
libxml2@2.13.9-r0
2.13.9-r1
1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
libxml2@2.13.9-r0
2.13.9-r1
1
nginxdemos/hello:plain-text751bf8933179
libxml2@2.13.8-r0
2.13.9-r1
1
nginxdemos/hello:0.4b28d1e16c676
libxml2@2.13.8-r0
2.13.9-r1
1
nginxinc/nginx-unprivileged:1.27.4-alpine62a904036bfc
libxml2@2.13.4-r5
2.13.9-r1
1
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
libxml2@2.13.8-r0
2.13.9-r1
1
nginxinc/nginx-unprivileged:mainline-alpinee93571f3d083
libxml2@2.13.9-r0
2.13.9-r1
1
novosga/novosga:latest34b9acbe6e51
libxml2@2.13.9-r0
2.13.9-r1
1
octoboxio/octobox:latestd909041c46eb
libxml2@2.13.9-r0
2.13.9-r1
1
opencsghq/csgship-portal:v1.2.1865814dc87a1
libxml2@2.13.4-r5
2.13.9-r1
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
libxml2@2.13.4-r5
2.13.9-r1
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
libxml2@2.13.4-r6
2.13.9-r1
1
owncloud/ocis:8.0.1b38fd8fdd58f
libxml2@2.13.9-r0
2.13.9-r1
1
photoprism/photoprism:260601650c6ad5a651
libxml2@2.15.2+dfsg-0.1
2.15.2+dfsg-0.1ubuntu0.1
1
photoprism/photoprism:251130db16ee6b1ba3
libxml2@2.14.5+dfsg-0.2
2.14.5+dfsg-0.2ubuntu0.2
1
pmoscode/excalidraw:v0.18.08ee61554699c
libxml2@2.13.9-r0
2.13.9-r1
1
reaper99/recipya:v1.2.27f7ec3aeb88c
libxml2@2.13.4-r3
2.13.9-r1
1
redocly/redoc:latest2e26bb660574
libxml2@2.13.9-r0
2.13.9-r1
1
rocm/k8s-device-plugin:1.31.0.926212c665aab
libxml2@2.13.4-r3
2.13.9-r1
1
rommapp/romm:5.2.03512f2ca4557
libxml2@2.13.9-r0
2.13.9-r1
1
rommapp/romm:4.4.1b909e95d1aab
libxml2@2.13.9-r0
2.13.9-r1
1
saidsef/scapy-containerised:v2025.02f17f7c435891
libxml2@2.13.4-r3
2.13.9-r1
1
seyiogunniran/my-nginx:1.03a0ed39e5830
libxml2@2.13.8-r0
2.13.9-r1
1
stashapp/stash:v0.31.1df744af5a0c9
libxml2@2.13.9-r0
2.13.9-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.