StackRadar

CVE-2026-76781

Medium

Advisory

Published 17 Sept 2026In the index since 19 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,096
of 17,828 indexed, latest versions
Container images
906
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,096 of 17,828 indexed charts deploy, on 906 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+58 moreno fix listed906
OSV records
DEBIAN-CVE-2026-76781UBUNTU-CVE-2026-76781ECHO-2007-775f-9d2b
Trending
Rank 6 in indexed charts, since 20 Sept 2026. See the ranking →

Charts affected

1,096 by stars
ChartLatestAffected imagesRadar Score
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,641
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,895
substra-frontendsubstraVerified publisher1.2.31 of 1See more

substra-frontend substra 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

3,036
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,378
flaresolverrsudo-kraken-flaresolverrVerified publisher2.1.41 of 1See more

flaresolverr sudo-kraken-flaresolverr 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

34,113
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

3,466
nginx-chartsuin-nginx0.1.01 of 1See more

nginx-chart suin-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
convert-datasvtechVerified publisher0.13.21 of 3See more

convert-data svtech 0.13.2

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

7,866
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

12,336
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

74,122
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

9,315
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

12,336
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
no fix listed

Open the chart page →

73,688
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed

Open the chart page →

8,460
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

3,375
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

11,436
nginx-charttaeseon-nginx0.1.01 of 1See more

nginx-chart taeseon-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:stablecb92301e719d
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,143
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,382
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
no fix listed
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
no fix listed

Open the chart page →

108,124
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,401
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

11,732
functionstest-helm-chart-hoanganht1k27Verified publisher0.1.11 of 1See more

functions test-helm-chart-hoanganht1k27 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
myfirstcharttest-helm-charts0.2.01 of 1See more

myfirstchart test-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,589
chatqnatest-opea1.0.07 of 11See more

chatqna test-opea 1.0.0

7 of the 11 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/chatqna:1.038c51b791efa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/embedding-tei:1.05c9639de61c1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/reranking-tei:1.0e48613afb191
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/retriever-redis:1.0eb746b263705
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
redis/redis-stack:7.2.0-v91c5f43fddcdd
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

39,817
codegentest-opea1.0.04 of 5See more

codegen test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/codegen:1.058f91683892d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/codegen-ui:1.02bee4eb66f3e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

29,160
codetranstest-opea1.0.04 of 5See more

codetrans test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/codetrans:1.0e2436483b73d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/codetrans-ui:1.03ef121f34610
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

28,889
docsumtest-opea1.0.04 of 5See more

docsum test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/docsum:1.03eaa91849512
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/docsum-ui:1.07f854e9bffaf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
opea/llm-docsum-tgi:1.002f9e8fa5d71
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

29,371
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,277
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,313
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

4,811
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

5,753
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,077
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,290
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

9,736
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,459
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

4,033
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

10,176
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
no fix listed

Open the chart page →

10,154
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

6,003
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

25,588
voyagertibuntu1.2.01 of 1See more

voyager tibuntu 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/aeharding/voyager:latest779759172676
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,965
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

5,683
todoapitodoapi-appVerified publisher0.1.01 of 2See more

todoapi todoapi-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
no fix listed

Open the chart page →

6,916
test0tohlejezkouska0.1.01 of 2See more

test0 tohlejezkouska 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,435
apptreenityVerified publisher0.1.531 of 2See more

app treenity 0.1.53

1 of the 2 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,268
treenitytreenityVerified publisher0.1.31 of 4See more

treenity treenity 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,782
openunison-operatortremolo3.0.311 of 1See more

openunison-operator tremolo 3.0.31

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.1392bd6c526c50
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,058
orchestratremolo3.1.562 of 5See more

orchestra tremolo 3.1.56

2 of the 5 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.51128081dae281
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
ghcr.io/openunison/openunison-kubernetes-operator:1.0.1392bd6c526c50
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

3,104
orchestra-login-portaltremolo2.3.981 of 1See more

orchestra-login-portal tremolo 2.3.98

1 of the 1 container images this version deploys carry CVE-2026-76781.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
libxml2@2.9.13+dfsg-1ubuntu0.9
no fix listed

Open the chart page →

3,070

Container images carrying it

906 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.