StackRadar

CVE-2026-75140

High

Advisory

Published 20 Aug 2026In the index since 6 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
157
of 18,026 indexed, latest versions
Container images
158
deployed by those charts
Fix available
1 of 1
affected package

jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations

Carried by container images the latest versions of 157 of 18,026 indexed charts deploy, on 158 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.6.1, 1.7.1, 1.7.2, 1.8.1+26 more1.23.2158
OSV records
GHSA-65r4-943x-97jj

Charts affected

157 by stars
ChartLatestAffected imagesRadar Score
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
jsoup@1.15.3
1.23.2

Open the chart page →

2,304
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
jsoup@1.14.3
1.23.2

Open the chart page →

3,338
daveit-at-mOfficialVerified publisher0.2.182 of 9See more

dave it-at-m 0.2.18

2 of the 9 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
jsoup@1.20.1
1.23.2
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
jsoup@1.21.2
1.23.2

Open the chart page →

14,812
jasperjasperVerified publisher1.0.2101 of 2See more

jasper jasper 1.0.210

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
jsoup@1.23.1
1.23.2

Open the chart page →

10,255
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
jsoup@1.7.1
1.23.2

Open the chart page →

12,235
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jsoup@1.9.1
1.23.2

Open the chart page →

13,190
proxerajfwenischVerified publisher0.12.201 of 1See more

proxera jfwenisch 0.12.20

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jsoup@1.22.2
1.23.2

Open the chart page →

325
james-mailserverjondos2.1.21 of 1See more

james-mailserver jondos 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
apache/james:distributed-3.7.2660c0fa12ec2
jsoup@1.15.3
1.23.2

Open the chart page →

8,339
xwikikeyporttech0.2.01 of 2See more

xwiki keyporttech 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
library/xwiki:lts-postgres-tomcat9b8142bce157
jsoup@1.23.1
1.23.2

Open the chart page →

1,569
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
jsoup@1.17.2
1.23.2
penpotapp/exporter:2.2.15c835ffd87ab
jsoup@1.7.2
1.23.2

Open the chart page →

19,014
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
jsoup@1.18.3
1.23.2

Open the chart page →

4,042
filebot-botluiscajl0.0.111 of 1See more

filebot-bot luiscajl 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
jsoup@1.14.2
1.23.2

Open the chart page →

4,225
lavandaluiscajl0.0.1341 of 5See more

lavanda luiscajl 0.0.134

1 of the 5 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
lavandadelpatio/filebot:0.0.671f2ccec8c0d
jsoup@1.13.1
1.23.2

Open the chart page →

20,147
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
jsoup@1.15.4
1.23.2

Open the chart page →

3,422
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
hugohg34/planner:0.0.2171f61e8d7e2
jsoup@1.12.1
1.23.2

Open the chart page →

34,155
tinymediamanagermedia-servarrVerified publisher1.7.11 of 2See more

tinymediamanager media-servarr 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.448c15784a127
jsoup@1.22.1
1.23.2

Open the chart page →

10,003
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
jsoup@1.18.2
1.23.2

Open the chart page →

3,050
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2799a49be18d7
jsoup@1.16.2
1.23.2

Open the chart page →

5,682
commafeedmt1905028.2.01 of 3See more

commafeed mt190502 8.2.0

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
jsoup@1.22.1
1.23.2

Open the chart page →

4,209
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
jsoup@1.12.1
1.23.2

Open the chart page →

9,620
Practica_4_helmmy-heml-appVerified publisher0.1.01 of 7See more

Practica_4_helm my-heml-app 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
adagber/planner:v1.0e5c1ed097752
jsoup@1.12.1
1.23.2

Open the chart page →

32,306
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jsoup@1.7.2
1.23.2

Open the chart page →

58,355
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
jsoup@1.11.3
1.23.2

Open the chart page →

3,731
nexus2novum-rgi-charts0.1.11 of 1See more

nexus2 novum-rgi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
sonatype/nexus:oss6bc88b51d4d7
jsoup@1.14.2
1.23.2

Open the chart page →

3,381
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
jsoup@1.17.2
1.23.2

Open the chart page →

2,414
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jsoup@1.18.1
1.23.2

Open the chart page →

6,916
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
jsoup@1.17.2
1.23.2

Open the chart page →

6,989
sentinelopennms-helm-chartsVerified publisher0.5.01 of 2See more

sentinel opennms-helm-charts 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.4e1880996623f
jsoup@1.15.3
1.23.2

Open the chart page →

2,120
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
jsoup@1.15.3
1.23.2

Open the chart page →

1,471
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
jsoup@1.15.3
1.23.2

Open the chart page →

234,921
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
jsoup@1.15.3
1.23.2

Open the chart page →

1,514
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
jsoup@1.12.1
1.23.2

Open the chart page →

30,523
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
jsoup@1.12.1
1.23.2

Open the chart page →

31,941
elasticsearchquench-elasticsearchVerified publisher0.0.211 of 1See more

elasticsearch quench-elasticsearch 0.0.21

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/elasticsearchdigest-pinnedb4ba7cccf293
jsoup@1.23.1
1.23.2

