StackRadar

CVE-2026-76781

Medium

Advisory

Published 17 Sept 2026In the index since 19 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,096
of 17,828 indexed, latest versions
Container images
906
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,096 of 17,828 indexed charts deploy, on 906 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 moreno fix listed906
OSV records
DEBIAN-CVE-2026-76781UBUNTU-CVE-2026-76781ECHO-2007-775f-9d2b
Trending
Rank 6 in indexed charts, since 20 Sept 2026. See the ranking →

Charts affected

1,096 by stars
ChartLatestAffected imagesRadar Score
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed

Open the chart page →

14,948
omec-control-planeopencord0.1.313 of 8See more

omec-control-plane opencord 0.1.31

3 of the 8 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
omecproject/mme-exporter:paging-latestbcc5f19fd676
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
omecproject/openmme:master-latest64776cb9edb3
libxml2@2.9.3+dfsg1-1ubuntu0.7
no fix listed

Open the chart page →

105,949
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
no fix listed

Open the chart page →

96,028
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

10,950
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

8,024
sohaopensohaVerified publisher0.1.91 of 2See more

soha opensoha 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

1,828
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed

Open the chart page →

99,366
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
libxml2@2.9.1+dfsg1-3ubuntu4.12
no fix listed

Open the chart page →

26,434
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

4,747
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.07 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

7 of the 40 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
yetiplatform/yeti-frontend:2.9.0873ef15d267b
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

200,900
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
yetiplatform/yeti-frontend:latest709064278c7e
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

6,893
webot-container-kit0.1.01 of 1See more

web ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

12,578
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

27,946
minecraftpaul1365972-mc3.0.11 of 1See more

minecraft paul1365972-mc 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
itzg/minecraft-server:latest77280d10744f
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

4,181
examplepauls-helm-charts0.1.21 of 1See more

example pauls-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
kubeconpauls-helm-charts0.1.01 of 1See more

kubecon pauls-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
matomopetbattle11.0.12 of 2See more

matomo petbattle 11.0.1

2 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

11,306
mariadbpetersandor15.2.51 of 1See more

mariadb petersandor 15.2.5

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnami/mariadb:11.7.216a7dae804fb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

2,956
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,913
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

16,578
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
libxml2@2.9.10+dfsg-5
no fix listed

Open the chart page →

90,166
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed

Open the chart page →

7,293
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

11,426
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
no fix listed

Open the chart page →

55,975
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
no fix listed

Open the chart page →

55,915
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed

Open the chart page →

5,036
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

12,161
web-chartpjw-ktcloudlab0.1.01 of 1See more

web-chart pjw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
planectlplanectlVerified publisher0.7.02 of 10See more

planectl planectl 0.7.0

2 of the 10 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
library/node:208f693eaa7e0a
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

26,601
plex-media-serverplex-media-server1.9.01 of 1See more

plex-media-server plex-media-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.43.3.10896-cb3ebc72d83a425ae9e13
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,028
k8s-oidc-discovery-providerpnnl-miscscripts0.1.21 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

4,398
nginx-apppnnl-miscscripts0.1.21 of 1See more

nginx-app pnnl-miscscripts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
pixiecore-simpleconfigpnnl-miscscripts0.1.51 of 1See more

pixiecore-simpleconfig pnnl-miscscripts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,150
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

77,539
libretimepodzone-chartsVerified publisher0.4.13 of 9See more

libretime podzone-charts 0.4.1

3 of the 9 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
library/postgres:16.24aea012537ed
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
ghcr.io/libretime/icecast:latest4bee94ce480c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

10,710
agentpolyaxon2.17.03 of 4See more

agent polyaxon 2.17.0

3 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
polyaxon/polyaxon-agent:2.17.0da877a2647fc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
polyaxon/polyaxon-cli:2.17.0297ed47ed63a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
polyaxon/polyaxon-streams:2.17.0a5fec70e757b
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

9,034
polyaxonpolyaxon2.17.04 of 5See more

polyaxon polyaxon 2.17.0

4 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
polyaxon/polyaxon-agent:2.17.0da877a2647fc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
polyaxon/polyaxon-api:2.17.0163707082036
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
polyaxon/polyaxon-cli:2.17.0297ed47ed63a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

12,832
postgrespostgresVerified publisher0.1.11 of 1See more

postgres postgres 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:13.12ced3ba927f4c
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

4,984
svc-postgrespostgres-fiap-lanches0.1.01 of 1See more

svc-postgres postgres-fiap-lanches 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,696
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,314
web-chartpsb-ktcloudlab0.1.01 of 1See more

web-chart psb-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
web-chartpsg-ktcloudlab0.1.01 of 1See more

web-chart psg-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
nginx-chartpshs-nginx0.1.01 of 1See more

nginx-chart pshs-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
apppvillaverdeVerified publisher0.2.61 of 1See more

app pvillaverde 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:1.31a53fc6c27208
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,868
game-serverpvillaverdeVerified publisher1.0.61 of 1See more

game-server pvillaverde 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/itzg/minecraft-server:latest46919d151d39
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

4,323
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
libxml2@2.9.14+dfsg-1.2
no fix listed

Open the chart page →

14,776

Container images carrying it

906 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.