StackRadar

CVE-2026-72522

Medium

Advisory

Published 10 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,182
of 17,787 indexed, latest versions
Container images
1,156
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-72522 affecting package expat for versions less than 2.8.3-1

Carried by container images the latest versions of 1,182 of 17,787 indexed charts deploy, on 1,156 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+34 more2.5.0-1+deb12u3, 2.8.3-1~deb13u1, 2.8.4-11,154
expatrpm2.8.2-1.azl32.8.3-12
OSV records
DEBIAN-CVE-2026-72522UBUNTU-CVE-2026-72522AZL-94698ECHO-de7d-deea-1f3e

Charts affected

1,182 by stars
ChartLatestAffected imagesRadar Score
karakeephelmforgeVerified publisher1.2.92 of 3See more

karakeep helmforge 1.2.9

2 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
expat@2.6.1-2ubuntu0.4
no fix listed
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

9,535
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
expat@2.8.2-1~deb13u1
2.8.3-1~deb13u1

Open the chart page →

3,654
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
expat@2.6.1-2ubuntu0.3
no fix listed
apache/hertzbeat-collector:1.8.0a2bab1be574c
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

14,109
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

6,354
kubeflowkubeflow1.6.22 of 45See more

kubeflow kubeflow 1.6.2

2 of the 45 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
expat@2.2.5-3ubuntu0.2
no fix listed
library/python:3.7eedf63967cdb
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

97,040
testkubekubeshop2.13.21 of 5See more

testkube kubeshop 2.13.2

1 of the 5 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

5,012
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

4,050
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

7,968
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

8,767
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

10,536
topolvmtopolvmVerified publisher17.2.01 of 1See more

topolvm topolvm 17.2.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
expat@2.4.7-1ubuntu0.7
no fix listed

Open the chart page →

2,364
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

19,363
reposilitevolker-raschekVerified publisher1.0.01 of 1See more

reposilite volker-raschek 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.5.264128c2d7a6ba
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

2,996
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

9,753
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

8,251
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
expat@2.7.4-1
no fix listed

Open the chart page →

1,245
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

8,007
geoservercloudcamptocamp23.0.17 of 7See more

geoservercloud camptocamp2 3.0.1

7 of the 7 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
expat@2.7.4-1
no fix listed
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
expat@2.7.4-1
no fix listed

Open the chart page →

10,819
thingsboardcetic0.1.21 of 2See more

thingsboard cetic 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
thingsboard/tb-postgres:latest2d17e4e36edc
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

5,243
collabora-codechrisingenhaag2.6.01 of 1See more

collabora-code chrisingenhaag 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
collabora/code:23.05.10.1.105299b452f7f
expat@2.5.0-1
2.5.0-1+deb12u3

Open the chart page →

4,184
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

17,475
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

27,984
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

9,348
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
expat@2.6.1-2ubuntu0.1
no fix listed

Open the chart page →

4,194
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

22,812
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
expat@2.2.9-1build1
no fix listed

Open the chart page →

10,652
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
expat@2.2.9-1ubuntu0.2
no fix listed

Open the chart page →

10,202
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
expat@2.2.9-1build1
no fix listed

Open the chart page →

10,676
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
expat@2.2.5-3ubuntu0.9
no fix listed

Open the chart page →

11,873
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
expat@2.7.4-1
no fix listed

Open the chart page →

1,820
terrariahalkeye0.4.21 of 2See more

terraria halkeye 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ryshe/terraria:latestb1c89f7f359a
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

4,154
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
expat@2.7.1-2
2.8.3-1~deb13u1
instill/mgmt-backend:d0933d4ebe12f77a3f9
expat@2.7.1-2
2.8.3-1~deb13u1
instill/model-backend:611f0f2e980125e5ba5
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

30,920
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
expat@2.6.1-2ubuntu0.1
no fix listed

Open the chart page →

4,357
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

4,546
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
expat@2.2.9-1ubuntu0.8
no fix listed

Open the chart page →

11,630
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
expat@2.1.0-7ubuntu0.16.04.3
no fix listed

Open the chart page →

15,345
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
expat@2.2.9-1ubuntu0.4
no fix listed

Open the chart page →

7,940
memgraph-high-availabilitymemgraphVerified publisher1.4.11 of 2See more

memgraph-high-availability memgraph 1.4.1

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.1bd3fe13228f4
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,208
kubecostmesosphere-stable0.37.51 of 9See more

kubecost mesosphere-stable 0.37.5

1 of the 9 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

17,755
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3

Open the chart page →

5,224
oesopsmxVerified publisher4.0.322 of 25See more

oes opsmx 4.0.32

2 of the 25 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
expat@2.6.1-2ubuntu0.3
no fix listed
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
no fix listed

Open the chart page →

107,899
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

5,079
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
expat@2.4.7-1ubuntu0.6
no fix listed

Open the chart page →

13,615
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

8,760
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

6,385
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
expat@2.2.9-1build1
no fix listed

Open the chart page →

24,549
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
expat@2.7.1-2
2.8.3-1~deb13u1

Open the chart page →

5,889
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
expat@2.4.7-1ubuntu0.6
no fix listed

Open the chart page →

5,814
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

15,525
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-72522.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3

Open the chart page →

7,064

Container images carrying it

1,156 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/zazukoians/qlever-server:v0.10.0f10fd24b2290
expat@2.6.1-2ubuntu0.4
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
mcr.microsoft.com/acstor/local-csi-driver:v0.3.0f9af53a79fd1
expat@2.8.2-1.azl3
2.8.3-1
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
expat@2.2.5-3ubuntu0.9
no fix listed
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
expat@2.2.9-1ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
expat@2.6.1-2ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
expat@2.4.7-1ubuntu0.7
no fix listed
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
expat@2.6.1-2ubuntu0.4
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
expat@2.2.5-3ubuntu0.9
no fix listed
1
mcr.microsoft.com/oss/v2/nvidia/k8s-device-plugin:v0.18.2-125a4e52c87bb9
expat@2.8.2-1.azl3
2.8.3-1
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
expat@2.6.1-2ubuntu0.3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
expat@2.6.1-2ubuntu0.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
expat@2.7.4-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
expat@2.7.4-1
no fix listed
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
expat@2.8.2-1+e1
2.8.4-1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
expat@2.5.0-1
2.5.0-1+deb12u3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
expat@2.2.9-1build1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
expat@2.5.0-1
2.5.0-1+deb12u3
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
expat@2.7.4-1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
expat@2.4.7-1
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
expat@2.4.7-1ubuntu0.2
no fix listed
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
expat@2.2.5-3ubuntu0.7
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
expat@2.4.7-1
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
expat@2.6.1-2ubuntu0.4
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
expat@2.5.0-1+deb12u1
2.5.0-1+deb12u3
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
no fix listed
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
expat@2.7.4-1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
expat@2.5.0-1
2.5.0-1+deb12u3
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
expat@2.6.1-2ubuntu0.4
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
expat@2.7.4-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
expat@2.7.1-2
2.8.3-1~deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
expat@2.5.0-1+deb12u2
2.5.0-1+deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.