StackRadar

CVE-2026-71497

Medium

Advisory

Published 6 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
78
of 17,781 indexed, latest versions
Container images
81
deployed by those charts
Fix available
1 of 1
affected package

jsoup: Cleaner may expose markup with custom raw-text elements

Carried by container images the latest versions of 78 of 17,781 indexed charts deploy, on 81 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.14.3, 1.15.3, 1.15.4, 1.16.1+11 more1.23.181
OSV records
GHSA-pmhh-3w7g-xqp8

Charts affected

78 by stars
ChartLatestAffected imagesRadar Score
metabasepmint932.27.61 of 1See more

metabase pmint93 2.27.6

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.1

Open the chart page →

1,639
jiraatlassian-data-centerVerified publisher2.0.151 of 2See more

jira atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
atlassian/jira-software:11.3.11e5548cd4eea8
jsoup@1.19.1
1.23.1

Open the chart page →

1,490
graylogkong-zVerified publisher3.0.321 of 5See more

graylog kong-z 3.0.32

1 of the 5 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.19.68690b204fe91
jsoup@1.15.3
1.23.1

Open the chart page →

2,699
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
penpotapp/backend:2.17.2770b55f6e51b
jsoup@1.22.2
1.23.1

Open the chart page →

4,314
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.3b149b30da686
jsoup@1.15.3
1.23.1

Open the chart page →

11,384
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
jsoup@1.22.2
1.23.1

Open the chart page →

1,444
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
jsoup@1.17.2
1.23.1
graviteeio/apim-management-api:4.12.19-debian27374522cd04
jsoup@1.22.1
1.23.1

Open the chart page →

4,806
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
jsoup@1.22.1
1.23.1

Open the chart page →

1,074
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
jsoup@1.21.2
1.23.1

Open the chart page →

2,283
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
jsoup@1.22.2
1.23.1

Open the chart page →

1,415
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
jsoup@1.22.1
1.23.1

Open the chart page →

1,500
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
jsoup@1.15.3
1.23.1

Open the chart page →

8,636
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.11.1a7a2076b167e
jsoup@1.15.3
1.23.1

Open the chart page →

6,168
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.10.0c8f3ebd2a934
jsoup@1.15.3
1.23.1

Open the chart page →

10,530
opensearchcaptnbpVerified publisher3.1.11 of 2See more

opensearch captnbp 3.1.1

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.19.269588c664014
jsoup@1.15.3
1.23.1

Open the chart page →

998
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
jsoup@1.15.3
1.23.1

Open the chart page →

7,450
aegraviteeioVerified publisher3.0.21 of 1See more

ae graviteeio 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
graviteeio/ae-engine:3.0.24140932887e0
jsoup@1.20.1
1.23.1

Open the chart page →

1,380
apimgraviteeioVerified publisher4.12.192 of 4See more

apim graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
jsoup@1.17.2
1.23.1
graviteeio/apim-management-api:4.12.19-debian27374522cd04
jsoup@1.22.1
1.23.1

Open the chart page →

4,806
tikaapache-tika3.2.21 of 1See more

tika apache-tika 3.2.2

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
apache/tika:3.2.2.0-fullffab324253ed
jsoup@1.21.1
1.23.1

Open the chart page →

437
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
jsoup@1.15.3
1.23.1

Open the chart page →

52,635
egagenteginnovationsVerified publisher0.10.01 of 1See more

egagent eginnovations 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
eginnovations/agent:7.5.4e4dfe242fe9f
jsoup@1.17.2
1.23.1

Open the chart page →

1,340
scoolderudikaVerified publisher0.3.01 of 1See more

scoold erudika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
erudikaltd/scoold:1.66.0949c56b57e8f
jsoup@1.22.1
1.23.1

Open the chart page →

1,605
amgraviteeioVerified publisher4.12.62 of 3See more

am graviteeio 4.12.6

2 of the 3 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
graviteeio/am-gateway:4.12.607b7f6dc267a
jsoup@1.16.1
1.23.1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
jsoup@1.22.1
1.23.1

