apache/airflow:2.10.2-python3.9 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of apache/airflow
apache/airflow:2.10.2-python3.9 resolved to ce90bdc3d2af, scanned 14 Sept 2026: 772 findings, 2 critical; deployed by 1 chart, among them rada-platform.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
772 distinct on this digest
Findings for digest ce90bdc3d2af as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | DEBIAN-CVE-2025-32988 | gnutls28 | 3.7.9-2+deb12u5 |
| Medium | DEBIAN-CVE-2025-13836 | python3.11 | 3.11.2-6+deb12u7 |
| Medium | DEBIAN-CVE-2026-11527 | libconfig-inifiles-perl | 3.000003-2+deb12u1 |
| Medium | DEBIAN-CVE-2026-18924 | curl | no fix listed |
| Medium | PYSEC-2026-2269 | pyopenssl | 26.0.0 |
| Medium | DEBIAN-CVE-2025-9230 | openssl | 3.0.17-1~deb12u3 |
| Medium | DEBIAN-CVE-2026-11856 | curl | no fix listed |
| Medium | GHSA-5r62-mjf5-xwhj | apache-airflow-providers-common-sql | 1.24.1 |
| Medium | GHSA-r837-hpv7-pc2f | apache-airflow | 2.11.1 |
| Medium | DEBIAN-CVE-2026-33845 | gnutls28 | 3.7.9-2+deb12u7 |
| Medium | DEBIAN-CVE-2011-3389 | gnutls28 | no fix listed |
| Medium | DEBIAN-CVE-2025-49794 | libxml2 | 2.9.14+dfsg-1.3~deb12u3 |
| Medium | DEBIAN-CVE-2024-25062 | libxml2 | 2.9.14+dfsg-1.3~deb12u2 |
| Medium | DEBIAN-CVE-2025-6021 | libxml2 | 2.9.14+dfsg-1.3~deb12u3 |
| Medium | DEBIAN-CVE-2024-12086 | rsync | 3.2.7-1+deb12u1 |
| Medium | GHSA-847f-9342-265h | h2 | 4.3.0 |
| Medium | DEBIAN-CVE-2026-42009 | gnutls28 | 3.7.9-2+deb12u7 |
| Medium | DEBIAN-CVE-2026-48165 | mariadb | 1:10.11.18-0+deb12u1 |
| Medium | DEBIAN-CVE-2026-63076 | openssl | no fix listed |
| Medium | DEBIAN-CVE-2025-59375 | expat | no fix listed |
| Medium | DEBIAN-CVE-2024-8176 | expat | 2.5.0-1+deb12u2 |
| Medium | DEBIAN-CVE-2024-9681 | curl | 7.88.1-10+deb12u9 |
| Medium | GHSA-9r64-3wmc-x8m8 | apache-airflow-providers-snowflake | 6.4.0 |
| Medium | DEBIAN-CVE-2026-33846 | gnutls28 | 3.7.9-2+deb12u7 |
| Medium | DEBIAN-CVE-2018-15919 | openssh | no fix listed |
| Medium | DEBIAN-CVE-2025-7424 | libxslt | 1.1.35-1+deb12u2 |
| Medium | DEBIAN-CVE-2025-0725 | curl | no fix listed |
| Medium | DEBIAN-CVE-2023-7104 | sqlite3 | 3.40.1-2+deb12u1 |
| Medium | DEBIAN-CVE-2025-13151 | libtasn1-6 | no fix listed |
| Medium | GHSA-2xpw-w6gg-jr37 | urllib3 | 2.6.0 |
| Medium | GHSA-gm62-xv2j-4w53 | urllib3 | 2.6.0 |
| Medium | DEBIAN-CVE-2024-26461 | krb5 | no fix listed |
| Medium | DEBIAN-CVE-2019-1010024 | glibc | no fix listed |
| Medium | GHSA-9r5j-7r2x-rv4g | apache-airflow-providers-http | 6.0.0 |
| Medium | DEBIAN-CVE-2026-5450 | glibc | no fix listed |
| Medium | GHSA-qf38-jq28-3ccq | apache-airflow-providers-sftp | 5.8.1 |
| Medium | DEBIAN-CVE-2024-9143 | openssl | 3.0.15-1~deb12u1 |
| Medium | GHSA-q34m-jh98-gwm2 | werkzeug | 3.0.6 |
| Medium | DEBIAN-CVE-2026-34182 | openssl | 3.0.20-1~deb12u2 |
| Medium | PYSEC-2023-221 | werkzeug | 2.3.8 |
| Medium | DEBIAN-CVE-2026-44172 | mariadb | 1:10.11.18-0+deb12u1 |
| Medium | DEBIAN-CVE-2025-27113 | libxml2 | 2.9.14+dfsg-1.3~deb12u2 |
| Medium | GHSA-8w49-h785-mj3c | tornado | 6.4.2 |
| Medium | GHSA-vqfr-h8mv-ghfj | h11 | 0.16.0 |
| Medium | DEBIAN-CVE-2026-6100 | python3.11 | 3.11.2-6+deb12u8 |
| Medium | DEBIAN-CVE-2026-31790 | openssl | 3.0.19-1~deb12u2 |
| Medium | DEBIAN-CVE-2025-32990 | gnutls28 | 3.7.9-2+deb12u5 |
| Medium | DEBIAN-CVE-2026-34180 | openssl | 3.0.20-1~deb12u2 |
| Medium | DEBIAN-CVE-2025-31115 | xz-utils | 5.4.1-1 |
| Medium | DEBIAN-CVE-2024-2379 | curl | no fix listed |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| rada-platformrada-platform | 0.1.0 | 2.10.2-python3.9 | 22 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.