StackRadar

CVE-2026-86137

Low

Advisory

Published 5 Sept 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,043
of 17,787 indexed, latest versions
Container images
842
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,043 of 17,787 indexed charts deploy, on 842 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+56 more2.12.7+dfsg+really2.9.14-2.1+deb13u3+e1842
OSV records
DEBIAN-CVE-2026-86137UBUNTU-CVE-2026-86137ECHO-0081-3031-f882
Trending
Rank 40 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,043 by stars
ChartLatestAffected imagesRadar Score
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

10,072
hawkhawk1.1.51 of 4See more

hawk hawk 1.1.5

1 of the 4 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,610
hello-helmhellok8s0.1.01 of 2See more

hello-helm hellok8s 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,000
guacamolehelmforgeVerified publisher1.5.23 of 5See more

guacamole helmforge 1.5.2

3 of the 5 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed
library/postgres:18.6-trixie4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
library/postgres:17.5-bookwormfbcea1bd13b6
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

8,716
matomohelmforgeVerified publisher2.3.01 of 3See more

matomo helmforge 2.3.0

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/matomo:5.13.0-apache8e6bdd396496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,680
mywebapphelm-nginxVerified publisher0.1.01 of 1See more

mywebapp helm-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,827
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
libxml2@2.9.13+dfsg-1ubuntu0.7
no fix listed

Open the chart page →

12,397
backendikusi-bk-chart1.0.31 of 3See more

backend ikusi-bk-chart 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,940
odooimioVerified publisher3.0.21 of 3See more

odoo imio 3.0.2

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:17.10ebba4f4de37f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,068
immichimmich-helm0.3.03 of 4See more

immich immich-helm 0.3.0

3 of the 4 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

15,712
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed

Open the chart page →

11,764
jellyfinjellyfinVerified publisher0.3.301 of 1See more

jellyfin jellyfin 0.3.30

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,604
web-chartkbt-ktcloudlab0.1.01 of 1See more

web-chart kbt-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,827
app-componentkeltio-helm-chartsVerified publisher3.14.01 of 1See more

app-component keltio-helm-charts 3.14.0

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,827
kikplatekikplateVerified publisher0.22.01 of 3See more

kikplate kikplate 0.22.0

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,770
glpikitsune-itopsVerified publisher1.0.71 of 3See more

glpi kitsune-itops 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
glpi/glpi:latest4b681082a79e
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,802
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

20,403
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
libxml2@2.9.13+dfsg-1ubuntu0.11
no fix listed

Open the chart page →

9,858
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

12,422
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

113,791
ohifkylesferrazzaVerified publisher0.1.01 of 2See more

ohif kylesferrazza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
jodogne/orthanc-plugins:latest6ff510aa29c2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,512
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

3,544
checkoutlabs64io-helm-chartsVerified publisher0.8.01 of 3See more

checkout labs64io-helm-charts 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,626
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,657
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

3,980
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

35,050
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

7,201
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

6,136
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,734
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,753
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
libxml2@2.9.14+dfsg-1.3ubuntu3
no fix listed

Open the chart page →

4,137
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,738
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
library/redmine:6.1.204ac44a2595b
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

7,527
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,827
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,827
spring-helmnaveenalla-springboot1.0.01 of 2See more

spring-helm naveenalla-springboot 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,626
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,827
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

14,250
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,039
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,827
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxml2@2.9.14+dfsg-1.2
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

14,838
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,779
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

22,420
opsopsVerified publisher1.2.01 of 2See more

ops ops 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
shaowenchen/ops-server:latest315444f703f4
libxml2@2.9.13+dfsg-1ubuntu0.9
no fix listed

Open the chart page →

8,939
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,681
paperless-ngxpaperlessVerified publisher0.4.02 of 3See more

paperless-ngx paperless 0.4.0

2 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

8,489
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

7,035
playgroundplayground0.1.11 of 1See more

playground playground 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,827
matomopockostVerified publisher1.3.01 of 3See more

matomo pockost 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
pockost/matomo:5.13.07f5d293cbe4e
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,047
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-86137.

Container imageDigestPackageFixed in
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

31,844

Container images carrying it

842 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/aeharding/voyager:latest779759172676
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
no fix listed
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/caninehq/canine:latesta058034ca006
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/damap-org/damap-frontend:5.0.1609f48af4efc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed
1
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.