StackRadar

CVE-2026-6732

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
171
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 171 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r0+2 more2.13.9-r1, 2.13.9-r2160
libxml2deb2.14.5+dfsg-0.2, 2.15.2+dfsg-0.12.14.5+dfsg-0.2ubuntu0.2, 2.15.2+dfsg-0.1ubuntu0.12
OSV records
ALPINE-CVE-2026-6732UBUNTU-CVE-2026-6732
Also known as
USN-8460-1

Charts affected

171 by stars
ChartLatestAffected imagesRadar Score
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
libxml2@2.13.4-r3
2.13.9-r1

Open the chart page →

2,817
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,802
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libxml2@2.15.2+dfsg-0.1
2.15.2+dfsg-0.1ubuntu0.1

Open the chart page →

10,348
seed-audio-ai-pwa-toolkitseed-audio-ai-pwa-helm-chartsVerified publisher0.1.01 of 1See more

seed-audio-ai-pwa-toolkit seed-audio-ai-pwa-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
library/nginx:1.27-alpine65645c7bb6a0
libxml2@2.13.4-r5
2.13.9-r1

Open the chart page →

840
return-nginx-chartseture0.1.01 of 1See more

return-nginx-chart seture 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
seyiogunniran/my-nginx:1.03a0ed39e5830
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

1,291
link-uishortlink0.7.51 of 1See more

link-ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,321
uishortlink0.7.51 of 1See more

ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,321
ingress-nginxsoftonic4.15.11 of 2See more

ingress-nginx softonic 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,547
mybbsudermanjr0.1.01 of 3See more

mybb sudermanjr 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
mybb/mybb:1.8f2a54bce31c5
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,157
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,396
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,115
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,043
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,825
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
erenozcan17/react_frontend:v4.56e1b14973f9b
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

6,973
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,109
deep-learning-toolsuninettsigma29.1.21 of 3See more

deep-learning-tools uninettsigma2 9.1.2

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
library/nginx:1.29.3-alpineb3c656d55d7a
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,567
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,620
evolution-apivcnngrVerified publisher1.0.02 of 5See more

evolution-api vcnngr 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
libxml2@2.13.9-r0
2.13.9-r1
evoapicloud/evolution-manager:latestcbfeb314afb9
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

4,768
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
libxml2@2.13.4-r5
2.13.9-r1

Open the chart page →

2,076
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

400

Container images carrying it

162 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
svcosti/cidrapp:latest8428d87bc5d0
libxml2@2.13.4-r5
2.13.9-r1
1
tombursch/kitchenowl-web:v0.7.8517f808eee66
libxml2@2.13.9-r0
2.13.9-r1
1
vabene1111/recipes:2.3.50f8d061895e9
libxml2@2.13.9-r0
2.13.9-r1
1
vcnngr/pnfrontend:latest4e4979ab8c41
libxml2@2.13.8-r0
2.13.9-r1
1
ymuski/geo-checker:5.0.05ba7fd8c7bdc
libxml2@2.13.9-r0
2.13.9-r1
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
libxml2@2.13.9-r0
2.13.9-r1
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
libxml2@2.13.9-r0
2.13.9-r1
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
libxml2@2.13.9-r0
2.13.9-r1
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
libxml2@2.13.9-r0
2.13.9-r1
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
libxml2@2.13.8-r0
2.13.9-r1
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
libxml2@2.13.4-r5
2.13.9-r1
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
libxml2@2.13.4-r5
2.13.9-r1
1
ghcr.io/blessingnator/keycloak-mcn-frontend:2.0.1ddd462dbde39
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/cloudtty/cloudshell:v0.8.900984ba0f0eb
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/colanode/web:latestbcad696f03ee
libxml2@2.13.4-r5
2.13.9-r1
1
ghcr.io/comet-ml/opik/opik-frontend:2.2.59bc2f49e9bb3e
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
libxml2@2.13.8-r0
2.13.9-r1
1
ghcr.io/dakera-ai/dakera-dashboard:0.3.292e059589f7f7
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
libxml2@2.13.4-r3
2.13.9-r1
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
libxml2@2.13.4-r3
2.13.9-r1
1
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
libxml2@2.13.4-r5
2.13.9-r1
1
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/ethpandaops/dispatchoor-web:latest18e30413dac2
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/gchq/cyberchef:11.0.045082a0ac41d
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
libxml2@2.13.4-r3
2.13.9-r1
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
libxml2@2.13.8-r0
2.13.9-r1
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/home-operations/lidarr:3.1.29df1e14c8e09
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/huscker/townsquare-frontend:2.15.2dc6384d10cc8
libxml2@2.13.4-r6
2.13.9-r1
1
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
libxml2@2.13.4-r6
2.13.9-r1
1
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
libxml2@2.13.8-r0
2.13.9-r1
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
libxml2@2.13.8-r0
2.13.9-r1
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
libxml2@2.13.4-r3
2.13.9-r1
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
libxml2@2.13.4-r5
2.13.9-r1
1
ghcr.io/linuxserver/radarr:6.0.4.10291-ls2896c0948b42c14
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/linuxserver/radarr:6.0.4c8a55bd83672
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/linuxserver/sonarr:4.0.16.2944-ls3008b9f2138ec50
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/marcuwynu23/vite-app-sample:latest21247f2b97c4
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/mydecisive/octant-ui:0.0.1-testing61e4066b22fb
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
libxml2@2.13.9-r0
2.13.9-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.