StackRadar

CVE-2026-86138

Medium

Advisory

Published 5 Sept 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,043
of 17,787 indexed, latest versions
Container images
842
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,043 of 17,787 indexed charts deploy, on 842 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+56 more2.12.7+dfsg+really2.9.14-2.1+deb13u3+e1842
OSV records
DEBIAN-CVE-2026-86138UBUNTU-CVE-2026-86138ECHO-76d1-f392-809f
Trending
Rank 28 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,043 by stars
ChartLatestAffected imagesRadar Score
nextcloudnextcloud9.2.61 of 1See more

nextcloud nextcloud 9.2.6

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3-apacheb97df9e0e1ee
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,507
giteagiteaOfficialVerified publisher12.7.02 of 4See more

gitea gitea 12.7.0

2 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

8,811
authentikgoauthentikOfficialVerified publisher2026.8.21 of 1See more

authentik goauthentik 2026.8.2

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,257
nginx-ingressnginxVerified publisher2.7.11 of 1See more

nginx-ingress nginx 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
nginx/nginx-ingress:5.6.18ca7b42ae702
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,285
artifact-hubartifact-hubVerified publisher1.23.01 of 7See more

artifact-hub artifact-hub 1.23.0

1 of the 7 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed

Open the chart page →

10,755
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

7,894
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

30,159
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

11,367
falcofalcosecurity9.1.01 of 3See more

falco falcosecurity 9.1.0

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

5,227
apisixapisix2.17.01 of 3See more

apisix apisix 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
apache/apisix:3.18.0-ubuntu9ee5df1611f9
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

3,045
zabbixzabbix-communityVerified publisher7.1.04 of 5See more

zabbix zabbix-community 7.1.0

4 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed

Open the chart page →

13,664
keycloakcloudpirates-keycloakVerified publisher0.21.372 of 3See more

keycloak cloudpirates-keycloak 0.21.37

2 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed
library/postgres:18.64ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,382
netdatanetdataVerified publisher3.7.1731 of 1See more

netdata netdata 3.7.173

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.0c45c71eb23ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,092
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

5,366
netboxnetboxOfficialVerified publisher8.3.751See more

netbox netbox 8.3.75

1 container image this version deploys carries CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/netbox-community/netbox:v4.7.01685e91c61bb
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

postgrescloudpirates-postgresVerified publisher0.20.51 of 1See more

postgres cloudpirates-postgres 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,626
zammadzammadOfficialVerified publisher18.2.02See more

zammad zammad 18.2.0

2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

6,342
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

32,259
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

10,622
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

4,314
weblateweblateOfficialVerified publisher0.5.362 of 3See more

weblate weblate 0.5.36

2 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
weblate/weblate:2026.9.1.0990720d1737a
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

6,699
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,626
difydoubanVerified publisher0.10.02 of 6See more

dify douban 0.10.0

2 of the 6 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libxml2@2.9.14+dfsg-1.3ubuntu3.6
no fix listed

Open the chart page →

19,391
dragonflydragonflyVerified publisher1.8.41 of 3See more

dragonfly dragonfly 1.8.4

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.4a1b52779c4dd
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

3,787
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed

Open the chart page →

3,606
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,927
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

22,002
yourlsyourlsOfficialVerified publisher8.9.111 of 2See more

yourls yourls 8.9.11

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.69b220ea83329
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,203
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,022
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.03 of 5See more

openproject openproject-helm-charts 13.11.0

3 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
openproject/hocuspocus:release-338001b288dc1359dfb5
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
openproject/openproject:17.8.0-slim48952034215d
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

19,926
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

11,384
zabbixcetic3.1.35 of 5See more

zabbix cetic 3.1.3

5 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

33,725
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,543
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

5,987
litellm-helmlitellm1.101.01See more

litellm-helm litellm 1.101.0

1 container image this version deploys carries CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

9,683
oneuptimeoneuptimeOfficialVerified publisher13.0.43 of 7See more

oneuptime oneuptime 13.0.4

3 of the 7 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
oneuptime/probe:release6b2d98713711
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
oneuptime/runner:release4accc516d800
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

11,192
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

7,880
milvusmilvus-helm5.0.281See more

milvus milvus-helm 5.0.28

1 container image this version deploys carries CVE-2026-86138.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

prefect-serverprefectVerified publisher2026.9.141419101See more

prefect-server prefect 2026.9.14141910

1 container image this version deploys carries CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed

Open the chart page →

18,509
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,685
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

1,115
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2api:3.86f56d239d280
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2auth:3.833ecfda16608
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2notifier:3.8f190a6212195
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed

Open the chart page →

96,419
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
budibase/proxy:3.41.38d780b6ee602
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

10,775
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

3,074
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

2,977
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

11,405
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

2,938

Container images carrying it

842 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
libxml2@2.9.10+dfsg-5ubuntu0.20.04.7
no fix listed
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/yourls/yourls:1.10.69b220ea83329
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
no fix listed
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
no fix listed
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
libxml2@2.9.4+dfsg1-6.1ubuntu1.9
no fix listed
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2+e6
2.12.7+dfsg+really2.9.14-2.1+deb13u3+e1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libxml2@2.9.10+dfsg-5
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.