StackRadar

CVE-2026-71497

Medium

Advisory

Published 6 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
78
of 17,781 indexed, latest versions
Container images
81
deployed by those charts
Fix available
1 of 1
affected package

jsoup: Cleaner may expose markup with custom raw-text elements

Carried by container images the latest versions of 78 of 17,781 indexed charts deploy, on 81 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.14.3, 1.15.3, 1.15.4, 1.16.1+11 more1.23.181
OSV records
GHSA-pmhh-3w7g-xqp8

Charts affected

78 by stars
ChartLatestAffected imagesRadar Score
paperlesshpVerified publisher0.1.11 of 5See more

paperless hp 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
jsoup@1.22.2
1.23.1

Open the chart page →

26,612
jenainseefrlab3.1.01 of 1See more

jena inseefrlab 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
stain/jena-fuseki:latestb1d0c96f19ad
jsoup@1.17.2
1.23.1

Open the chart page →

1,262
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
jsoup@1.15.3
1.23.1

Open the chart page →

1,754
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
jsoup@1.14.3
1.23.1

Open the chart page →

2,653
daveit-at-mOfficialVerified publisher0.2.152 of 11See more

dave it-at-m 0.2.15

2 of the 11 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
jsoup@1.20.1
1.23.1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
jsoup@1.21.2
1.23.1

Open the chart page →

15,089
proxerajfwenischVerified publisher0.12.201 of 1See more

proxera jfwenisch 0.12.20

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jsoup@1.22.2
1.23.1

Open the chart page →

185
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
jsoup@1.17.2
1.23.1

Open the chart page →

16,877
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
jsoup@1.18.3
1.23.1

Open the chart page →

3,131
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
jsoup@1.15.4
1.23.1

Open the chart page →

3,290
tinymediamanagermedia-servarrVerified publisher1.6.21 of 2See more

tinymediamanager media-servarr 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
jsoup@1.22.1
1.23.1

Open the chart page →

7,944
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
jsoup@1.18.2
1.23.1

Open the chart page →

2,589
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
jsoup@1.16.2
1.23.1

Open the chart page →

5,663
commafeedmt1905028.2.01 of 3See more

commafeed mt190502 8.2.0

1 of the 3 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
jsoup@1.22.1
1.23.1

Open the chart page →

3,687
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
jsoup@1.17.2
1.23.1

Open the chart page →

2,049
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jsoup@1.18.1
1.23.1

Open the chart page →

5,826
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
jsoup@1.17.2
1.23.1

Open the chart page →

6,037
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
jsoup@1.15.3
1.23.1

Open the chart page →

2,024
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
jsoup@1.15.3
1.23.1

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
jsoup@1.15.3
1.23.1

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
jsoup@1.15.3
1.23.1

Open the chart page →

1,753
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jsoup@1.15.4
1.23.1

Open the chart page →

6,207
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
jsoup@1.15.3
1.23.1

Open the chart page →

4,946
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
jsoup@1.15.4
1.23.1

Open the chart page →

4,674
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jsoup@1.22.1
1.23.1

Open the chart page →

1,825
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
jsoup@1.15.3
1.23.1

Open the chart page →

5,484
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
jsoup@1.21.2
1.23.1

Open the chart page →

2,191
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.1

Open the chart page →

1,639
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-71497.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.1

Open the chart page →

9,381

Container images carrying it

81 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
airbyte/workload-launcher:2.2.0119be7bfb719
jsoup@1.15.3
1.23.1
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
jsoup@1.17.2
1.23.1
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
jsoup@1.22.1
1.23.1
2
library/elasticsearch:8.19.1289729a95066a
jsoup@1.21.2
1.23.1
2
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.1
2
opensearchproject/opensearch:2.1.04254021a8c71
jsoup@1.14.3
1.23.1
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.1
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
jsoup@1.20.1
1.23.1
2
1dev/server:11.9.0cd5b12fe5471
jsoup@1.17.2
1.23.1
1
airbyte/bootloader:2.2.0f71cf4e185d5
jsoup@1.15.3
1.23.1
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
jsoup@1.15.3
1.23.1
1
airbyte/cron:2.2.0d97b67a1346d
jsoup@1.15.3
1.23.1
1
airbyte/server:2.2.070e125498a1c
jsoup@1.15.3
1.23.1
1
airbyte/worker:2.2.08060b88b29c8
jsoup@1.15.3
1.23.1
1
airbyte/workload-api-server:2.2.042093cff86e9
jsoup@1.15.3
1.23.1
1
apache/tika:3.3.1.090b7fa1dc018
jsoup@1.22.2
1.23.1
1
apache/tika:3.2.2.0-fullffab324253ed
jsoup@1.21.1
1.23.1
1
assistiot/automated_configuration:latest23f195a7a26a
jsoup@1.14.3
1.23.1
1
athou/commafeed:6.2.0-postgresql5e388351df1a
jsoup@1.22.1
1.23.1
1
atlassian/bitbucket:10.2.705933f2b1cfd
jsoup@1.22.2
1.23.1
1
atlassian/crowd:7.2.3c81cc7d6bc9e
jsoup@1.22.2
1.23.1
1
atlassian/crowd:5.2.2ebf761c7d437
jsoup@1.16.2
1.23.1
1
atlassian/jira-software:9.7.264a75aa4ec4e
jsoup@1.15.3
1.23.1
1
atlassian/jira-software:11.3.11e5548cd4eea8
jsoup@1.19.1
1.23.1
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
jsoup@1.15.3
1.23.1
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
jsoup@1.15.4
1.23.1
1
bluerange/bluerange:26.1.307c8f73b55df
jsoup@1.20.1
1.23.1
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jsoup@1.17.2
1.23.1
1
codetogether/codetogether:latest4348c8a38752
jsoup@1.15.3
1.23.1
1
conductoross/conductor:3.31.09fba127693e6
jsoup@1.15.4
1.23.1
1
easypi/openrefine:3.7.0d2950a36a576
jsoup@1.15.3
1.23.1
1
eginnovations/agent:7.5.4e4dfe242fe9f
jsoup@1.17.2
1.23.1
1
epamedp/edp-gerrit:3.14.249e8fe9c4855
jsoup@1.14.3
1.23.1
1
erudikaltd/scoold:1.66.0949c56b57e8f
jsoup@1.22.1
1.23.1
1
frankescobar/allure-docker-service:latestdc171ec796d5
jsoup@1.22.2
1.23.1
1
gotson/komga:1.22.0ba892ab3e082
jsoup@1.18.3
1.23.1
1
graviteeio/ae-engine:3.0.24140932887e0
jsoup@1.20.1
1.23.1
1
graviteeio/am-gateway:4.12.607b7f6dc267a
jsoup@1.16.1
1.23.1
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
jsoup@1.22.1
1.23.1
1
graylog/graylog:7.1.9598bd41fefd5
jsoup@1.22.1
1.23.1
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
jsoup@1.22.1
1.23.1
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
jsoup@1.21.2
1.23.1
1
gridgain/gridgain9:9.1.1895018390077b
jsoup@1.16.1
1.23.1
1
hivemq/hivemq4:dns-4.5.144d194450d48e
jsoup@1.14.3
1.23.1
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
jsoup@1.15.3
1.23.1
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
jsoup@1.15.4
1.23.1
1
library/elasticsearch:9.5.38d09295845fe
jsoup@1.21.2
1.23.1
1
library/elasticsearch:9.5.19656a9ca03f8
jsoup@1.21.2
1.23.1
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
jsoup@1.18.1
1.23.1
1
liukunup/jmeter:5.59c079617a81b
jsoup@1.15.3
1.23.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.