StackRadar

CVE-2026-86140

High

Advisory

Published 5 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,056
of 17,787 indexed, latest versions
Container images
856
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,056 of 17,787 indexed charts deploy, on 856 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+56 more2.12.7+dfsg+really2.9.14-2.1+deb13u3+e1856
OSV records
DEBIAN-CVE-2026-86140UBUNTU-CVE-2026-86140ECHO-a8a9-016d-71e9
Trending
Rank 23 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,056 by stars
ChartLatestAffected imagesRadar Score
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

8,767
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

9,753
matrixzekker6Verified publisher3.30.01 of 4See more

matrix zekker6 3.30.0

1 of the 4 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.160.078de1d10bef0
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,568
changedetectionalekcVerified publisher0.14.41 of 1See more

changedetection alekc 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

2,448
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed

Open the chart page →

1,245
limesurveyarea-42Verified publisher0.3.942 of 2See more

limesurvey area-42 0.3.94

2 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
adamzammit/limesurvey:7.1.0f48962e1528c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

4,678
thingsboardcetic0.1.21 of 2See more

thingsboard cetic 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
thingsboard/tb-postgres:latest2d17e4e36edc
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed

Open the chart page →

5,243
clowardenclowarden0.2.31 of 4See more

clowarden clowarden 0.2.3

1 of the 4 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed

Open the chart page →

5,620
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

17,475
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

27,984
crossviewcrossviewOfficialVerified publisher4.6.01 of 2See more

crossview crossview 4.6.0

1 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,803
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

9,348
defectdojodefectdojo1.9.521 of 4See more

defectdojo defectdojo 1.9.52

1 of the 4 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
defectdojo/defectdojo-django:3.3.100c597abdbb535
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,340
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed

Open the chart page →

22,812
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

10,652
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

14,001
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
no fix listed

Open the chart page →

9,666
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

10,676
gitvotegitvoteVerified publisher1.5.01 of 6See more

gitvote gitvote 1.5.0

1 of the 6 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u1
no fix listed

Open the chart page →

5,627
terrariahalkeye0.4.21 of 2See more

terraria halkeye 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ryshe/terraria:latestb1c89f7f359a
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed

Open the chart page →

4,154
netbirdhelmforgeVerified publisher1.0.101 of 4See more

netbird helmforge 1.0.10

1 of the 4 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

3,012
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

10,563
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

30,920
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
libxml2@2.9.14+dfsg-1.3ubuntu3
no fix listed

Open the chart page →

4,357
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

4,546
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
no fix listed

Open the chart page →

7,375
webdavk8s-webdavVerified publisher0.0.71 of 1See more

webdav k8s-webdav 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/httpd:2.4979c38c2228d
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,693
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
libxml2@2.9.10+dfsg-5ubuntu0.20.04.10
no fix listed

Open the chart page →

11,630
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
no fix listed

Open the chart page →

15,345
memgraph-high-availabilitymemgraphVerified publisher1.4.11 of 2See more

memgraph-high-availability memgraph 1.4.1

1 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.1bd3fe13228f4
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

1,208
kubecostmesosphere-stable0.37.51 of 9See more

kubecost mesosphere-stable 0.37.5

1 of the 9 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

17,755
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.042a8200d3597
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed

Open the chart page →

4,066
observalobservalVerified publisher1.13.12 of 8See more

observal observal 1.13.1

2 of the 8 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
ghcr.io/observal/observal-api:1.13.1153b8b893232
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

5,839
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
no fix listed

Open the chart page →

107,899
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed

Open the chart page →

3,334
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

2,613
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

5,079
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

13,615
nominatimrobjuz6.4.12 of 4See more

nominatim robjuz 6.4.1

2 of the 4 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
mediagis/nominatim:5.3.27923a8e67197
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed

Open the chart page →

8,760
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed

Open the chart page →

24,549
lldapself-hosters-by-nightVerified publisher0.5.21 of 2See more

lldap self-hosters-by-night 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed

Open the chart page →

3,412
spartanspartan0.9.11 of 1See more

spartan spartan 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,839
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed

Open the chart page →

7,064
pretixtechwolf12Verified publisher2026.7.02 of 3See more

pretix techwolf12 2026.7.0

2 of the 3 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
pretix/standalone:2026.7.05df3b7aa852e
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

9,825
crossplaneupbound-stable2.4.0-up.11 of 5See more

crossplane upbound-stable 2.4.0-up.1

1 of the 5 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,638
vrijbrpvrijbrpVerified publisher0.1.51 of 5See more

vrijbrp vrijbrp 0.1.5

1 of the 5 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

8,823
wgerwgerOfficialVerified publisher1.0.03 of 8See more

wger wger 1.0.0

3 of the 8 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
library/postgres:15.186eb0add3b77c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
wger/server:2.6997ead43aabd
libxml2@2.9.14+dfsg-1.3ubuntu3.7
no fix listed

Open the chart page →

8,587
windmillwindmill4.0.2631 of 3See more

windmill windmill 4.0.263

1 of the 3 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

1,638
paperlesszekker6Verified publisher11.8.01 of 1See more

paperless zekker6 11.8.0

1 of the 1 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

4,644
paperless-ngxadnoctemVerified publisher0.4.22 of 5See more

paperless-ngx adnoctem 0.4.2

2 of the 5 container images this version deploys carry CVE-2026-86140.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed

Open the chart page →

19,769

Container images carrying it

856 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.