StackRadar

CVE-2026-86140

High

Advisory

Published 5 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,049
of 17,790 indexed, latest versions
Container images
845
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,049 of 17,790 indexed charts deploy, on 845 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+56 more2.12.7+dfsg+really2.9.14-2.1+deb13u3+e1845
OSV records
DEBIAN-CVE-2026-86140UBUNTU-CVE-2026-86140ECHO-a8a9-016d-71e9
Trending
Rank 23 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

1,049 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

845 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mediagis/nominatim:3.7c15e941485ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
libxml2@2.9.13+dfsg-1ubuntu0.3
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
middlewareeng/middleware:0.3.1747d880812f1
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mindsdb/mindsdb:latest163011c09299
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
libxml2@2.9.13+dfsg-1ubuntu0.4
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
libxml2@2.9.14+dfsg-1.3~deb12u6
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/camera-viewer:lateste418cc694bd5
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
libxml2@2.9.14+dfsg-1.3~deb12u5
no fix listed
1
moreillon/group-manager-front:latest5f0a38498271
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
moreillon/user-manager-front:v5.1.06597e6b98d21
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
no fix listed
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
libxml2@2.15.2+dfsg-0.1ubuntu0.1
no fix listed
1
netdata/netdata:v2.11.0c45c71eb23ff
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
libxml2@2.9.13+dfsg-1ubuntu0.12
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libxml2@2.9.3+dfsg1-1ubuntu0.6
no fix listed
1
nginxinc/nginx-unprivileged:latest4210a3296e7c
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u2
no fix listed
1
nginx/nginx-ingress:edge520d439f9a9a
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
nirmalnaveen/supermario:latest8541a39162f3
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
libxml2@2.9.14+dfsg-1.3~deb12u4
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
no fix listed
1
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
libxml2@2.9.3+dfsg1-1ubuntu0.5
no fix listed
1
omecproject/openmme:master-latest64776cb9edb3
libxml2@2.9.3+dfsg1-1ubuntu0.7
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
libxml2@2.9.3+dfsg1-1ubuntu0.6
no fix listed
1
onyxdotapp/onyx-backend:latest473fdffe4e67
libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
no fix listed
1
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
libxml2@2.9.3+dfsg1-1ubuntu0.2
no fix listed
1
opea/chatqna:1.038c51b791efa
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/codegen:1.058f91683892d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/codetrans:1.0e2436483b73d
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/docsum:1.03eaa91849512
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/guardrails-tgi:1.0262c6048aab8
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/guardrails-tgi:latestf68bec6a1271
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1
opea/speecht5:1.0249afad3d268
libxml2@2.9.14+dfsg-1.3~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.