StackRadar

CVE-2026-75140

High

Advisory

Published 20 Aug 2026In the index since 6 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
157
of 18,026 indexed, latest versions
Container images
158
deployed by those charts
Fix available
1 of 1
affected package

jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations

Carried by container images the latest versions of 157 of 18,026 indexed charts deploy, on 158 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.6.1, 1.7.1, 1.7.2, 1.8.1+26 more1.23.2158
OSV records
GHSA-65r4-943x-97jj

Charts affected

157 by stars
ChartLatestAffected imagesRadar Score
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
jsoup@1.15.3
1.23.2

Open the chart page →

2,304
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
jsoup@1.14.3
1.23.2

Open the chart page →

3,338
daveit-at-mOfficialVerified publisher0.2.182 of 9See more

dave it-at-m 0.2.18

2 of the 9 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
jsoup@1.20.1
1.23.2
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
jsoup@1.21.2
1.23.2

Open the chart page →

14,812
jasperjasperVerified publisher1.0.2101 of 2See more

jasper jasper 1.0.210

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
jsoup@1.23.1
1.23.2

Open the chart page →

10,255
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
jsoup@1.7.1
1.23.2

Open the chart page →

12,235
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jsoup@1.9.1
1.23.2

Open the chart page →

13,190
proxerajfwenischVerified publisher0.12.201 of 1See more

proxera jfwenisch 0.12.20

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jsoup@1.22.2
1.23.2

Open the chart page →

325
james-mailserverjondos2.1.21 of 1See more

james-mailserver jondos 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
apache/james:distributed-3.7.2660c0fa12ec2
jsoup@1.15.3
1.23.2

Open the chart page →

8,339
xwikikeyporttech0.2.01 of 2See more

xwiki keyporttech 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
library/xwiki:lts-postgres-tomcat9b8142bce157
jsoup@1.23.1
1.23.2

Open the chart page →

1,569
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
jsoup@1.17.2
1.23.2
penpotapp/exporter:2.2.15c835ffd87ab
jsoup@1.7.2
1.23.2

Open the chart page →

19,014
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
jsoup@1.18.3
1.23.2

Open the chart page →

4,042
filebot-botluiscajl0.0.111 of 1See more

filebot-bot luiscajl 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
jsoup@1.14.2
1.23.2

Open the chart page →

4,225
lavandaluiscajl0.0.1341 of 5See more

lavanda luiscajl 0.0.134

1 of the 5 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
lavandadelpatio/filebot:0.0.671f2ccec8c0d
jsoup@1.13.1
1.23.2

Open the chart page →

20,147
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
jsoup@1.15.4
1.23.2

Open the chart page →

3,422
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
hugohg34/planner:0.0.2171f61e8d7e2
jsoup@1.12.1
1.23.2

Open the chart page →

34,155
tinymediamanagermedia-servarrVerified publisher1.7.11 of 2See more

tinymediamanager media-servarr 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.448c15784a127
jsoup@1.22.1
1.23.2

Open the chart page →

10,003
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
jsoup@1.18.2
1.23.2

Open the chart page →

3,050
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2799a49be18d7
jsoup@1.16.2
1.23.2

Open the chart page →

5,682
commafeedmt1905028.2.01 of 3See more

commafeed mt190502 8.2.0

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
jsoup@1.22.1
1.23.2

Open the chart page →

4,209
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
jsoup@1.12.1
1.23.2

Open the chart page →

9,620
Practica_4_helmmy-heml-appVerified publisher0.1.01 of 7See more

Practica_4_helm my-heml-app 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
adagber/planner:v1.0e5c1ed097752
jsoup@1.12.1
1.23.2

Open the chart page →

32,306
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jsoup@1.7.2
1.23.2

Open the chart page →

58,355
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
jsoup@1.11.3
1.23.2

Open the chart page →

3,731
nexus2novum-rgi-charts0.1.11 of 1See more

nexus2 novum-rgi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
sonatype/nexus:oss6bc88b51d4d7
jsoup@1.14.2
1.23.2

Open the chart page →

3,381
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
jsoup@1.17.2
1.23.2

Open the chart page →

2,414
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jsoup@1.18.1
1.23.2

Open the chart page →

6,916
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
jsoup@1.17.2
1.23.2

Open the chart page →

6,989
sentinelopennms-helm-chartsVerified publisher0.5.01 of 2See more

sentinel opennms-helm-charts 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.4e1880996623f
jsoup@1.15.3
1.23.2

Open the chart page →

2,120
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
jsoup@1.15.3
1.23.2

Open the chart page →

1,471
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
jsoup@1.15.3
1.23.2

Open the chart page →

234,921
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
jsoup@1.15.3
1.23.2

Open the chart page →

1,514
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
jsoup@1.12.1
1.23.2

Open the chart page →

30,523
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
jsoup@1.12.1
1.23.2

Open the chart page →

31,941
elasticsearchquench-elasticsearchVerified publisher0.0.211 of 1See more

elasticsearch quench-elasticsearch 0.0.21

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/elasticsearchdigest-pinnedb4ba7cccf293
jsoup@1.23.1
1.23.2

Open the chart page →

59
opensearchquench-opensearchVerified publisher0.1.121 of 1See more

opensearch quench-opensearch 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/opensearchdigest-pinned316df4614532
jsoup@1.23.1
1.23.2

Open the chart page →

59
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
jsoup@1.12.1
1.23.2

Open the chart page →

31,113
komgarubxkubeVerified publisher0.1.51 of 1See more

komga rubxkube 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
gotson/komga:1.28.1d8f772dce7b3
jsoup@1.23.1
1.23.2

