StackRadar

CVE-2026-75140

High

Advisory

Published 20 Aug 2026In the index since 6 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
157
of 18,026 indexed, latest versions
Container images
158
deployed by those charts
Fix available
1 of 1
affected package

jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations

Carried by container images the latest versions of 157 of 18,026 indexed charts deploy, on 158 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.6.1, 1.7.1, 1.7.2, 1.8.1+26 more1.23.2158
OSV records
GHSA-65r4-943x-97jj

Charts affected

157 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jsoup@1.8.3
1.23.2

Open the chart page →

30,229
elasticsearchwiremindVerified publisher8.19.11 of 1See more

elasticsearch wiremind 8.19.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.22d071f96fab6c
jsoup@1.21.2
1.23.2

Open the chart page →

648
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.2

Open the chart page →

1,826
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jsoup@1.12.1
1.23.2

Open the chart page →

12,127
ei-pattern-1wso26.6.0-33 of 6See more

ei-pattern-1 wso2 6.6.0-3

3 of the 6 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
jsoup@1.10.3
1.23.2
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
jsoup@1.10.3
1.23.2
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
jsoup@1.10.3
1.23.2

Open the chart page →

52,046
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
jsoup@1.10.3
1.23.2

Open the chart page →

6,307
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.2

Open the chart page →

12,360

Container images carrying it

158 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
jsoup@1.7.2
1.23.2
1
opensearchproject/opensearch:2.15.01963b3ece46d
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.14.0466a49f379bb
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.12.0645d3d9390ad
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.19.269588c664014
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:3.3.2798cf28e226a
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
jsoup@1.15.3
1.23.2
1
opensearchproject/opensearch:2.19.6e321cb03c643
jsoup@1.15.3
1.23.2
1
owasp/dependency-track:3.8.0efc65e702ee1
jsoup@1.11.3
1.23.2
1
pcarrascoponce/planner:v1.0981fc482442c
jsoup@1.12.1
1.23.2
1
pedrocesarti/jmeter-docker:3.314851f144f57
jsoup@1.10.3
1.23.2
1
penpotapp/backend:2.2.147853d9bb9dd
jsoup@1.17.2
1.23.2
1
penpotapp/backend:1.16.0-betae978e871be07
jsoup@1.15.1
1.23.2
1
penpotapp/exporter:2.2.15c835ffd87ab
jsoup@1.7.2
1.23.2
1
penpotapp/exporter:1.16.0-betafa7086ad92b1
jsoup@1.7.2
1.23.2
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
jsoup@1.15.3
1.23.2
1
raykrueger/riemann:0.2.14c8baf3de57bb
jsoup@1.6.1
1.23.2
1
sismics/docs:v1.10f4b0ef019cf1
jsoup@1.13.1
1.23.2
1
sonatype/nexus:oss6bc88b51d4d7
jsoup@1.14.2
1.23.2
1
sonatype/nexus3:3.53.04bd975493104
jsoup@1.15.3
1.23.2
1
sonatype/nexus3:3.58.1586060431b64
jsoup@1.15.3
1.23.2
1
sonatype/nexus3:3.96.45f48f9085096
jsoup@1.23.1
1.23.2
1
stain/jena-fuseki:latestb1d0c96f19ad
jsoup@1.17.2
1.23.2
1
tinymediamanager/tinymediamanager:5.3.448c15784a127
jsoup@1.22.1
1.23.2
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
jsoup@1.12.1
1.23.2
1
wazuh/wazuh-indexer:4.14.49c344d2b1757
jsoup@1.15.3
1.23.2
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
jsoup@1.15.3
1.23.2
1
wazuh/wazuh-indexer:4.14.3b149b30da686
jsoup@1.15.3
1.23.2
1
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
jsoup@1.10.3
1.23.2
1
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
jsoup@1.10.3
1.23.2
1
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
jsoup@1.10.3
1.23.2
1
xetusoss/archiva:v2.2.588f25242b9ee
jsoup@1.7.2
1.23.2
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
jsoup@1.8.1
1.23.2
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
jsoup@1.16.1
1.23.2
1
ghcr.io/booklore-app/booklore:v2.3.1d3d3af34bc2c
jsoup@1.22.2
1.23.2
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
jsoup@1.23.1
1.23.2
1
ghcr.io/damap-org/damap-backend:5.0.10d5166b01eec
jsoup@1.21.2
1.23.2
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
jsoup@1.20.1
1.23.2
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
jsoup@1.21.2
1.23.2
1
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
jsoup@1.23.1
1.23.2
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jsoup@1.9.1
1.23.2
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
jsoup@1.11.3
1.23.2
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jsoup@1.22.1
1.23.2
1
ghcr.io/quenchworks/images/elasticsearchb4ba7cccf293
jsoup@1.23.1
1.23.2
1
ghcr.io/quenchworks/images/opensearch316df4614532
jsoup@1.23.1
1.23.2
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jsoup@1.15.4
1.23.2
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jsoup@1.23.1
1.23.2
1
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jsoup@1.22.2
1.23.2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
jsoup@1.12.1
1.23.2
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.