StackRadar

CVE-2026-77214

High

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,497
of 18,053 indexed, latest versions
Container images
1,316
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,497 of 18,053 indexed charts deploy, on 1,316 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+45 more2.8.4-2+e31,316
OSV records
DEBIAN-CVE-2026-77214ECHO-c50c-9d1f-aedbUBUNTU-CVE-2026-77214
Trending
Rank 1 in indexed charts, since 6 Oct 2026. See the ranking →

Charts affected

1,497 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,316 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
sslhep/servicex_app:v1.8.6c935e123030d
expat@2.8.3-1~deb13u1
no fix listed
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.67827e689caa5
expat@2.8.3-1~deb13u1
no fix listed
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.62d6843be2d8d
expat@2.8.3-1~deb13u1
no fix listed
1
sslhep/servicex_code_gen_python:v1.8.696805be717ff
expat@2.8.3-1~deb13u1
no fix listed
1
sslhep/servicex_code_gen_raw_uproot:v1.8.61494a81a474b
expat@2.8.3-1~deb13u1
no fix listed
1
sslhep/servicex_code_gen_topcp:v1.8.6f7faf8c6c3e4
expat@2.8.3-1~deb13u1
no fix listed
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.6bd738c952e72
expat@2.8.3-1~deb13u1
no fix listed
1
sslhep/servicex-did-finder-cernopendata:v1.8.623a80e40ab18
expat@2.8.3-1~deb13u1
no fix listed
1
sslhep/servicex-did-finder-xrootd:v1.8.69a9fb17458f1
expat@2.8.3-1~deb13u1
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2api:3.86f56d239d280
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2auth:3.833ecfda16608
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2notifier:3.8f190a6212195
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2rulesengine:3.8259503496ff9
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2scheduler:3.8b1de2055c362
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2stream:3.81c8904a3bf67
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
expat@2.2.9-1ubuntu0.6
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
expat@2.2.9-1ubuntu0.6
no fix listed
1
stashapp/stash:latest24dbd7607174
expat@2.2.9-1build1
no fix listed
1
stashapp/stash-box:latesta534c8afdf39
expat@2.6.1-2ubuntu0.3
no fix listed
1
statcan/ckan:2.93921305425b8
expat@2.2.9-1build1
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
expat@2.2.9-1build1
no fix listed
1
structurizr/onpremises:2025.11.094b5ffb5119c8
expat@2.6.1-2ubuntu0.3
no fix listed
1
substratusai/verba:v0.4.0-baseURL261695be635eb
expat@2.5.0-1
no fix listed
1
supabase/realtime:latest7a6d995635f7
expat@2.7.1-2
no fix listed
1
supabase/realtime:v2.102.3aa1c92c0cf32
expat@2.5.0-1+deb12u2
no fix listed
1
supabase/studio:20241021-9f9b08326d8070c55e9
expat@2.5.0-1+deb12u1
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
expat@2.5.0-1+deb12u2
no fix listed
1
supabase/studio:latestfdb56cfa1705
expat@2.5.0-1+deb12u3
no fix listed
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
expat@2.4.7-1ubuntu0.3
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
expat@2.2.9-1ubuntu0.6
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
expat@2.5.0-1
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
expat@2.2.9-1ubuntu0.6
no fix listed
1
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
expat@2.5.0-1+deb12u3
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
expat@2.4.7-1ubuntu0.7
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
expat@2.5.0-1+deb12u1
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
expat@2.5.0-1+deb12u1
no fix listed
1
tchiotludo/akhq:0.28.0c2824dc2ae44
expat@2.7.4-1
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
expat@2.5.0-1
no fix listed
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
1
tenureai/tenure:v1.0.285f5b222df9a5
expat@2.7.1-2+dhi4
no fix listed
1
themoah/klag:0.2.187178531ebe86
expat@2.6.1-2ubuntu0.6
no fix listed
1
theradius/loggia:0.463ba348546ec
expat@2.5.0-1
no fix listed
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
expat@2.7.1-2
no fix listed
1
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
expat@2.7.1-2
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
expat@2.5.0-1+deb12u2
no fix listed
1
thongngo3301/stakefish:latesta341af5976e3
expat@2.5.0-1
no fix listed
1
tianon/exim4:latest8eeab7cc5efe
expat@2.8.3-1~deb13u1
no fix listed
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.