StackRadar

CVE-2026-86138

Medium

Advisory

Published 5 Sept 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,053
of 17,781 indexed, latest versions
Container images
852
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,053 of 17,781 indexed charts deploy, on 852 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+56 more2.12.7+dfsg+really2.9.14-2.1+deb13u3+e1852
OSV records
DEBIAN-CVE-2026-86138UBUNTU-CVE-2026-86138ECHO-76d1-f392-809f
Trending
Rank 28 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,053 by stars
ChartLatestAffected imagesRadar Score
nextcloudnextcloud9.2.61 of 1See more

nextcloud nextcloud 9.2.6

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3-apacheb97df9e0e1ee
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,507
giteagiteaOfficialVerified publisher12.7.02 of 4See more

gitea gitea 12.7.0

2 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

8,811
authentikgoauthentikOfficialVerified publisher2026.8.21 of 1See more

authentik goauthentik 2026.8.2

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,257
nginx-ingressnginxVerified publisher2.7.11 of 1See more

nginx-ingress nginx 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
nginx/nginx-ingress:5.6.18ca7b42ae702
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,285
artifact-hubartifact-hubVerified publisher1.23.01 of 7See more

artifact-hub artifact-hub 1.23.0

1 of the 7 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed

Open the chart page →

10,755
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

7,894
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

30,159
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

11,367
falcofalcosecurity9.1.01 of 3See more

falco falcosecurity 9.1.0

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

5,227
apisixapisix2.17.01 of 3See more

apisix apisix 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
apache/apisix:3.18.0-ubuntu9ee5df1611f9
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

3,045
zabbixzabbix-communityVerified publisher7.1.04 of 5See more

zabbix zabbix-community 7.1.0

4 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed

Open the chart page →

13,664
keycloakcloudpirates-keycloakVerified publisher0.21.372 of 3See more

keycloak cloudpirates-keycloak 0.21.37

2 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed
library/postgres:18.64ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,382
netdatanetdataVerified publisher3.7.1731 of 1See more

netdata netdata 3.7.173

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.0c45c71eb23ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,092
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

5,366
netboxnetboxOfficialVerified publisher8.3.741 of 5See more

netbox netbox 8.3.74

1 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/netbox-community/netbox:v4.7.01685e91c61bb
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

1,015
postgrescloudpirates-postgresVerified publisher0.20.51 of 1See more

postgres cloudpirates-postgres 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,626
zammadzammadOfficialVerified publisher18.0.52 of 5See more

zammad zammad 18.0.5

2 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

6,887
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

6,342
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

32,259
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

10,622
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

4,314
weblateweblateOfficialVerified publisher0.5.362 of 3See more

weblate weblate 0.5.36

2 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
weblate/weblate:2026.9.1.0990720d1737a
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

6,699
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,626
difydoubanVerified publisher0.10.02 of 6See more

dify douban 0.10.0

2 of the 6 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libxml2@2.9.14+dfsg-1.3ubuntu3.6
no fix listed

Open the chart page →

19,391
dragonflydragonflyVerified publisher1.8.41 of 3See more

dragonfly dragonfly 1.8.4

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.4a1b52779c4dd
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

3,787
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed

Open the chart page →

3,606
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,927
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

22,002
yourlsyourlsOfficialVerified publisher8.9.111 of 2See more

yourls yourls 8.9.11

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.69b220ea83329
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,203
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,022
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.03 of 5See more

openproject openproject-helm-charts 13.11.0

3 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
openproject/hocuspocus:release-338001b288dc1359dfb5
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
openproject/openproject:17.8.0-slim48952034215d
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

19,926
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

11,384
zabbixcetic3.1.35 of 5See more

zabbix cetic 3.1.3

5 of the 5 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

33,725
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

6,543
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

5,987
litellm-helmlitellm1.100.11 of 2See more

litellm-helm litellm 1.100.1

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,003
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

9,683
oneuptimeoneuptimeOfficialVerified publisher13.0.43 of 7See more

oneuptime oneuptime 13.0.4

3 of the 7 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
oneuptime/probe:release6b2d98713711
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
oneuptime/runner:release4accc516d800
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

11,192
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

7,880
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

10,670
prefect-serverprefectVerified publisher2026.9.32126051 of 2See more

prefect-server prefect 2026.9.3212605

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,786
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed

Open the chart page →

18,509
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,685
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

1,115
memgraphmemgraphVerified publisher1.0.61 of 2See more

memgraph memgraph 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.0a1dc375774ed
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,373
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2api:3.86f56d239d280
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2auth:3.833ecfda16608
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2notifier:3.8f190a6212195
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed

Open the chart page →

96,419
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
budibase/proxy:3.41.38d780b6ee602
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

10,775
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

3,074
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

2,977
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

11,405

Container images carrying it

852 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pgvector/pgvector:0.8.6-pg16-bookworm:pg16ccc6e83d6e35
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
2
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
2
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed
2
technitium/dns-server:15.4.0df7d90ef0f7b
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
2
wurstmeister/zookeeper:latest7a7fd44a7210
libxml2@2.9.1+dfsg1-3ubuntu4.3
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
libxml2@2.9.14+dfsg-0+ubuntu22.04.1+deb.sury.org+1
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libxml2@2.9.13+dfsg-1ubuntu0.1
no fix listed
2
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
2
ghcr.io/dgtlmoon/changedetection.io:0.60.3:latestecacd9fd0c66
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
2
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
5200710/hadoop:3.2.3-java8092d3088a5fb
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
adamzammit/limesurvey:7.0.15e75e2f455c8d
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
no fix listed
1
airbyte/pod-sweeper:1.5.198d2c39d512e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
libxml2@2.9.14+dfsg-1.2
no fix listed
1
akeyless/base:latest759e4289fae8
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed
1
akeyless/gateway:5.3.13d2e7dce5eb9
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
libxml2@2.9.4+dfsg1-6.1ubuntu1.6
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libxml2@2.9.13+dfsg-1ubuntu0.7
no fix listed
1
anguda/ant-media:2.5c435285fc241
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
no fix listed
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
anujdatar/cups:25.07.01685df04a643b
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
1
apache/airflow:2.8.4-python3.964e58748b6b9
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.