CVE-2026-6732
HighAdvisory
Published 23 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.006
- 48th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 171
- of 17,781 indexed, latest versions
- Container images
- 162
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 171 of 17,781 indexed charts deploy, on 162 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| libxml2apk | 2.13.4-r3, 2.13.4-r5, 2.13.4-r6, 2.13.8-r0+2 more | 2.13.9-r1, 2.13.9-r2 | 160 |
| libxml2deb | 2.14.5+dfsg-0.2, 2.15.2+dfsg-0.1 | 2.14.5+dfsg-0.2ubuntu0.2, 2.15.2+dfsg-0.1ubuntu0.1 | 2 |
- OSV records
- ALPINE-CVE-2026-6732UBUNTU-CVE-2026-6732
- Also known as
- USN-8460-1
Charts affected
171 by stars
Container images carrying it
162 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| nginxinc/ | 0c79d56aee56 | libxml2 | 2.13.9-r1 | 6 |
| registry.k8s.io/ | 594ceea76b01 | libxml2 | 2.13.9-r1 | 5 |
| alpine/ | 048f8d9c8cc7 | libxml2 | 2.13.9-r2 | 2 |
| clamav/ | 629a3050df6a | libxml2 | 2.13.9-r1 | 2 |
| excalidraw/ | f7ee194addd6 | libxml2 | 2.13.9-r1 | 2 |
| library/ | fb9065b6e3e2 | libxml2 | 2.13.9-r1 | 2 |
| nginxinc/ | 65e3e85dbaed | libxml2 | 2.13.9-r1 | 2 |
| timescale/ | 6343bdc87ca1 | libxml2 | 2.13.9-r1 | 2 |
| ghcr.io/ | c137478627cc | libxml2 | 2.13.9-r1 | 2 |
| registry.gitlab.com/ | 9bdb1062d960 | libxml2 | 2.13.9-r1 | 2 |
| registry.k8s.io/ | 695d79381ee6 | libxml2 | 2.13.9-r1 | 2 |
| registry.k8s.io/ | d2fbc4ec70d8 | libxml2 | 2.13.9-r1 | 2 |
| airbyte/ | 3b6985a0ce75 | libxml2 | 2.13.9-r1 | 1 |
| aktosecurity/ | 853e37321e6e | libxml2 | 2.13.9-r1 | 1 |
| alpine/ | 6dbe6f391eda | libxml2 | 2.13.9-r1 | 1 |
| alpine/ | 7a319b15cfc9 | libxml2 | 2.13.9-r1 | 1 |
| alpine/ | 7e1e7d5b7a96 | libxml2 | 2.13.9-r1 | 1 |
| alpine/ | 9c4976d47656 | libxml2 | 2.13.9-r1 | 1 |
| alpine/ | d870622d0040 | libxml2 | 2.13.9-r2 | 1 |
| alpine/ | eec354133193 | libxml2 | 2.13.9-r1 | 1 |
| appwrite/ | 1aaa70127114 | libxml2 | 2.13.9-r1 | 1 |
| appwrite/ | 3dcdc8492ac6 | libxml2 | 2.13.9-r1 | 1 |
| awesometechnologies/ | a1c1f4662875 | libxml2 | 2.13.9-r1 | 1 |
| beyzkaya/ | bf412d75c510 | libxml2 | 2.13.9-r1 | 1 |
| blackducksoftware/ | 6310fac39d53 | libxml2 | 2.13.9-r1 | 1 |
| camunda/ | bcc5bb0542df | libxml2 | 2.13.9-r1 | 1 |
| cars10/ | efddf4fa0fd8 | libxml2 | 2.13.9-r1 | 1 |
| chandanteekinavar/ | 6de5bd44a325 | libxml2 | 2.13.9-r1 | 1 |
| chibisafe/ | 3da4fcbc1a18 | libxml2 | 2.13.9-r1 | 1 |
| cloudposse/ | 0d9507e8a760 | libxml2 | 2.13.9-r1 | 1 |
| clowder/ | fe97882672ca | libxml2 | 2.13.9-r1 | 1 |
| copyparty/ | 0a0a8605062c | libxml2 | 2.13.9-r1 | 1 |
| dependencytrack/ | 00560b57a6cf | libxml2 | 2.13.9-r1 | 1 |
| devkrishan001/ | a0ad60836e6b | libxml2 | 2.13.9-r1 | 1 |
| docuseal/ | 7493fd7f6728 | libxml2 | 2.13.9-r1 | 1 |
| eclipseaerios/ | 3a8e4cf60629 | libxml2 | 2.13.9-r1 | 1 |
| eftechcombr/ | f3d0ed01709e | libxml2 | 2.13.9-r1 | 1 |
| erenozcan17/ | 6e1b14973f9b | libxml2 | 2.13.9-r1 | 1 |
| esteban1930/ | f9078279632c | libxml2 | 2.13.9-r1 | 1 |
| evoapicloud/ | 966625532d90 | libxml2 | 2.13.9-r1 | 1 |
| evoapicloud/ | cbfeb314afb9 | libxml2 | 2.13.9-r1 | 1 |
| extrim/ | 9cb7eb5598b6 | libxml2 | 2.13.9-r1 | 1 |
| folioci/ | 1513fad2b799 | libxml2 | 2.13.9-r1 | 1 |
| gdrocha/ | ffbc1571c234 | libxml2 | 2.13.9-r1 | 1 |
| gitea/ | 7d13848af126 | libxml2 | 2.13.9-r1 | 1 |
| grafana/ | 499851658393 | libxml2 | 2.13.9-r1 | 1 |
| gridgain/ | 95018390077b | libxml2 | 2.13.9-r1 | 1 |
| heartexlabs/ | aa461572e8f9 | libxml2 | 2.13.9-r1 | 1 |
| helmforge/ | 7ba0d47b943f | libxml2 | 2.13.9-r1 | 1 |
| intelowlproject/ | 2f01e79b8064 | libxml2 | 2.13.9-r1 | 1 |