Open the chart page →

2,088
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
jsoup@1.15.3
1.23.1

Open the chart page →

2,067
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
jsoup@1.15.3
1.23.1

Open the chart page →

13,479
connector-rollout-workerairbyteVerified publisher1.9.21 of 1See more

connector-rollout-worker airbyte 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
jsoup@1.15.3
1.23.1

Open the chart page →

829
airbyteairbyte-v2Verified publisher2.2.06 of 10See more

airbyte airbyte-v2 2.2.0

6 of the 10 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
airbyte/bootloader:2.2.0f71cf4e185d5
jsoup@1.15.3
1.23.1
airbyte/cron:2.2.0d97b67a1346d
jsoup@1.15.3
1.23.1
airbyte/server:2.2.070e125498a1c
jsoup@1.15.3
1.23.1
airbyte/worker:2.2.08060b88b29c8
jsoup@1.15.3
1.23.1
airbyte/workload-api-server:2.2.042093cff86e9
jsoup@1.15.3
1.23.1
airbyte/workload-launcher:2.2.0119be7bfb719
jsoup@1.15.3
1.23.1

Open the chart page →

12,473
airbyte-data-planeairbyte-v2Verified publisher2.2.01 of 1See more

airbyte-data-plane airbyte-v2 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
airbyte/workload-launcher:2.2.0119be7bfb719
jsoup@1.15.3
1.23.1

Open the chart page →

790
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
jsoup@1.18.1
1.23.1

Open the chart page →

1,748
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
jsoup@1.22.2
1.23.1

Open the chart page →

3,647
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
jsoup@1.20.1
1.23.1

Open the chart page →

3,963
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
jsoup@1.14.3
1.23.1
ghcr.io/appscode/inbox-server:latest536358d7b17e
jsoup@1.20.1
1.23.1

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
jsoup@1.14.3
1.23.1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
jsoup@1.16.1
1.23.1

Open the chart page →

16,975
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
jsoup@1.14.3
1.23.1

Open the chart page →

14,728
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
jsoup@1.15.3
1.23.1

Open the chart page →

9,722
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
jsoup@1.15.4
1.23.1

Open the chart page →

4,292
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
jsoup@1.20.1
1.23.1

Open the chart page →

1,816
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
jsoup@1.15.3
1.23.1

Open the chart page →

1,073
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jsoup@1.17.2
1.23.1

Open the chart page →

1,215
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
jsoup@1.21.2
1.23.1

Open the chart page →

13,936
metabasedasmeta0.1.01 of 1See more

metabase dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.1.124f150effd484
jsoup@1.21.2
1.23.1

Open the chart page →

804
gerrit-operatorepmdedpVerified publisher2.25.01 of 2See more

gerrit-operator epmdedp 2.25.0

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
epamedp/edp-gerrit:3.14.249e8fe9c4855
jsoup@1.14.3
1.23.1

Open the chart page →

1,159
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
jsoup@1.15.3
1.23.1

Open the chart page →

34,754
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.1

Open the chart page →

49,025
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
jsoup@1.21.2
1.23.1

Open the chart page →

1,691
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
jsoup@1.16.1
1.23.1

Open the chart page →

3,199
booklorehelmforgeVerified publisher2.0.11 of 3See more

booklore helmforge 2.0.1

1 of the 3 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
ghcr.io/booklore-app/booklore:v2.3.1d3d3af34bc2c
jsoup@1.22.2
1.23.1

Open the chart page →

2,280
elasticsearchhelmforgeVerified publisher1.1.81 of 2See more

elasticsearch helmforge 1.1.8

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
library/elasticsearch:9.5.38d09295845fe
jsoup@1.21.2
1.23.1

Open the chart page →

280
kibanahelmforgeVerified publisher1.1.71 of 3See more

kibana helmforge 1.1.7

1 of the 3 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
library/elasticsearch:9.5.19656a9ca03f8
jsoup@1.21.2
1.23.1

Open the chart page →

341
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.3.2798cf28e226a
jsoup@1.15.3
1.23.1

