alfio/alf.io:2.0-M5-2606 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of alfio/alf.io
alfio/alf.io:2.0-M5-2606 resolved to 0c836a081446, scanned 14 Sept 2026: 48 findings, 0 critical; deployed by 1 chart, among them alfio.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
48 distinct on this digest
Findings for digest 0c836a081446 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-98qh-xjc8-98pq | postgresql | 42.7.11 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.21.4 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.21.4 |
| Low | GHSA-3pxv-7cmr-fjr4 | log4j-core | 2.25.4 |
| Low | GHSA-445c-vh5m-36rj | log4j-core | 2.25.4 |
| Low | GHSA-2fvj-hgj9-j2gr | jetty-security | 12.0.36 |
| Low | GHSA-qv9r-c865-cp47 | log4j-api | 2.25.5 |
| Low | GHSA-vc5p-v9hr-52mj | log4j-core | 2.25.3 |
| Low | GHSA-v435-xc8x-wvr9 | bcprov-jdk15on | 1.78 |
| Low | GHSA-x23c-287f-qqv5 | spring-webmvc | 6.2.19 |
| Low | GHSA-8xfc-gm6g-vgpv | bcprov-jdk15on | 1.78 |
| Low | GHSA-wg6q-6289-32hp | bcpkix-jdk15on | 1.84 |
| Low | GHSA-4h8f-2wvx-gg5w | bcprov-jdk15on | 1.78 |
| Low | GHSA-wjxj-5m7g-mg7q | bcprov-jdk15on | no fix listed |
| Low | GHSA-r5w3-xv2f-j59q | spring-expression | 6.2.19 |
| Low | GHSA-j92g-9f8w-j867 | postgresql | 42.7.12 |
| Low | GHSA-4cx2-fc23-5wg6 | bcpkix-jdk15on | 1.79 |
| Low | GHSA-hr8g-6v94-x4m9 | bcprov-jdk15on | no fix listed |
| Low | GHSA-6hg6-v5c8-fphq | log4j-core | 2.25.4 |
| Low | GHSA-f4v5-65jj-pcr2 | jetty-server | 12.0.36 |
| Low | GHSA-rcqc-6cw3-h962 | jackson-databind | 2.21.4 |
| Low | GHSA-5gvw-p9qm-jgwh | jackson-databind | 2.21.5 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.4_git20230717-r6 |
| Low | GHSA-3pjw-73gf-8qr5 | jackson-databind | 2.21.4 |
| Low | GHSA-72pg-x5f8-j25j | spring-webmvc | 6.2.19 |
| Low | GHSA-mq64-j8f9-9gcj | spring-webmvc | 6.2.19 |
| Low | GHSA-9fxm-vc8v-hj55 | jackson-databind | 2.21.4 |
| Low | GHSA-r7wm-3cxj-wff9 | jackson-core | 2.21.4 |
| Low | GHSA-3chg-m5w7-qfv5 | spring-webmvc | 6.2.19 |
| Low | GHSA-5hh8-q8hv-fr38 | jackson-databind | 2.21.4 |
| Low | GHSA-hgj6-7826-r7m5 | jackson-databind | 2.21.4 |
| Low | GHSA-wxpp-56q6-5pcg | spring-expression | 6.2.19 |
| Low | GHSA-5jmj-h7xm-6q6v | jackson-databind | 2.21.5 |
| Low | GHSA-w7x5-g22v-xqhr | jetty-util | 12.0.35 |
| Low | GHSA-x2r2-rvhq-2mqv | spring-security-web | 6.5.11 |
| Low | GHSA-7p3p-8qv8-m2vh | jetty-server | 12.0.35 |
| Low | GHSA-293q-567p-wmwq | spring-security-web | 6.5.11 |
| Low | GHSA-957g-f97v-vppc | spring-webmvc | 6.2.19 |
| Low | GHSA-cjpg-rgq5-fr37 | spring-webmvc | 6.2.19 |
| Low | GHSA-mhm7-754m-9p8w | jackson-databind | 2.21.5 |
| Low | ALPINE-CVE-2026-6042 | musl | 1.2.4_git20230717-r6 |
| Low | GHSA-659m-px2c-25wj | spring-core | 6.2.19 |
| Low | GHSA-ggg2-9786-hwc8 | spring-boot-autoconfigure | 3.5.15 |
| Low | GHSA-h3qp-gqrc-q736 | spring-webmvc | 6.2.19 |
| Low | GHSA-7m2p-62gw-p8qq | spring-web | 6.2.19 |
| Low | GHSA-9f52-rjqv-25qv | spring-expression | 6.2.19 |
| Low | ALPINE-CVE-2025-46394 | busybox | 1.36.1-r21 |
| Low | ALPINE-CVE-2024-58251 | busybox | 1.36.1-r21 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| alfiohelmforgeVerified publisher | 1.2.12 | 2.0-M5-2606 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.