StackRadar

CVE-2026-76781

Medium

Advisory

Published 17 Sept 2026In the index since 19 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,096
of 17,828 indexed, latest versions
Container images
906
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,096 of 17,828 indexed charts deploy, on 906 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 moreno fix listed906
OSV records
DEBIAN-CVE-2026-76781UBUNTU-CVE-2026-76781ECHO-2007-775f-9d2b
Trending
Rank 6 in indexed charts, since 20 Sept 2026. See the ranking →

Charts affected

1,096 by stars
ChartLatestAffected imagesRadar Score
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

8,024
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

5,306
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

10,795
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

5,096
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,401
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

110,965
apm-hubflanksourceVerified publisher0.0.471 of 2See more

apm-hub flanksource 0.0.47

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,813
facetflanksourceVerified publisher0.1.721 of 1See more

facet flanksource 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.7237237038be15
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

21,572
mission-controlflanksourceVerified publisher0.1.3381 of 8See more

mission-control flanksource 0.1.338

1 of the 8 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

9,129
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,401
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,805
fluxer-helmfluxer-helm0.3.02 of 18See more

fluxer-helm fluxer-helm 0.3.0

2 of the 18 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
ghcr.io/fluxerapp/fluxer-media-proxy:2026.820.164955ced7544e6b3f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

27,620
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

4,192
fr24feederfnzv0.1.21 of 1See more

fr24feeder fnzv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,501
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,618
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

1,806
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

1,806
plexfydrah-charts2.2.01 of 1See more

plex fydrah-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
libxml2@2.9.3+dfsg1-1ubuntu0.7
no fix listed

Open the chart page →

9,020
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latest096dae27b5d6
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

2,701
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,306
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed

Open the chart page →

6,486
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
libxml2@2.9.14+dfsg-1.3ubuntu3.1
no fix listed
gchq/hdfs:3.3.35ec58edbb2db
libxml2@2.9.14+dfsg-1.3ubuntu3.1
no fix listed

Open the chart page →

17,191
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
libxml2@2.9.14+dfsg-1.3ubuntu3.1
no fix listed

Open the chart page →

9,493
garge-apigargeVerified publisher0.1.561 of 1See more

garge-api garge 0.1.56

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
sondresjo/garge-api:v2.12.762dfd5c9b2e4
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,133
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

18,189
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

14,924
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
no fix listed

Open the chart page →

19,337
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

16,315
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
no fix listed

Open the chart page →

13,631
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

85,137
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:lateste1fdac6133ad
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,767
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

9,561
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

9,943
lancachegeek-cookbookVerified publisher0.6.21 of 1See more

lancache geek-cookbook 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
lancachenet/monolithic:latest37f28b362c93
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,350
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

14,523
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,157
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

12,366
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed

Open the chart page →

28,162
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

19,713
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

15,855
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
no fix listed

Open the chart page →

12,081
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

10,632
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libxml2@2.9.10+dfsg-5
no fix listed

Open the chart page →

98,535
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
no fix listed

Open the chart page →

27,112
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

12,135
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
no fix listed

Open the chart page →

18,210
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

3,330
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

12,550
goofy-chartgoofy-chart0.1.01 of 1See more

goofy-chart goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
googly-logingoogly-login0.1.01 of 2See more

googly-login googly-login 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,268

Container images carrying it

906 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.