apache/airflow:2.8.1 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of apache/airflow
apache/airflow:2.8.1 resolved to e5560ad0b86e, scanned 14 Sept 2026: 851 findings, 6 critical; deployed by 1 chart, among them airflow.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
851 distinct on this digest
Findings for digest e5560ad0b86e as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | PYSEC-2025-49 | setuptools | 78.1.1 |
| Medium | DEBIAN-CVE-2019-9192 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2026-42010 | gnutls28 | 3.7.9-2+deb12u7 |
| Medium | DEBIAN-CVE-2024-12087 | rsync | 3.2.7-1+deb12u1 |
| Medium | DEBIAN-CVE-2024-7592 | python3.11 | 3.11.2-6+deb12u5 |
| Medium | DEBIAN-CVE-2024-34459 | libxml2 | 2.9.14+dfsg-1.3~deb12u2 |
| Medium | GHSA-2943-9672-r45w | apache-airflow | 3.3.0 |
| Medium | DEBIAN-CVE-2024-6232 | python3.11 | 3.11.2-6+deb12u4 |
| Medium | DEBIAN-CVE-2023-31486 | perl | no fix listed |
| Medium | DEBIAN-CVE-2026-3497 | openssh | 1:9.2p1-2+deb12u9 |
| Medium | DEBIAN-CVE-2018-5709 | krb5 | no fix listed |
| Medium | DEBIAN-CVE-2024-28757 | expat | no fix listed |
| Medium | GHSA-7c2f-r6gc-h92h | apache-airflow | 2.11.1 |
| Medium | DEBIAN-CVE-2024-8088 | python3.11 | 3.11.2-6+deb12u3 |
| Medium | DEBIAN-CVE-2026-10536 | curl | no fix listed |
| Medium | DEBIAN-CVE-2023-31484 | perl | 5.36.0-7+deb12u3 |
| Medium | DEBIAN-CVE-2023-2953 | openldap | no fix listed |
| Medium | DEBIAN-CVE-2016-20012 | openssh | no fix listed |
| Medium | DEBIAN-CVE-2023-52425 | expat | 2.5.0-1+deb12u2 |
| Medium | GHSA-29h4-r29x-hchv | redshift-connector | 2.1.14 |
| Medium | DEBIAN-CVE-2018-6829 | libgcrypt20 | no fix listed |
| Medium | DEBIAN-CVE-2025-32988 | gnutls28 | 3.7.9-2+deb12u5 |
| Medium | DEBIAN-CVE-2024-45490 | expat | 2.5.0-1+deb12u1 |
| Medium | DEBIAN-CVE-2024-33599 | glibc | 2.36-9+deb12u7 |
| Medium | DEBIAN-CVE-2025-13836 | python3.11 | 3.11.2-6+deb12u7 |
| Medium | DEBIAN-CVE-2026-11527 | libconfig-inifiles-perl | 3.000003-2+deb12u1 |
| Medium | DEBIAN-CVE-2026-18924 | curl | no fix listed |
| Medium | DEBIAN-CVE-2023-5678 | openssl | 3.0.13-1~deb12u1 |
| Medium | PYSEC-2026-2269 | pyopenssl | 26.0.0 |
| Medium | DEBIAN-CVE-2025-9230 | openssl | 3.0.17-1~deb12u3 |
| Medium | DEBIAN-CVE-2026-11856 | curl | no fix listed |
| Medium | GHSA-j2pw-vp55-fqqj | flask-appbuilder | 4.3.11 |
| Medium | DEBIAN-CVE-2023-6129 | openssl | 3.0.13-1~deb12u1 |
| Medium | GHSA-5r62-mjf5-xwhj | apache-airflow-providers-common-sql | 1.24.1 |
| Medium | GHSA-r837-hpv7-pc2f | apache-airflow | 2.11.1 |
| Medium | DEBIAN-CVE-2026-33845 | gnutls28 | 3.7.9-2+deb12u7 |
| Medium | DEBIAN-CVE-2011-3389 | gnutls28 | no fix listed |
| Medium | DEBIAN-CVE-2025-49794 | libxml2 | 2.9.14+dfsg-1.3~deb12u3 |
| Medium | PYSEC-2024-60 | idna | 3.7 |
| Medium | DEBIAN-CVE-2024-25062 | libxml2 | 2.9.14+dfsg-1.3~deb12u2 |
| Medium | DEBIAN-CVE-2025-6021 | libxml2 | 2.9.14+dfsg-1.3~deb12u3 |
| Medium | DEBIAN-CVE-2024-12086 | rsync | 3.2.7-1+deb12u1 |
| Medium | DEBIAN-CVE-2026-42009 | gnutls28 | 3.7.9-2+deb12u7 |
| Medium | DEBIAN-CVE-2026-48165 | mariadb | 1:10.11.18-0+deb12u1 |
| Medium | DEBIAN-CVE-2026-63076 | openssl | no fix listed |
| Medium | DEBIAN-CVE-2025-59375 | expat | no fix listed |
| Medium | DEBIAN-CVE-2024-8176 | expat | 2.5.0-1+deb12u2 |
| Medium | DEBIAN-CVE-2024-9681 | curl | 7.88.1-10+deb12u9 |
| Medium | GHSA-9r64-3wmc-x8m8 | apache-airflow-providers-snowflake | 6.4.0 |
| Medium | DEBIAN-CVE-2026-33846 | gnutls28 | 3.7.9-2+deb12u7 |