Open the chart page →

25,017

Container images carrying it

81 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
airbyte/workload-launcher:2.2.0119be7bfb719
jsoup@1.15.3
1.23.1
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
jsoup@1.17.2
1.23.1
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
jsoup@1.22.1
1.23.1
2
library/elasticsearch:8.19.1289729a95066a
jsoup@1.21.2
1.23.1
2
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.1
2
opensearchproject/opensearch:2.1.04254021a8c71
jsoup@1.14.3
1.23.1
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.1
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
jsoup@1.20.1
1.23.1
2
1dev/server:11.9.0cd5b12fe5471
jsoup@1.17.2
1.23.1
1
airbyte/bootloader:2.2.0f71cf4e185d5
jsoup@1.15.3
1.23.1
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
jsoup@1.15.3
1.23.1
1
airbyte/cron:2.2.0d97b67a1346d
jsoup@1.15.3
1.23.1
1
airbyte/server:2.2.070e125498a1c
jsoup@1.15.3
1.23.1
1
airbyte/worker:2.2.08060b88b29c8
jsoup@1.15.3
1.23.1
1
airbyte/workload-api-server:2.2.042093cff86e9
jsoup@1.15.3
1.23.1
1
apache/tika:3.3.1.090b7fa1dc018
jsoup@1.22.2
1.23.1
1
apache/tika:3.2.2.0-fullffab324253ed
jsoup@1.21.1
1.23.1
1
assistiot/automated_configuration:latest23f195a7a26a
jsoup@1.14.3
1.23.1
1
athou/commafeed:6.2.0-postgresql5e388351df1a
jsoup@1.22.1
1.23.1
1
atlassian/bitbucket:10.2.705933f2b1cfd
jsoup@1.22.2
1.23.1
1
atlassian/crowd:7.2.3c81cc7d6bc9e
jsoup@1.22.2
1.23.1
1
atlassian/crowd:5.2.2ebf761c7d437
jsoup@1.16.2
1.23.1
1
atlassian/jira-software:9.7.264a75aa4ec4e
jsoup@1.15.3
1.23.1
1
atlassian/jira-software:11.3.11e5548cd4eea8
jsoup@1.19.1
1.23.1
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
jsoup@1.15.3
1.23.1
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
jsoup@1.15.4
1.23.1
1
bluerange/bluerange:26.1.307c8f73b55df
jsoup@1.20.1
1.23.1
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jsoup@1.17.2
1.23.1
1
codetogether/codetogether:latest4348c8a38752
jsoup@1.15.3
1.23.1
1
conductoross/conductor:3.31.09fba127693e6
jsoup@1.15.4
1.23.1
1
easypi/openrefine:3.7.0d2950a36a576
jsoup@1.15.3
1.23.1
1
eginnovations/agent:7.5.4e4dfe242fe9f
jsoup@1.17.2
1.23.1
1
epamedp/edp-gerrit:3.14.249e8fe9c4855
jsoup@1.14.3
1.23.1
1
erudikaltd/scoold:1.66.0949c56b57e8f
jsoup@1.22.1
1.23.1
1
frankescobar/allure-docker-service:latestdc171ec796d5
jsoup@1.22.2
1.23.1
1
gotson/komga:1.22.0ba892ab3e082
jsoup@1.18.3
1.23.1
1
graviteeio/ae-engine:3.0.24140932887e0
jsoup@1.20.1
1.23.1
1
graviteeio/am-gateway:4.12.607b7f6dc267a
jsoup@1.16.1
1.23.1
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
jsoup@1.22.1
1.23.1
1
graylog/graylog:7.1.9598bd41fefd5
jsoup@1.22.1
1.23.1
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
jsoup@1.22.1
1.23.1
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
jsoup@1.21.2
1.23.1
1
gridgain/gridgain9:9.1.1895018390077b
jsoup@1.16.1
1.23.1
1
hivemq/hivemq4:dns-4.5.144d194450d48e
jsoup@1.14.3
1.23.1
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
jsoup@1.15.3
1.23.1
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
jsoup@1.15.4
1.23.1
1
library/elasticsearch:9.5.38d09295845fe
jsoup@1.21.2
1.23.1
1
library/elasticsearch:9.5.19656a9ca03f8
jsoup@1.21.2
1.23.1
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
jsoup@1.18.1
1.23.1
1
liukunup/jmeter:5.59c079617a81b
jsoup@1.15.3
1.23.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.