Open the chart page →

59
opensearchquench-opensearchVerified publisher0.1.121 of 1See more

opensearch quench-opensearch 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/opensearchdigest-pinned316df4614532
jsoup@1.23.1
1.23.2

Open the chart page →

59
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
jsoup@1.12.1
1.23.2

Open the chart page →

31,113
komgarubxkubeVerified publisher0.1.51 of 1See more

komga rubxkube 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
gotson/komga:1.28.1d8f772dce7b3
jsoup@1.23.1
1.23.2

Open the chart page →

34,000
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jsoup@1.15.4
1.23.2

Open the chart page →

7,127
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jsoup@1.23.1
1.23.2

Open the chart page →

2,055
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
jsoup@1.15.3
1.23.2

Open the chart page →

5,066
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
jsoup@1.7.2
1.23.2

Open the chart page →

6,954
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jsoup@1.9.2
1.23.2

Open the chart page →

14,218
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
jsoup@1.8.3
1.23.2

Open the chart page →

13,568
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
jsoup@1.12.1
1.23.2

Open the chart page →

30,217
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.23.2

Open the chart page →

12,637
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.23.2

Open the chart page →

12,637
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jsoup@1.22.1
1.23.2

Open the chart page →

2,075
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jsoup@1.12.1
1.23.2

Open the chart page →

13,022
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jsoup@1.8.3
1.23.2

Open the chart page →

4,358
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
jsoup@1.15.3
1.23.2

Open the chart page →

7,239

Container images carrying it

158 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
jsoup@1.7.2
1.23.2
1
opensearchproject/opensearch:2.15.01963b3ece46d
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.14.0466a49f379bb
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.12.0645d3d9390ad
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.19.269588c664014
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:3.3.2798cf28e226a
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.19.6e321cb03c643
jsoup@1.15.3
1.23.2
1
owasp/dependency-track:3.8.0efc65e702ee1
jsoup@1.11.3
1.23.2
1
pcarrascoponce/planner:v1.0981fc482442c
jsoup@1.12.1
1.23.2
1
pedrocesarti/jmeter-docker:3.314851f144f57
jsoup@1.10.3
1.23.2
1
penpotapp/backend:2.2.147853d9bb9dd
jsoup@1.17.2
1.23.2
1
penpotapp/backend:1.16.0-betae978e871be07
jsoup@1.15.1
1.23.2
1
penpotapp/exporter:2.2.15c835ffd87ab
jsoup@1.7.2
1.23.2
1
penpotapp/exporter:1.16.0-betafa7086ad92b1
jsoup@1.7.2
1.23.2
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
jsoup@1.15.3
1.23.2
1
raykrueger/riemann:0.2.14c8baf3de57bb
jsoup@1.6.1
1.23.2
1
sismics/docs:v1.10f4b0ef019cf1
jsoup@1.13.1
1.23.2
1
sonatype/nexus:oss6bc88b51d4d7
jsoup@1.14.2
1.23.2
1
sonatype/nexus3:3.53.04bd975493104
jsoup@1.15.3
1.23.2
1
sonatype/nexus3:3.58.1586060431b64
jsoup@1.15.3
1.23.2
1
sonatype/nexus3:3.96.45f48f9085096
jsoup@1.23.1
1.23.2
1
stain/jena-fuseki:latestb1d0c96f19ad
jsoup@1.17.2
1.23.2
1
tinymediamanager/tinymediamanager:5.3.448c15784a127
jsoup@1.22.1
1.23.2
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
jsoup@1.12.1
1.23.2
1
wazuh/wazuh-indexer:4.14.49c344d2b1757
jsoup@1.15.3
1.23.2
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
jsoup@1.15.3
1.23.2
1
wazuh/wazuh-indexer:4.14.3b149b30da686
jsoup@1.15.3
1.23.2
1
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
jsoup@1.10.3
1.23.2
1
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
jsoup@1.10.3
1.23.2
1
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
jsoup@1.10.3
1.23.2
1
xetusoss/archiva:v2.2.588f25242b9ee
jsoup@1.7.2
1.23.2
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
jsoup@1.8.1
1.23.2
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
jsoup@1.16.1
1.23.2
1
ghcr.io/booklore-app/booklore:v2.3.1d3d3af34bc2c
jsoup@1.22.2
1.23.2
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
jsoup@1.23.1
1.23.2
1
ghcr.io/damap-org/damap-backend:5.0.10d5166b01eec
jsoup@1.21.2
1.23.2
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
jsoup@1.20.1
1.23.2
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
jsoup@1.21.2
1.23.2
1
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
jsoup@1.23.1
1.23.2
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jsoup@1.9.1
1.23.2
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
jsoup@1.11.3
1.23.2
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jsoup@1.22.1
1.23.2
1
ghcr.io/quenchworks/images/elasticsearchb4ba7cccf293
jsoup@1.23.1
1.23.2
1
ghcr.io/quenchworks/images/opensearch316df4614532
jsoup@1.23.1
1.23.2
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jsoup@1.15.4
1.23.2
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jsoup@1.23.1
1.23.2
1
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jsoup@1.22.2
1.23.2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
jsoup@1.12.1
1.23.2
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.