StackRadar

CVE-2026-86138

Medium

Advisory

Published 5 Sept 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,056
of 17,787 indexed, latest versions
Container images
856
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,056 of 17,787 indexed charts deploy, on 856 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+56 more2.12.7+dfsg+really2.9.14-2.1+deb13u3+e1856
OSV records
DEBIAN-CVE-2026-86138UBUNTU-CVE-2026-86138ECHO-76d1-f392-809f
Trending
Rank 30 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,056 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

7,685
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-86138.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed

Open the chart page →

7,916

Container images carrying it

856 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mathesar/mathesar:0.12.0091757cb01fe
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
matrixdotorg/synapse:v1.160.078de1d10bef0
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
mbround18/valheim:3.1.070bd4da591cd
libxml2@2.9.13+dfsg-1ubuntu0.6
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
middlewareeng/middleware:0.3.1747d880812f1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mindsdb/mindsdb:latest163011c09299
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/camera-viewer:lateste418cc694bd5
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
moreillon/group-manager-front:latest5f0a38498271
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
moreillon/user-manager-front:v5.1.06597e6b98d21
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
no fix listed
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed
1
netdata/netdata:v2.11.0c45c71eb23ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libxml2@2.9.3+dfsg1-1ubuntu0.6
no fix listed
1
nginxinc/nginx-unprivileged:latest4210a3296e7c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
nginx/nginx-ingress:edge520d439f9a9a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
nginx/nginx-ingress:5.6.18ca7b42ae702
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
nirmalnaveen/supermario:latest8541a39162f3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
no fix listed
1
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
libxml2@2.9.3+dfsg1-1ubuntu0.5
no fix listed
1
omecproject/openmme:master-latest64776cb9edb3
libxml2@2.9.3+dfsg1-1ubuntu0.7
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
libxml2@2.9.3+dfsg1-1ubuntu0.6
no fix listed
1
oneuptime/probe:release6b2d98713711
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
oneuptime/runner:release4accc516d800
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
onyxdotapp/onyx-backend:latest473fdffe4e67
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
libxml2@2.9.3+dfsg1-1ubuntu0.2
no fix listed
1
opea/chatqna:1.038c51b791efa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/codegen:1.058f91683892d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.