StackRadar

CVE-2026-75140

High

Advisory

Published 20 Aug 2026In the index since 6 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
157
of 18,026 indexed, latest versions
Container images
158
deployed by those charts
Fix available
1 of 1
affected package

jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations

Carried by container images the latest versions of 157 of 18,026 indexed charts deploy, on 158 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.6.1, 1.7.1, 1.7.2, 1.8.1+26 more1.23.2158
OSV records
GHSA-65r4-943x-97jj

Charts affected

157 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jsoup@1.8.3
1.23.2

Open the chart page →

30,229
elasticsearchwiremindVerified publisher8.19.11 of 1See more

elasticsearch wiremind 8.19.1

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.22d071f96fab6c
jsoup@1.21.2
1.23.2

Open the chart page →

648
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.2

Open the chart page →

1,826
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jsoup@1.12.1
1.23.2

Open the chart page →

12,127
ei-pattern-1wso26.6.0-33 of 6See more

ei-pattern-1 wso2 6.6.0-3

3 of the 6 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
jsoup@1.10.3
1.23.2
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
jsoup@1.10.3
1.23.2
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
jsoup@1.10.3
1.23.2

Open the chart page →

52,046
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
jsoup@1.10.3
1.23.2

Open the chart page →

6,307
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-75140.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.2

Open the chart page →

12,360

Container images carrying it

158 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mastercloudapps/planner:v1.2340a950b311b2
jsoup@1.12.1
1.23.2
4
codeurjc/planner:v1.0800cf520c245
jsoup@1.12.1
1.23.2
3
airbyte/workload-launcher:2.3.00e18b1abcda6
jsoup@1.15.3
1.23.2
2
graviteeio/apim-gateway:4.12.21-debianc7564f313dda
jsoup@1.17.2
1.23.2
2
graviteeio/apim-management-api:4.12.21-debian3caf0b09f8b5
jsoup@1.22.1
1.23.2
2
library/elasticsearch:8.19.22d071f96fab6c
jsoup@1.21.2
1.23.2
2
linuxserver/ubooquity:2.1.2-ls369932d6759112
jsoup@1.8.3
1.23.2
2
metabase/metabase:v0.61.1.x9491ed11c901
jsoup@1.21.2
1.23.2
2
opensearchproject/opensearch:2.1.04254021a8c71
jsoup@1.14.3
1.23.2
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
jsoup@1.15.3
1.23.2
2
sonatype/nexus3:3.96.4-ubi78e56e6a05d0
jsoup@1.23.1
1.23.2
2
sonatype/nexus-iq-server:1.207.1a70014ed10b1
jsoup@1.23.1
1.23.2
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.23.2
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
jsoup@1.20.1
1.23.2
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
jsoup@1.14.2
1.23.2
2
1dev/server:11.9.0cd5b12fe5471
jsoup@1.17.2
1.23.2
1
adagber/planner:v1.0e5c1ed097752
jsoup@1.12.1
1.23.2
1
airbyte/bootloader:2.3.0205b99d17c1a
jsoup@1.15.3
1.23.2
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
jsoup@1.15.3
1.23.2
1
airbyte/cron:2.3.0bf4835757eaa
jsoup@1.15.3
1.23.2
1
airbyte/server:2.3.039141ed8ce5e
jsoup@1.15.3
1.23.2
1
airbyte/worker:2.3.0f2e33fbc53d1
jsoup@1.15.3
1.23.2
1
airbyte/workload-api-server:2.3.0434b4a811156
jsoup@1.15.3
1.23.2
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
jsoup@1.11.3
1.23.2
1
apache/james:distributed-3.7.2660c0fa12ec2
jsoup@1.15.3
1.23.2
1
apache/tika:latest-full80072bb73dd3
jsoup@1.23.1
1.23.2
1
apache/tika:3.3.1.090b7fa1dc018
jsoup@1.22.2
1.23.2
1
apache/tika:3.2.2.0-fullffab324253ed
jsoup@1.21.1
1.23.2
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jsoup@1.12.1
1.23.2
1
arturisimo/planner:v1.0fff9de644941
jsoup@1.12.1
1.23.2
1
assistiot/automated_configuration:latest23f195a7a26a
jsoup@1.14.3
1.23.2
1
assistiot/identity-manager_kc:latest0df4b4fa899a
jsoup@1.14.2
1.23.2
1
athou/commafeed:6.2.0-postgresql5e388351df1a
jsoup@1.22.1
1.23.2
1
atlassian/bamboo:12.1.119160c3bfb73b
jsoup@1.23.1
1.23.2
1
atlassian/bitbucket:10.2.705933f2b1cfd
jsoup@1.22.2
1.23.2
1
atlassian/confluence-server:7.10.03b9222ab32ef
jsoup@1.9.2
1.23.2
1
atlassian/crowd:7.2.351e6d33676f6
jsoup@1.22.2
1.23.2
1
atlassian/crowd:5.2.2799a49be18d7
jsoup@1.16.2
1.23.2
1
atlassian/jira-software:8.14.037bc46cbec1a
jsoup@1.8.3
1.23.2
1
atlassian/jira-software:11.3.114046f4a668a4
jsoup@1.19.1
1.23.2
1
atlassian/jira-software:9.7.264a75aa4ec4e
jsoup@1.15.3
1.23.2
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
jsoup@1.11.3
1.23.2
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
jsoup@1.15.3
1.23.2
1
blackducksoftware/blackduck-alert:8.4.1b66c8385ba53
jsoup@1.15.4
1.23.2
1
bluerange/bluerange:26.2.0503577ef9143
jsoup@1.20.1
1.23.2
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jsoup@1.17.2
1.23.2
1
codetogether/codetogether:latest4348c8a38752
jsoup@1.15.3
1.23.2
1
craigwillis/c2metadata-bd:latestae317d7e4724
jsoup@1.7.2
1.23.2
1
easypi/openrefine:3.7.0d2950a36a576
jsoup@1.15.3
1.23.2
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
jsoup@1.12.1
1.23.2
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.