StackRadar

CVE-2026-6732

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
171
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 171 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r0+2 more2.13.9-r1, 2.13.9-r2160
libxml2deb2.14.5+dfsg-0.2, 2.15.2+dfsg-0.12.14.5+dfsg-0.2ubuntu0.2, 2.15.2+dfsg-0.1ubuntu0.12
OSV records
ALPINE-CVE-2026-6732UBUNTU-CVE-2026-6732
Also known as
USN-8460-1

Charts affected

171 by stars
ChartLatestAffected imagesRadar Score
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
libxml2@2.13.4-r3
2.13.9-r1

Open the chart page →

2,817
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,802
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libxml2@2.15.2+dfsg-0.1
2.15.2+dfsg-0.1ubuntu0.1

Open the chart page →

10,348
seed-audio-ai-pwa-toolkitseed-audio-ai-pwa-helm-chartsVerified publisher0.1.01 of 1See more

seed-audio-ai-pwa-toolkit seed-audio-ai-pwa-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
library/nginx:1.27-alpine65645c7bb6a0
libxml2@2.13.4-r5
2.13.9-r1

Open the chart page →

840
return-nginx-chartseture0.1.01 of 1See more

return-nginx-chart seture 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
seyiogunniran/my-nginx:1.03a0ed39e5830
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

1,291
link-uishortlink0.7.51 of 1See more

link-ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,321
uishortlink0.7.51 of 1See more

ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,321
ingress-nginxsoftonic4.15.11 of 2See more

ingress-nginx softonic 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,547
mybbsudermanjr0.1.01 of 3See more

mybb sudermanjr 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
mybb/mybb:1.8f2a54bce31c5
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,157
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,396
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,115
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,043
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,825
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
erenozcan17/react_frontend:v4.56e1b14973f9b
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

6,973
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,109
deep-learning-toolsuninettsigma29.1.21 of 3See more

deep-learning-tools uninettsigma2 9.1.2

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
library/nginx:1.29.3-alpineb3c656d55d7a
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

1,567
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

2,620
evolution-apivcnngrVerified publisher1.0.02 of 5See more

evolution-api vcnngr 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
libxml2@2.13.9-r0
2.13.9-r1
evoapicloud/evolution-manager:latestcbfeb314afb9
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
libxml2@2.13.8-r0
2.13.9-r1

Open the chart page →

4,768
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
libxml2@2.13.4-r5
2.13.9-r1

Open the chart page →

2,076
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-6732.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libxml2@2.13.9-r0
2.13.9-r1

