StackRadar

CVE-2026-76781

Medium

Advisory

Published 17 Sept 2026In the index since 19 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,096
of 17,828 indexed, latest versions
Container images
906
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,096 of 17,828 indexed charts deploy, on 906 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 moreno fix listed906
OSV records
DEBIAN-CVE-2026-76781UBUNTU-CVE-2026-76781ECHO-2007-775f-9d2b
Trending
Rank 6 in indexed charts, since 20 Sept 2026. See the ranking →

Charts affected

1,096 by stars
ChartLatestAffected imagesRadar Score
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

6,165
strapihelmforgeVerified publisher2.3.141 of 3See more

strapi helmforge 2.3.14

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,143
supersethelmforgeVerified publisher1.3.61 of 5See more

superset helmforge 1.3.6

1 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,889
text-embeddings-inferencehelmforgeVerified publisher1.0.01 of 2See more

text-embeddings-inference helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

2,609
twentyhelmforgeVerified publisher1.0.11 of 5See more

twenty helmforge 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,732
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,830
mywebhelm-httpdVerified publisher0.3.01 of 1See more

myweb helm-httpd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/httpd:latest454942557d44
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,247
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

12,845
jellyfinhelm-l3st86Verified publisher0.1.81 of 1See more

jellyfin helm-l3st86 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
jellyfin/jellyfin:latest78d3ea1207d1
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,597
openaevhelm-openbasVerified publisher2.0.62 of 7See more

openaev helm-openbas 2.0.6

2 of the 7 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
openaev/platform:3.260917.17e32eb72ca60
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

7,300
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

25,612
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
libxml2@2.9.13+dfsg-1ubuntu0.7
no fix listed

Open the chart page →

6,164
my-nginxhelmtaiwo0.1.01 of 1See more

my-nginx helmtaiwo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
samplehelmapphelmtraining3.0.01 of 1See more

samplehelmapp helmtraining 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
praravind1801/helmimages:3.0.0f29d637b9ce1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,057
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

14,576
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

16,645
paperlesshpVerified publisher0.1.22 of 5See more

paperless hp 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.3467097317623a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

27,556
hydrahydraVerified publisher0.9.51 of 2See more

hydra hydra 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

9,003
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

7,681
nginx-charthyomin-nginx0.1.01 of 1See more

nginx-chart hyomin-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
hyperglance-helmhyperglance-helmVerified publisher10.0.81 of 6See more

hyperglance-helm hyperglance-helm 10.0.8

1 of the 6 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
hyperglance/postgresql-v2:10.0.8a05d73bb30e7
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed

Open the chart page →

11,389
nginx-charthyun-nginx0.1.01 of 1See more

nginx-chart hyun-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
no fix listed

Open the chart page →

12,702
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
no fix listed

Open the chart page →

81,515
ibm-ucv-prodibm-helm5.3.01 of 16See more

ibm-ucv-prod ibm-helm 5.3.0

1 of the 16 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

12,249
browserlessicoretechVerified publisher0.16.61 of 1See more

browserless icoretech 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

2,036
metamcpicoretechVerified publisher0.3.111 of 2See more

metamcp icoretech 0.3.11

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,268
multicaicoretechVerified publisher0.5.11 of 4See more

multica icoretech 0.5.1

1 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
pgvector/pgvector:pg17cf134a767f47
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

2,000
nextjsicoretechVerified publisher1.2.01 of 1See more

nextjs icoretech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
tolgeeicoretechVerified publisher0.49.31 of 3See more

tolgee icoretech 0.49.3

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,800
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed

Open the chart page →

9,255
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

111,073
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

3,648
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,383
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

11,895
web-chartimcherry57780.1.01 of 1See more

web-chart imcherry5778 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
onechartimioVerified publisher0.76.01 of 1See more

onechart imio 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
plausible-analyticsimioVerified publisher0.4.23 of 5See more

plausible-analytics imio 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

10,803
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
libxml2@2.9.4+dfsg1-6.1ubuntu1.8
no fix listed

Open the chart page →

16,462
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

5,458
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
infisical/infisical:latest3365445909be
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,499
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,155
op-stackinfradao0.0.11 of 1See more

op-stack infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

10,633
gmaintelVerified publisher0.1.01 of 1See more

gma intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed

Open the chart page →

73,687
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

86,729
map5gintelVerified publisher1.0.01 of 1See more

map5g intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed

Open the chart page →

73,687
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

79,472
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

18,213
inventreeinventreeOfficialVerified publisher0.4.292 of 2See more

inventree inventree 0.4.29

2 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
inventree/inventree:1.5.55dc64d7ceee3
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
library/nginx:stable0aa2d81d65bc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,048

Container images carrying it

906 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.