StackRadar

CVE-2026-86140

High

Advisory

Published 5 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,049
of 17,790 indexed, latest versions
Container images
845
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,049 of 17,790 indexed charts deploy, on 845 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+56 more2.12.7+dfsg+really2.9.14-2.1+deb13u3+e1845
OSV records
DEBIAN-CVE-2026-86140UBUNTU-CVE-2026-86140ECHO-a8a9-016d-71e9
Trending
Rank 23 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,049 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

845 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jellyfin/jellyfin:10.11.81694ff069f0c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
jodogne/orthanc-plugins:latest6ff510aa29c2
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
kixote/typemill4e9dff179519
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
kixote/typemill628f79a08cc7
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
kong/kong-ai-gateway:2.0.3367ed5985b76
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
libxml2@2.9.14+dfsg-1.3ubuntu3.3
no fix listed
1
kuzwolka/aws9:main1ad759b961b1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
laly9999/node-app:1dd0e503913e1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
lancachenet/monolithic:latest37f28b362c93
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libxml2@2.9.14+dfsg-1.3ubuntu3.6
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
libxml2@2.9.14+dfsg-1.3ubuntu3.8
no fix listed
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
library/httpd:2.4.631ae8051591a5
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
1
library/matomo:5.1.2-apache2415789e1602
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
library/matomo:5.13.0-apache8e6bdd396496
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
libxml2@2.9.14+dfsg-1.3~deb12u2
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
library/nextcloud:34.0.4-apachede4ad9389386
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
library/nginx:1.27.409369da6b103
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
library/nginx:1.291881968aff6f
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
library/nginx:1.276784fb0834aa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
library/nginx:1.25.167f9a4f10d14
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
library/nginx:1.25.49ff236ed47fe
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.