StackRadar

CVE-2026-93990

High

Advisory

Published 19 Sept 2026In the index since 21 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,459
of 17,832 indexed, latest versions
Container images
1,292
deployed by those charts
Fix available
None
affected packages

CVE-2026-93990 affecting package expat 2.8.3-2

Carried by container images the latest versions of 1,459 of 17,832 indexed charts deploy, on 1,292 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+37 moreno fix listed1,290
expatrpm2.8.2-1.azl3no fix listed2
OSV records
DEBIAN-CVE-2026-93990UBUNTU-CVE-2026-93990AZL-103316ECHO-41d9-8113-ce4d
Trending
Rank 3 in indexed charts, since 21 Sept 2026. See the ranking →

Charts affected

1,459 by stars
ChartLatestAffected imagesRadar Score
aktoakto0.2.02 of 7See more

akto akto 0.2.0

2 of the 7 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-dashboard:latestb53a854bd7c1
expat@2.6.1-2ubuntu0.4
no fix listed
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

13,886
akto-ai-guardrails-v2akto0.3.02 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

2 of the 6 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
expat@2.7.4-1
no fix listed
redis/redis-stack-server:7.4.0-v172035434f455
expat@2.4.7-1ubuntu0.4
no fix listed

Open the chart page →

42,635
akto-central-setupakto1.2.01See more

akto-central-setup akto 1.2.0

1 container image this version deploys carries CVE-2026-93990.

Container imageDigestPackageFixed in
library/eclipse-temurin:2192a2a4d7a928
expat@2.7.4-1
no fix listed

Open the chart page →

akto-dashboardakto0.1.71 of 1See more

akto-dashboard akto 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,265
akto-dbabsakto0.1.91 of 1See more

akto-dbabs akto 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

1,229
akto-hybrid-redactakto1.44.72 of 5See more

akto-hybrid-redact akto 1.44.7

2 of the 5 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.6_local8b9208c09d76
expat@2.7.4-1
no fix listed
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
expat@2.7.4-1
no fix listed

Open the chart page →

4,948
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8b9208c09d76
expat@2.7.4-1
no fix listed

Open the chart page →

2,687
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
expat@2.7.4-1
no fix listed

Open the chart page →

6,606
akto-regional-setupakto1.4.04 of 9See more

akto-regional-setup akto 1.4.0

4 of the 9 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
expat@2.7.4-1
no fix listed
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
expat@2.7.4-1
no fix listed
redis/redis-stack-server:7.4.072035434f455
expat@2.4.7-1ubuntu0.4
no fix listed
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
expat@2.7.4-1
no fix listed

Open the chart page →

40,759
akto-runtimeakto0.1.81 of 2See more

akto-runtime akto 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
expat@2.7.4-1
no fix listed

Open the chart page →

1,556
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

35,334
akto-threat-backendakto0.1.51 of 2See more

akto-threat-backend akto 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latestdffb8c3676ef
expat@2.7.4-1
no fix listed

Open the chart page →

1,399
akto-threat-clientakto0.2.01 of 2See more

akto-threat-client akto 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
expat@2.7.4-1
no fix listed

Open the chart page →

1,428
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

57,534
browserlessalekcVerified publisher1.2.71 of 1See more

browserless alekc 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

2,173
esphomealekcVerified publisher2.9.01 of 1See more

esphome alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
esphome/esphome:2026.9.09959730a04c7
expat@2.7.1-2
no fix listed

Open the chart page →

3,242
komodoalekcVerified publisher3.1.01 of 1See more

komodo alekc 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,957
alertigatealertigate0.6.01 of 1See more

alertigate alertigate 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/feresberbeche/alertigate:2.0.07b9bba80f207
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,361
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

6,391
flaresolverralexmorbo-flaresolverrVerified publisher0.2.01 of 1See more

flaresolverr alexmorbo-flaresolverr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

27,797
nginx-sni-proxyalexpressoVerified publisher1.0.21 of 1See more

nginx-sni-proxy alexpresso 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
expat@2.8.3-1~deb13u1
no fix listed

Open the chart page →

1,589
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
expat@2.2.5-3ubuntu0.7
no fix listed

Open the chart page →

89,955
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
expat@2.6.1-2ubuntu0.4
no fix listed

Open the chart page →

3,744
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,350
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

28,511
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
expat@2.5.0-1
no fix listed

Open the chart page →

7,641
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

5,800
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
expat@2.2.9-1build1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
expat@2.2.5-3ubuntu0.2
no fix listed

Open the chart page →

20,350
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
expat@2.2.5-3ubuntu0.9
no fix listed

Open the chart page →

11,662
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

7,204
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
expat@2.5.0-1+deb12u2
no fix listed

