StackRadar

CVE-2026-75140

High

Advisory

Published 20 Aug 2026In the index since 6 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
157
of 18,026 indexed, latest versions
Container images
158
deployed by those charts
Fix available
1 of 1
affected package

jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations

Carried by container images the latest versions of 157 of 18,026 indexed charts deploy, on 158 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.6.1, 1.7.1, 1.7.2, 1.8.1+26 more1.23.2158
OSV records
GHSA-65r4-943x-97jj

Charts affected

157 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jsoup@1.8.3
1.23.2

Open the chart page →

30,229
elasticsearchwiremindVerified publisher8.19.11 of 1See more

elasticsearch wiremind 8.19.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.22d071f96fab6c
jsoup@1.21.2
1.23.2

Open the chart page →

648
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.2

Open the chart page →

1,826
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jsoup@1.12.1
1.23.2

Open the chart page →

12,127
ei-pattern-1wso26.6.0-33 of 6See more

ei-pattern-1 wso2 6.6.0-3

3 of the 6 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
jsoup@1.10.3
1.23.2
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
jsoup@1.10.3
1.23.2
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
jsoup@1.10.3
1.23.2

Open the chart page →

52,046
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
jsoup@1.10.3
1.23.2

Open the chart page →

6,307
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.2

Open the chart page →

12,360

Container images carrying it

158 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
eginnovations/agent:7.5.4e4dfe242fe9f
jsoup@1.17.2
1.23.2
1
emcniece/dockeryourxyzzy:404eccbccc15c
jsoup@1.11.2
1.23.2
1
epam/ai-dial-admin-backend:0.21.08b91130e3731
jsoup@1.23.1
1.23.2
1
epamedp/edp-gerrit:3.14.249e8fe9c4855
jsoup@1.14.3
1.23.2
1
erudikaltd/scoold:1.66.0949c56b57e8f
jsoup@1.22.1
1.23.2
1
fiware/mintaka:0.7.092a3c5cf43c0
jsoup@1.12.1
1.23.2
1
fiware/mintaka:latestefc6793388cc
jsoup@1.12.1
1.23.2
1
frankescobar/allure-docker-service:latestdc171ec796d5
jsoup@1.22.2
1.23.2
1
gotson/komga:0.99.49b15ea6bfc30
jsoup@1.13.1
1.23.2
1
gotson/komga:1.27.19cf102f5fb78
jsoup@1.23.1
1.23.2
1
gotson/komga:1.22.0ba892ab3e082
jsoup@1.18.3
1.23.2
1
gotson/komga:1.28.1d8f772dce7b3
jsoup@1.23.1
1.23.2
1
graviteeio/ae-engine:3.0.24140932887e0
jsoup@1.20.1
1.23.2
1
graviteeio/am-gateway:4.12.8d09cf41530da
jsoup@1.16.1
1.23.2
1
graviteeio/am-management-api:4.12.849d0188a58ae
jsoup@1.16.1
1.23.2
1
graylog/graylog:7.1.9598bd41fefd5
jsoup@1.22.1
1.23.2
1
graylog/graylog:7.2.0-rc.1-1e5f1335a759c
jsoup@1.23.1
1.23.2
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
jsoup@1.22.1
1.23.2
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
jsoup@1.21.2
1.23.2
1
gridgain/gridgain9:9.1.1895018390077b
jsoup@1.16.1
1.23.2
1
hivemq/hivemq4:dns-4.5.144d194450d48e
jsoup@1.14.3
1.23.2
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
jsoup@1.14.2
1.23.2
1
hotavneesh/eclipse-jdtls:latesta4579b163414
jsoup@1.14.2
1.23.2
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
jsoup@1.12.1
1.23.2
1
hugohg34/planner:0.0.2171f61e8d7e2
jsoup@1.12.1
1.23.2
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
jsoup@1.7.2
1.23.2
1
ibmcom/microclimate-portal:latested5505e5c7ec
jsoup@1.10.3
1.23.2
1
ibmcom/microclimate-theia:lateste17bdccc5030
jsoup@1.9.2
1.23.2
1
jenkinsci/jenkins:2.67a1f33f004659
jsoup@1.7.1
1.23.2
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
jsoup@1.15.3
1.23.2
1
kdhrubo/db2rest:lateste20610ff81b0
jsoup@1.15.3
1.23.2
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
jsoup@1.13.1
1.23.2
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
jsoup@1.14.2
1.23.2
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
jsoup@1.15.4
1.23.2
1
library/elasticsearch:9.5.19656a9ca03f8
jsoup@1.21.2
1.23.2
1
library/elasticsearch:9.5.3a4e2b3d21ad0
jsoup@1.21.2
1.23.2
1
library/xwiki:lts-postgres-tomcat9b8142bce157
jsoup@1.23.1
1.23.2
1
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
jsoup@1.14.3
1.23.2
1
linuxserver/airsonic-advanced:11.1.4bae6dde843d7
jsoup@1.18.1
1.23.2
1
liukunup/jmeter:5.59c079617a81b
jsoup@1.15.3
1.23.2
1
lourdesmorente/new-planner:1.0.0608745878cdb
jsoup@1.12.1
1.23.2
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
jsoup@1.15.3
1.23.2
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
jsoup@1.10.3
1.23.2
1
metabase/metabase:v0.63.1.124f150effd484
jsoup@1.21.2
1.23.2
1
metabase/metabase:v0.53.4.17807bc5cad17
jsoup@1.18.2
1.23.2
1
molynx/planner:v1441c9f52f092
jsoup@1.12.1
1.23.2
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jsoup@1.18.1
1.23.2
1
olvid/bot-daemon:2.0.1e0e6b165d879
jsoup@1.17.2
1.23.2
1
opendronemap/nodeodm:3.6.2fcd99eb23d8d
jsoup@1.8.1
1.23.2
1
opennms/sentinel:36.0.4e1880996623f
jsoup@1.15.3
1.23.2
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.