CVE-2026-75140
HighAdvisory
Published 20 Aug 2026In the index since 6 Oct 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 43rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 157
- of 18,026 indexed, latest versions
- Container images
- 158
- deployed by those charts
- Fix available
- 1 of 1
- affected package
jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations
Carried by container images the latest versions of 157 of 18,026 indexed charts deploy, on 158 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jsoupmaven | 1.6.1, 1.7.1, 1.7.2, 1.8.1+26 more | 1.23.2 | 158 |
- OSV records
- GHSA-65r4-943x-97jj
Charts affected
157 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| webhookie-allwebhookie | 0.1.2 | 1 of 3See more | 30,229 |
| elasticsearchwiremindVerified publisher | 8.19.1 | 1 of 1See more | 648 |
| metabasewiremindVerified publisher | 2.27.5-wiremind0 | 1 of 1See more | 1,826 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 12,127 |
| ei-pattern-1wso2 | 6.6.0-3 | 3 of 6See more | 52,046 |
| is-pattern-1wso2is-pattern1 | 5.11.0 | 1 of 2See more | 6,307 |
| ygdrassil-monitoringygdrassilVerified publisher | 0.4.0 | 1 of 10See more | 12,360 |
Container images carrying it
158 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.