StackRadar

CVE-2026-77214

Unscored

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
779
of 18,026 indexed, latest versions
Container images
648
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 779 of 18,026 indexed charts deploy, on 648 images.

Affected packageAffected versionsFixed inImages
expatdeb2.5.0-1, 2.5.0-1+deb12u1, 2.5.0-1+deb12u2, 2.5.0-1+deb12u3+7 moreno fix listed648
OSV records
DEBIAN-CVE-2026-77214
Trending
Rank 36 in indexed charts, since 6 Oct 2026. See the ranking →

Charts affected

779 by stars
ChartLatestAffected imagesRadar Score
trident-protect-consoletrident-protect100.2609.0-console1 of 3See more

trident-protect-console trident-protect 100.2609.0-console

1 of the 3 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v3.0.0cad26cd945d1
expat@2.8.2-1~deb13u1
no fix listed

Open the chart page →

7,054
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
expat@2.5.0-1
no fix listed

Open the chart page →

19,431
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

9,728
applicationuniversal-helm-chartVerified publisher0.4.51 of 1See more

application universal-helm-chart 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,855
unlaunla0.10.01 of 3See more

unla unla 0.10.0

1 of the 3 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
ghcr.io/amoylab/unla/web:latesteac1df1c5e66
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

10,392
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
expat@2.5.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
expat@2.5.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
expat@2.5.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
expat@2.5.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
expat@2.5.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

48,037
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
expat@2.5.0-1
no fix listed

Open the chart page →

15,159
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
expat@2.8.2-1~deb13u1
no fix listed

Open the chart page →

2,257
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

11,567
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

2,239
argus-test-envvk-helm-charts2.0.01 of 1See more

argus-test-env vk-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,855
aih-scannerwallarmVerified publisher2.9.01 of 2See more

aih-scanner wallarm 2.9.0

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.9.0b39795d50e83
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,296
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

6,436
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
expat@2.5.0-1
no fix listed

Open the chart page →

7,625
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
expat@2.5.0-1
no fix listed

Open the chart page →

10,984
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,145
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

11,185
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

11,185
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
expat@2.5.0-1
no fix listed

Open the chart page →

5,831
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/wordpress:latest8746e7e072e3
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

5,595
wordpresswordpress-ng1.0.101 of 2See more

wordpress wordpress-ng 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
cloudtooling/wordpress:7.1.20b390e7e3425
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

4,463
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

8,553
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

15,306
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,855
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,855
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,145
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

2,932
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:latestf9ea18bfa4fa
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,655
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

5,028

Container images carrying it

648 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/nginx:1.27.098f8ec75657d
expat@2.5.0-1
no fix listed
2
library/nginx:1.29.49dd288848f44
expat@2.7.1-2
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
expat@2.5.0-1+deb12u1
no fix listed
2
library/python:3.7eedf63967cdb
expat@2.5.0-1
no fix listed
2
library/redmine:6.1.3-trixief474a901faec
expat@2.8.3-1~deb13u1
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
expat@2.7.1-2
no fix listed
2
library/wordpress:latest8746e7e072e3
expat@2.8.3-1~deb13u1
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
expat@2.5.0-1+deb12u2
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
expat@2.5.0-1+deb12u2
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
expat@2.5.0-1+deb12u2
no fix listed
2
louislam/uptime-kuma:2.5.5c74379ac4509
expat@2.5.0-1+deb12u2
no fix listed
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
expat@2.5.0-1
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
expat@2.5.0-1
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
expat@2.5.0-1
no fix listed
2
nginxinc/nginx-unprivileged:stable0918d093d608
expat@2.8.3-1~deb13u1
no fix listed
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
expat@2.8.3-1~deb13u1
no fix listed
2
nutanix/nai-jobs:v2.8.0:v2.8.19c373718e1b1
expat@2.8.3-1~deb13u1
no fix listed
2
obolnetwork/charon:v1.10.0278c7e2897b6
expat@2.7.1-2
no fix listed
2
opea/embedding-tei:1.05c9639de61c1
expat@2.5.0-1
no fix listed
2
opea/reranking-tei:1.0e48613afb191
expat@2.5.0-1
no fix listed
2
opea/retriever-redis:1.0eb746b263705
expat@2.5.0-1
no fix listed
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
expat@2.5.0-1+deb12u1
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
expat@2.5.0-1+deb12u1
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
expat@2.5.0-1+deb12u1
no fix listed
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
expat@2.5.0-1+deb12u1
no fix listed
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
expat@2.5.0-1+deb12u1
no fix listed
2
opencsghq/label-studio:v2.5.047e22aa71870
expat@2.8.3-1~deb13u1
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
expat@2.5.0-1
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
expat@2.5.0-1
no fix listed
2
uffizzi/controller:latest0344805f267b
expat@2.5.0-1
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
expat@2.5.0-1
no fix listed
2
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
expat@2.8.2-1~deb13u1
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
expat@2.5.0-1+deb12u2
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
expat@2.5.0-1
no fix listed
2
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
expat@2.5.0-1+deb12u2
no fix listed
2
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
expat@2.7.1-2
no fix listed
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
expat@2.5.0-1+deb12u3
no fix listed
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
expat@2.5.0-1+deb12u1
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
expat@2.5.0-1+deb12u2
no fix listed
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
expat@2.5.0-1+deb12u2
no fix listed
2
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
expat@2.5.0-1+deb12u2
no fix listed
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
expat@2.7.1-2
no fix listed
1
aboogie/login_test_backend:new9c41a4483ac8
expat@2.5.0-1
no fix listed
1
adamzammit/limesurvey:7.5.0911507d751f8
expat@2.8.3-1~deb13u1
no fix listed
1
agentarea/agentarea-mcp-base:latestcd57c37971a0
expat@2.5.0-1+deb12u3
no fix listed
1
agentarea/agentarea-mcp-runner:latest9030cc19a0fc
expat@2.5.0-1+deb12u3
no fix listed
1
airbyte/manifest-server:7.28.2deec511b51c3
expat@2.5.0-1+deb12u2
no fix listed
1
airbyte/pod-sweeper:1.5.198d2c39d512e
expat@2.5.0-1+deb12u1
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
expat@2.5.0-1
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
expat@2.5.0-1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.