StackRadar

CVE-2026-72522

Medium

Advisory

Published 10 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,182
of 17,787 indexed, latest versions
Container images
1,156
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-72522 affecting package expat for versions less than 2.8.3-1

Carried by container images the latest versions of 1,182 of 17,787 indexed charts deploy, on 1,156 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+34 more2.5.0-1+deb12u3, 2.8.3-1~deb13u1, 2.8.4-11,154
expatrpm2.8.2-1.azl32.8.3-12
OSV records
DEBIAN-CVE-2026-72522UBUNTU-CVE-2026-72522AZL-94698ECHO-de7d-deea-1f3e

Charts affected

1,182 by stars
ChartLatestAffected imagesRadar Score
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
expat@2.6.1-2ubuntu0.3
no fix listed
oscarsotosanchez/weatherservice:v1.0911ec961d10b
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

27,349
eoloPlanteolo-plannerVerified publisher0.1.03 of 7See more

eoloPlant eolo-planner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.11-managementc3f70098e01d
expat@2.4.7-1ubuntu0.2
no fix listed
mastercloudapps/planner:v1.2340a950b311b2
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

27,667
eoloplannereoloplannerVerified publisher0.1.03 of 7See more

eoloplanner eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
expat@2.4.7-1ubuntu0.2
no fix listed
codeurjc/toposervice:v1.09fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

32,336
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.03 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.11-managementc3f70098e01d
expat@2.4.7-1ubuntu0.2
no fix listed
mastercloudapps/planner:v1.2340a950b311b2
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

27,667
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
expat@2.6.1-2ubuntu0.3
no fix listed
oscarsotosanchez/weatherservice:v1.0911ec961d10b
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

27,314
eoloplannereoloplanner-molynx-gat0.1.02 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

28,539
eolo-plannereolo-planner-repo0.1.02 of 7See more

eolo-planner eolo-planner-repo 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

27,188
eoloplanteoloplant1.0.03 of 7See more

eoloplant eoloplant 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.11-managementc3f70098e01d
expat@2.4.7-1ubuntu0.2
no fix listed
mastercloudapps/planner:v1.2340a950b311b2
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

27,667
eoloplantseoloplants-urjcVerified publisher0.1.02 of 7See more

eoloplants eoloplants-urjc 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

27,812
servereoloserverVerified publisher0.1.03 of 7See more

server eoloserver 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
expat@2.4.7-1ubuntu0.2
no fix listed
codeurjc/toposervice:v1.09fb4c11e6a49
expat@2.2.5-3ubuntu0.9
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

32,336
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

9,383
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

5,316
rabbitmqeosc-lot-1Verified publisher0.3.01 of 2See more

rabbitmq eosc-lot-1 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/rabbitmq:3.13-managemente582c0bc7766
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

2,505
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

6,475
assertoorethereum-helm-chartsVerified publisher1.2.01 of 1See more

assertoor ethereum-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ethpandaops/assertoor:latest1efa2fba6711
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

2,903
chaos-meshethereum-helm-chartsVerified publisher0.0.31 of 4See more

chaos-mesh ethereum-helm-charts 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

12,147
powfaucetethereum-helm-chartsVerified publisher1.2.11 of 1See more

powfaucet ethereum-helm-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
pk910/powfaucet:v2-stable3dcae6a62896
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

4,117
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

7,406
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

7,406
nethermindethersphereVerified publisher0.2.11 of 1See more

nethermind ethersphere 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
nethermind/nethermind:1.14.615517708c3b6
expat@2.4.7-1ubuntu0.1
no fix listed

Open the chart page →

4,964
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
expat@2.2.9-1build1
no fix listed

Open the chart page →

20,987
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

7,665
event-generatorfalcosecurity0.4.01 of 1See more

event-generator falcosecurity 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
falcosecurity/event-generator:latest932956d86c99
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

3,651
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
expat@2.4.7-1
no fix listed

Open the chart page →

13,491
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
expat@2.1.0-7ubuntu0.16.04.5
no fix listed

Open the chart page →

14,688
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

10,119
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
expat@2.6.1-2build1
no fix listed

Open the chart page →

12,510
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

5,038
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
expat@2.7.1-2
2.8.3-1~deb13u1
fireflyiii/data-importer:version-2.2.3ab52bf932546
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

10,258
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

4,828
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
expat@2.2.9-1ubuntu0.8
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

64,192
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

5,340
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

8,831
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
expat@2.4.7-1
no fix listed

Open the chart page →

5,690
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

4,123
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

2,432
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

3,143
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

13,247
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
expat@2.6.1-2ubuntu0.2
no fix listed
gchq/hdfs:3.3.35ec58edbb2db
expat@2.6.1-2ubuntu0.2
no fix listed

Open the chart page →

16,969
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
expat@2.6.1-2ubuntu0.2
no fix listed

Open the chart page →

9,381
garge-apigargeVerified publisher0.1.551 of 1See more

garge-api garge 0.1.55

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
sondresjo/garge-api:v2.12.6f41e452800ff
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,084
pagesgary-pages1.0.02 of 3See more

pages gary-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,233
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
expat@2.2.9-1build1
no fix listed

Open the chart page →

18,217
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

14,698
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

19,234
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
expat@2.2.9-1build1
no fix listed

Open the chart page →

16,178
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

13,572
dizquetvgeek-cookbookVerified publisher4.4.21 of 1See more

dizquetv geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
vexorian/dizquetv:1.4.37e2b99844a5c
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

4,885
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
expat@2.2.9-1build1
no fix listed

Open the chart page →

12,270
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:latesta792931146b4
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,764

Container images carrying it

1,156 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
expat@2.6.1-2ubuntu0.3
no fix listed
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
expat@2.4.7-1ubuntu0.4
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
expat@2.4.7-1ubuntu0.2
no fix listed
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
expat@2.4.7-1ubuntu0.3
no fix listed
1
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
expat@2.5.0-1
2.5.0-1+deb12u3
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
expat@2.4.7-1ubuntu0.5
no fix listed
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
expat@2.4.7-1ubuntu0.2
no fix listed
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
expat@2.2.9-1ubuntu0.6
no fix listed
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
expat@2.5.0-1
2.5.0-1+deb12u3
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
expat@2.4.7-1ubuntu0.2
no fix listed
1
ghcr.io/caninehq/canine:latesta058034ca006
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/cleanuparr/cleanuparr:2.10.5c7cd53ad559a
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
expat@2.6.1-2ubuntu0.3
no fix listed
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/damap-org/damap-frontend:5.0.1609f48af4efc
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
expat@2.8.2-1~deb13u1
2.8.3-1~deb13u1
1
ghcr.io/dask/dask:2024.1.0080150de7d86
expat@2.2.9-1ubuntu0.6
no fix listed
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
expat@2.4.7-1ubuntu0.2
no fix listed
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
expat@2.6.1-2ubuntu0.1
no fix listed
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
expat@2.5.0-1
2.5.0-1+deb12u3
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
expat@2.2.5-3ubuntu0.2
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
expat@2.5.0-1
2.5.0-1+deb12u3
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
expat@2.8.2-1~deb13u1
2.8.3-1~deb13u1
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
expat@2.7.1-2
2.8.3-1~deb13u1
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/firecrawl/firecrawl:2.11.33470453d7102cc
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.