Open the chart page →

400

Container images carrying it

162 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
libxml2@2.13.9-r0
2.13.9-r1
6
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
libxml2@2.13.9-r0
2.13.9-r1
5
alpine/k8s:1.32.12048f8d9c8cc7
libxml2@2.13.9-r0
2.13.9-r2
2
clamav/clamav:1.4.3_base629a3050df6a
libxml2@2.13.9-r0
2.13.9-r1
2
excalidraw/excalidraw:latestf7ee194addd6
libxml2@2.13.4-r5
2.13.9-r1
2
library/postgres:13-alpinefb9065b6e3e2
libxml2@2.13.9-r0
2.13.9-r1
2
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
libxml2@2.13.4-r6
2.13.9-r1
2
timescale/timescaledb:latest-pg156343bdc87ca1
libxml2@2.13.9-r0
2.13.9-r1
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
libxml2@2.13.8-r0
2.13.9-r1
2
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
libxml2@2.13.9-r0
2.13.9-r1
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
libxml2@2.13.8-r0
2.13.9-r1
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
libxml2@2.13.4-r5
2.13.9-r1
2
airbyte/db:2.2.03b6985a0ce75
libxml2@2.13.9-r0
2.13.9-r1
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
libxml2@2.13.8-r0
2.13.9-r1
1
alpine/k8s:1.31.106dbe6f391eda
libxml2@2.13.8-r0
2.13.9-r1
1
alpine/k8s:1.31.137a319b15cfc9
libxml2@2.13.8-r0
2.13.9-r1
1
alpine/k8s:1.32.47e1e7d5b7a96
libxml2@2.13.4-r5
2.13.9-r1
1
alpine/k8s:1.31.49c4976d47656
libxml2@2.13.4-r3
2.13.9-r1
1
alpine/k8s:1.35.5d870622d0040
libxml2@2.13.9-r1
2.13.9-r2
1
alpine/k8s:1.32.3eec354133193
libxml2@2.13.4-r5
2.13.9-r1
1
appwrite/appwrite:1.9.01aaa70127114
libxml2@2.13.9-r0
2.13.9-r1
1
appwrite/console:8.7.383dcdc8492ac6
libxml2@2.13.9-r0
2.13.9-r1
1
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
libxml2@2.13.9-r0
2.13.9-r1
1
beyzkaya/blog-frontend:v1.0.0bf412d75c510
libxml2@2.13.8-r0
2.13.9-r1
1
blackducksoftware/blackduck-alert-db:8.4.06310fac39d53
libxml2@2.13.9-r0
2.13.9-r1
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
libxml2@2.13.8-r0
2.13.9-r1
1
cars10/elasticvue:1.15.0efddf4fa0fd8
libxml2@2.13.9-r0
2.13.9-r1
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
libxml2@2.13.4-r3
2.13.9-r1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
libxml2@2.13.8-r0
2.13.9-r1
1
cloudposse/bastion:latest0d9507e8a760
libxml2@2.13.9-r0
2.13.9-r1
1
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
libxml2@2.13.9-r0
2.13.9-r1
1
copyparty/ac:1.19.200a0a8605062c
libxml2@2.13.9-r0
2.13.9-r1
1
dependencytrack/frontend:4.14.200560b57a6cf
libxml2@2.13.9-r0
2.13.9-r1
1
devkrishan001/frontend:latesta0ad60836e6b
libxml2@2.13.9-r0
2.13.9-r1
1
docuseal/docuseal:2.4.17493fd7f6728
libxml2@2.13.9-r0
2.13.9-r1
1
eclipseaerios/management-portal-frontend:1.2.23a8e4cf60629
libxml2@2.13.9-r0
2.13.9-r1
1
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
libxml2@2.13.9-r0
2.13.9-r1
1
erenozcan17/react_frontend:v4.56e1b14973f9b
libxml2@2.13.8-r0
2.13.9-r1
1
esteban1930/frontend-1:1.8.0f9078279632c
libxml2@2.13.8-r0
2.13.9-r1
1
evoapicloud/evolution-api:latest966625532d90
libxml2@2.13.9-r0
2.13.9-r1
1
evoapicloud/evolution-manager:latestcbfeb314afb9
libxml2@2.13.9-r0
2.13.9-r1
1
extrim/perlite:1.5.99cb7eb5598b6
libxml2@2.13.4-r5
2.13.9-r1
1
folioci/mod-copycat:latest1513fad2b799
libxml2@2.13.9-r0
2.13.9-r1
1
gdrocha/togglr-frontend:1.0.0ffbc1571c234
libxml2@2.13.9-r0
2.13.9-r1
1
gitea/gitea:1.26.27d13848af126
libxml2@2.13.9-r0
2.13.9-r1
1
grafana/oncall:v1.16.5499851658393
libxml2@2.13.4-r6
2.13.9-r1
1
gridgain/gridgain9:9.1.1895018390077b
libxml2@2.13.9-r0
2.13.9-r1
1
heartexlabs/label-studio:latestaa461572e8f9
libxml2@2.13.9-r0
2.13.9-r1
1
helmforge/openreel-video:v0.5.07ba0d47b943f
libxml2@2.13.9-r0
2.13.9-r1
1
intelowlproject/intelowl_nginx:v6.6.12f01e79b8064
libxml2@2.13.9-r0
2.13.9-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.