StackRadar

CVE-2026-77214

Unscored

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
768
of 18,035 indexed, latest versions
Container images
638
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 768 of 18,035 indexed charts deploy, on 638 images.

Affected packageAffected versionsFixed inImages
expatdeb2.5.0-1, 2.5.0-1+deb12u1, 2.5.0-1+deb12u2, 2.5.0-1+deb12u3+6 moreno fix listed638
OSV records
DEBIAN-CVE-2026-77214
Trending
Rank 36 in indexed charts, since 6 Oct 2026. See the ranking →

Charts affected

768 by stars
ChartLatestAffected imagesRadar Score
aih-scannerwallarmVerified publisher2.9.01 of 2See more

aih-scanner wallarm 2.9.0

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.9.0b39795d50e83
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,296
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

6,436
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
expat@2.5.0-1
no fix listed

Open the chart page →

7,625
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
expat@2.5.0-1
no fix listed

Open the chart page →

10,984
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,145
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

11,185
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

11,185
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
expat@2.5.0-1
no fix listed

Open the chart page →

5,831
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/wordpress:latest8746e7e072e3
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

5,595
wordpresswordpress-ng1.0.101 of 2See more

wordpress wordpress-ng 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
cloudtooling/wordpress:7.1.20b390e7e3425
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

4,463
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
expat@2.5.0-1
no fix listed

Open the chart page →

8,553
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

15,306
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,855
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,855
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

3,145
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

2,932
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
library/nginx:latestf9ea18bfa4fa
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,655
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77214.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
expat@2.5.0-1+deb12u3
no fix listed

Open the chart page →

5,028

Container images carrying it

638 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/airflow:2.8.4-python3.964e58748b6b9
expat@2.5.0-1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
expat@2.5.0-1+deb12u1
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
expat@2.5.0-1
no fix listed
1
apache/druid:29.0.10cef139b6bf1
expat@2.5.0-1
no fix listed
1
apache/superset:4.0.1ab9467fd712c
expat@2.5.0-1
no fix listed
1
appwrite/new:1.1.159-self-hosted1811ce1d8154
expat@2.8.3-1~deb13u1
no fix listed
1
arbuzov/claude-code-api:0.1.02d7dd8070610
expat@2.5.0-1+deb12u1
no fix listed
1
archivebox/archivebox:0.9.708c21bb233130
expat@2.8.3-1~deb13u1
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
expat@2.5.0-1
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
expat@2.5.0-1
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
expat@2.5.0-1
no fix listed
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
expat@2.5.0-1
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
expat@2.5.0-1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
expat@2.5.0-1
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
expat@2.5.0-1
no fix listed
1
avzini/web-app:latestf40b30210ed0
expat@2.5.0-1
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
expat@2.5.0-1+deb12u1
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
expat@2.5.0-1+deb12u1
no fix listed
1
berkeleyskypilot/skypilot:0.14.0a8362d205365
expat@2.8.3-1~deb13u1
no fix listed
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
expat@2.7.1-2
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.301249fc292e84
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.3164614ef8290f
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
expat@2.5.0-1+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
expat@2.5.0-1
no fix listed
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
expat@2.5.0-1+deb12u1
no fix listed
1
blackducksoftware/bdba-frontend:2026.9.10afa8763ccb8
expat@2.8.3-1~deb13u1
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
expat@2.5.0-1+deb12u1
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
expat@2.5.0-1+deb12u1
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
expat@2.5.0-1+deb12u1
no fix listed
1
boky/postfix:5.1.0:v5.1.0aafc77238423
expat@2.7.1-2
no fix listed
1
boky/postfix:4.4.0f3f247fd4252
expat@2.5.0-1+deb12u1
no fix listed
1
buall/postgres-stack:18.6881a785642cb
expat@2.8.3-1~deb13u1
no fix listed
1
budibase/database:2.1.0d90f656261c9
expat@2.5.0-1+deb12u2
no fix listed
1
budibase/proxy:3.41.38d780b6ee602
expat@2.7.1-2
no fix listed
1
calltelemetry/web:0.8.1-rc7205d13269e350
expat@2.5.0-1+deb12u1
no fix listed
1
carbone/carbone-ee:full-5.15.3ed6d19082849
expat@2.8.3-1~deb13u1
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
expat@2.5.0-1+deb12u1
no fix listed
1
caronc/apprise:latestcc5ef662ad2a
expat@2.8.3-1~deb13u1
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
expat@2.5.0-1+deb12u1
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
expat@2.7.1-2
no fix listed
1
cccs/assemblyline-core:4.7.4.stable2125fdf4aa72ab
expat@2.5.0-1+deb12u3
no fix listed
1
cccs/assemblyline-rust:4.7.4.stable21871423aa4655
expat@2.5.0-1+deb12u3
no fix listed
1
cccs/assemblyline-socketio:4.7.4.stable21ba390e87f340
expat@2.5.0-1+deb12u3
no fix listed
1
cccs/assemblyline-ui:4.7.4.stable210623c3fd039e
expat@2.5.0-1+deb12u3
no fix listed
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
expat@2.8.3-1~deb13u1
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
expat@2.7.1-2
no fix listed
1
ckulka/baikal:0.10.1-nginx434bdd162247
expat@2.5.0-1+deb12u1
no fix listed
1
cloudtooling/moodle:5.3.0.2d3e3607acf56
expat@2.5.0-1+deb12u4
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.