CVE-2026-86139
MediumAdvisory
Published 5 Sept 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.9
- base score, highest
- EPSS
- 0.001
- 1st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,055
- of 17,790 indexed, latest versions
- Container images
- 857
- deployed by those charts
- Fix available
- None
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 1,055 of 17,790 indexed charts deploy, on 857 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| libxml2deb | 2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+55 more | no fix listed | 857 |
- OSV records
- DEBIAN-CVE-2026-86139UBUNTU-CVE-2026-86139
- Trending
- Rank 39 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
1,055 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,697 |
| nginx-chartxxoznge-nginx | 0.1.0 | 1 of 1See more | 1,849 |
| my-nginx-appyasser-nginx-app | 0.1.0 | 1 of 1See more | 1,849 |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,849 |
| zoo-project-druzoo-projectOfficialVerified publisher | 0.10.4 | 1 of 6See more | 7,929 |
Container images carrying it
857 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | c6a934439421 | libxml2 | no fix listed | 1 |
| quay.io/ | e0d9b93dbf2b | libxml2 | no fix listed | 1 |
| registry.gitlab.com/ | 166a06f73d8c | libxml2 | no fix listed | 1 |
| registry.gitlab.com/ | 66353ce9bf98 | libxml2 | no fix listed | 1 |
| registry.gitlab.com/ | 0e3cd8c7776d | libxml2 | no fix listed | 1 |
| registry.gitlab.com/ | f6385712935f | libxml2 | no fix listed | 1 |
| registry.gitlab.com/ | d76185d7270d | libxml2 | no fix listed | 1 |