StackRadar

CVE-2026-6732

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
171
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 171 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r0+2 more2.13.9-r1, 2.13.9-r2160
libxml2deb2.14.5+dfsg-0.2, 2.15.2+dfsg-0.12.14.5+dfsg-0.2ubuntu0.2, 2.15.2+dfsg-0.1ubuntu0.12
OSV records
ALPINE-CVE-2026-6732UBUNTU-CVE-2026-6732
Also known as
USN-8460-1

Charts affected

171 by stars
ChartLatestAffected imagesRadar Score
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
libxml2@2.13.4-r3
2.13.9-r1

Open the chart page →

2,817
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,802
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libxml2@2.15.2+dfsg-0.1
2.15.2+dfsg-0.1ubuntu0.1

Open the chart page →

10,348
seed-audio-ai-pwa-toolkitseed-audio-ai-pwa-helm-chartsVerified publisher0.1.01 of 1See more

seed-audio-ai-pwa-toolkit seed-audio-ai-pwa-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
library/nginx:1.27-alpine65645c7bb6a0
libxml2@2.13.4-r5
2.13.9-r1

Open the chart page →

840
return-nginx-chartseture0.1.01 of 1See more

return-nginx-chart seture 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
seyiogunniran/my-nginx:1.03a0ed39e5830
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

1,291
link-uishortlink0.7.51 of 1See more

link-ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,321
uishortlink0.7.51 of 1See more

ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,321
ingress-nginxsoftonic4.15.11 of 2See more

ingress-nginx softonic 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,547
mybbsudermanjr0.1.01 of 3See more

mybb sudermanjr 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
mybb/mybb:1.8f2a54bce31c5
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,157
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,396
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,115
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,043
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,825
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
erenozcan17/react_frontend:v4.56e1b14973f9b
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

6,973
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,109
deep-learning-toolsuninettsigma29.1.21 of 3See more

deep-learning-tools uninettsigma2 9.1.2

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
library/nginx:1.29.3-alpineb3c656d55d7a
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,567
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,620
evolution-apivcnngrVerified publisher1.0.02 of 5See more

evolution-api vcnngr 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
libxml2@2.13.9-r0
2.13.9-r1
evoapicloud/evolution-manager:latestcbfeb314afb9
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

4,768
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
libxml2@2.13.4-r5
2.13.9-r1

Open the chart page →

2,076
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

400

Container images carrying it

162 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
libxml2@2.13.4-r5
2.13.9-r1
1
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libxml2@2.13.9-r0
2.13.9-r1
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
libxml2@2.13.8-r0
2.13.9-r1
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
libxml2@2.13.9-r0
2.13.9-r1
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
libxml2@2.13.9-r0
2.13.9-r1
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
libxml2@2.13.9-r0
2.13.9-r1
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
libxml2@2.13.8-r0
2.13.9-r1
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
libxml2@2.13.8-r0
2.13.9-r1
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
libxml2@2.13.4-r3
2.13.9-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.