Open the chart page →

4,105
games-on-whalesangelnu2.0.04 of 7See more

games-on-whales angelnu 2.0.0

4 of the 7 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
expat@2.4.7-1ubuntu0.6
no fix listed
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
expat@2.2.9-1build1
no fix listed
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
expat@2.2.9-1build1
no fix listed
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
expat@2.2.9-1build1
no fix listed

Open the chart page →

116,070
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
expat@2.7.1-2
no fix listed

Open the chart page →

5,684
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
expat@2.5.0-1
no fix listed
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
expat@2.5.0-1
no fix listed

Open the chart page →

26,322
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
expat@2.7.1-2
no fix listed

Open the chart page →

3,373
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

6,341
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
expat@2.4.7-1ubuntu0.6
no fix listed

Open the chart page →

4,106
inbox-server-distributedappscodeVerified publisher2025.12.253 of 4See more

inbox-server-distributed appscode 2025.12.25

3 of the 4 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
expat@2.4.7-1ubuntu0.2
no fix listed
library/rabbitmq:3.12.1-managementf020c06da226
expat@2.4.7-1ubuntu0.2
no fix listed
ghcr.io/appscode/inbox-server:latest536358d7b17e
expat@2.4.7-1ubuntu0.6
no fix listed

Open the chart page →

15,997
james-komposeappscodeVerified publisher0.1.03 of 4See more

james-kompose appscode 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
expat@2.4.7-1ubuntu0.2
no fix listed
library/rabbitmq:3.12.1-managementf020c06da226
expat@2.4.7-1ubuntu0.2
no fix listed
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

17,380
platform-apiappscodeVerified publisher2026.9.111 of 3See more

platform-api appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
expat@2.7.1-2
no fix listed

Open the chart page →

38,104
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
expat@2.4.7-1ubuntu0.3
no fix listed

Open the chart page →

3,369
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
expat@2.7.1-2
no fix listed

Open the chart page →

7,599
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
expat@2.6.1-2ubuntu0.3
no fix listed

Open the chart page →

7,743
arlas-aiasarlas-stackVerified publisher28.9.01 of 22See more

arlas-aias arlas-stack 28.9.0

1 of the 22 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
expat@2.5.0-1+deb12u1
no fix listed

Open the chart page →

39,854
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

23,484
keystonearzu0.2.293 of 4See more

keystone arzu 0.2.29

3 of the 4 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
library/rabbitmq:3.7-managementb6dd45cc35b3
expat@2.2.5-3ubuntu0.2
no fix listed
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
expat@2.2.9-1ubuntu0.6
no fix listed
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
expat@2.2.9-1ubuntu0.6
no fix listed

Open the chart page →

22,882
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
expat@2.1.0-7ubuntu0.16.04.3
no fix listed

Open the chart page →

188,990
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
expat@2.1.0-7ubuntu0.16.04.3
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
expat@2.1.0-7ubuntu0.16.04.3
no fix listed

Open the chart page →

188,990
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
expat@2.4.7-1
no fix listed

Open the chart page →

10,227
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-93990.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
expat@2.4.7-1ubuntu0.2
no fix listed

Open the chart page →

86,618

Container images carrying it

1,292 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
expat@2.7.4-1
no fix listed
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
expat@2.5.0-1
no fix listed
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
expat@2.8.2-1+e1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
expat@2.5.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
expat@2.5.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
expat@2.5.0-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
expat@2.5.0-1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
expat@2.5.0-1
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
expat@2.5.0-1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
expat@2.2.9-1build1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
expat@2.5.0-1
no fix listed
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
expat@2.7.4-1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
expat@2.4.7-1
no fix listed
1
quay.io/argoproj/argocd:v2.10.783c86003b781
expat@2.4.7-1ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
expat@2.4.7-1ubuntu0.2
no fix listed
1
quay.io/argoprojlabs/gitops-promoter:v0.41.0cab605cc1d1d
expat@2.8.3-1~deb13u1
no fix listed
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
expat@2.5.0-1+deb12u1
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
expat@2.2.5-3ubuntu0.7
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
expat@2.4.7-1
no fix listed
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
expat@2.6.1-2ubuntu0.4
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
expat@2.5.0-1+deb12u3
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
expat@2.5.0-1+deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
expat@2.5.0-1+deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
expat@2.5.0-1+deb12u3
no fix listed
1
quay.io/kannika/kannika-api:0.18.0bcf9906d5a3c
expat@2.8.3-1~deb13u1
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
expat@2.5.0-1+deb12u1
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
expat@2.6.1-2ubuntu0.3
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
no fix listed
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
expat@2.7.4-1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
expat@2.5.0-1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
expat@2.6.1-2ubuntu0.4
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
expat@2.7.4-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
expat@2.7.1-2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
expat@2.5.0-1+deb12u2
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
expat@2.2.9-1build1
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
expat@2.5.0-1+deb12u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
expat@2.7.1-2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
expat@2.5.0-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
expat@2.5.0-1+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
expat@2.5.0-1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.