Open the chart page →

34,000
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jsoup@1.15.4
1.23.2

Open the chart page →

7,127
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jsoup@1.23.1
1.23.2

Open the chart page →

2,055
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
jsoup@1.15.3
1.23.2

Open the chart page →

5,066
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
jsoup@1.7.2
1.23.2

Open the chart page →

6,954
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jsoup@1.9.2
1.23.2

Open the chart page →

14,218
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
jsoup@1.8.3
1.23.2

Open the chart page →

13,568
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
jsoup@1.12.1
1.23.2

Open the chart page →

30,217
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.23.2

Open the chart page →

12,637
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.23.2

Open the chart page →

12,637
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jsoup@1.22.1
1.23.2

Open the chart page →

2,075
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jsoup@1.12.1
1.23.2

Open the chart page →

13,022
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jsoup@1.8.3
1.23.2

Open the chart page →

4,358
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
jsoup@1.15.3
1.23.2

Open the chart page →

7,239

Container images carrying it

158 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mastercloudapps/planner:v1.2340a950b311b2
jsoup@1.12.1
1.23.2
4
codeurjc/planner:v1.0800cf520c245
jsoup@1.12.1
1.23.2
3
airbyte/workload-launcher:2.3.00e18b1abcda6
jsoup@1.15.3
1.23.2
2
graviteeio/apim-gateway:4.12.21-debianc7564f313dda
jsoup@1.17.2
1.23.2
2
graviteeio/apim-management-api:4.12.21-debian3caf0b09f8b5
jsoup@1.22.1
1.23.2
2
library/elasticsearch:8.19.22d071f96fab6c
jsoup@1.21.2
1.23.2
2
linuxserver/ubooquity:2.1.2-ls369932d6759112
jsoup@1.8.3
1.23.2
2
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.2
2
opensearchproject/opensearch:2.1.04254021a8c71
jsoup@1.14.3
1.23.2
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.2
2
sonatype/nexus3:3.96.4-ubi78e56e6a05d0
jsoup@1.23.1
1.23.2
2
sonatype/nexus-iq-server:1.207.1a70014ed10b1
jsoup@1.23.1
1.23.2
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.23.2
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
jsoup@1.20.1
1.23.2
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
jsoup@1.14.2
1.23.2
2
1dev/server:11.9.0cd5b12fe5471
jsoup@1.17.2
1.23.2
1
adagber/planner:v1.0e5c1ed097752
jsoup@1.12.1
1.23.2
1
airbyte/bootloader:2.3.0205b99d17c1a
jsoup@1.15.3
1.23.2
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
jsoup@1.15.3
1.23.2
1
airbyte/cron:2.3.0bf4835757eaa
jsoup@1.15.3
1.23.2
1
airbyte/server:2.3.039141ed8ce5e
jsoup@1.15.3
1.23.2
1
airbyte/worker:2.3.0f2e33fbc53d1
jsoup@1.15.3
1.23.2
1
airbyte/workload-api-server:2.3.0434b4a811156
jsoup@1.15.3
1.23.2
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
jsoup@1.11.3
1.23.2
1
apache/james:distributed-3.7.2660c0fa12ec2
jsoup@1.15.3
1.23.2
1
apache/tika:latest-full80072bb73dd3
jsoup@1.23.1
1.23.2
1
apache/tika:3.3.1.090b7fa1dc018
jsoup@1.22.2
1.23.2
1
apache/tika:3.2.2.0-fullffab324253ed
jsoup@1.21.1
1.23.2
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jsoup@1.12.1
1.23.2
1
arturisimo/planner:v1.0fff9de644941
jsoup@1.12.1
1.23.2
1
assistiot/automated_configuration:latest23f195a7a26a
jsoup@1.14.3
1.23.2
1
assistiot/identity-manager_kc:latest0df4b4fa899a
jsoup@1.14.2
1.23.2
1
athou/commafeed:6.2.0-postgresql5e388351df1a
jsoup@1.22.1
1.23.2
1
atlassian/bamboo:12.1.119160c3bfb73b
jsoup@1.23.1
1.23.2
1
atlassian/bitbucket:10.2.705933f2b1cfd
jsoup@1.22.2
1.23.2
1
atlassian/confluence-server:7.10.03b9222ab32ef
jsoup@1.9.2
1.23.2
1
atlassian/crowd:7.2.351e6d33676f6
jsoup@1.22.2
1.23.2
1
atlassian/crowd:5.2.2799a49be18d7
jsoup@1.16.2
1.23.2
1
atlassian/jira-software:8.14.037bc46cbec1a
jsoup@1.8.3
1.23.2
1
atlassian/jira-software:11.3.114046f4a668a4
jsoup@1.19.1
1.23.2
1
atlassian/jira-software:9.7.264a75aa4ec4e
jsoup@1.15.3
1.23.2
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
jsoup@1.11.3
1.23.2
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
jsoup@1.15.3
1.23.2
1
blackducksoftware/blackduck-alert:8.4.1b66c8385ba53
jsoup@1.15.4
1.23.2
1
bluerange/bluerange:26.2.0503577ef9143
jsoup@1.20.1
1.23.2
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jsoup@1.17.2
1.23.2
1
codetogether/codetogether:latest4348c8a38752
jsoup@1.15.3
1.23.2
1
craigwillis/c2metadata-bd:latestae317d7e4724
jsoup@1.7.2
1.23.2
1
easypi/openrefine:3.7.0d2950a36a576
jsoup@1.15.3
1.23.2
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
jsoup@1.12.1
1.23.2
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.