apache/druid:29.0.1 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of apache/druid
apache/druid:29.0.1 resolved to 0cef139b6bf1, scanned 14 Sept 2026: 433 findings, 12 critical, 1 on KEV; deployed by 1 chart, among them druid.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
135 distinct on this digest
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest 0cef139b6bf1 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | DEBIAN-CVE-2026-25646 | libpng1.6 | 1.6.39-2+deb12u3 |
| Medium | DEBIAN-CVE-2019-1010024 | glibc | no fix listed |
| Medium | GHSA-9w38-p64v-xpmv | commons-configuration2 | 2.10.1 |
| Medium | GHSA-3x8x-79m2-3w2w | jackson-databind | 2.12.6 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.18.8 |
| Medium | DEBIAN-CVE-2026-5450 | glibc | no fix listed |
| Medium | GHSA-493p-pfq6-5258 | json-smart | 2.4.9 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.18.8 |
| Medium | GHSA-56h3-78gp-v83r | jettison | 1.5.1 |
| Medium | DEBIAN-CVE-2024-21147 | openjdk-17 | 17.0.12+7-2~deb12u1 |
| Medium | GHSA-mfj5-cf8g-g2fv | async-http-client | 2.12.4 |
| Medium | DEBIAN-CVE-2026-33416 | libpng1.6 | 1.6.39-2+deb12u4 |
| Medium | GHSA-prj3-ccx8-p6x4 | netty-codec-http2 | 4.1.124.Final |
| Medium | GHSA-55g7-9cwv-5qfv | snappy-java | 1.1.10.4 |
| Medium | GHSA-h46c-h94j-95f3 | jackson-core | 2.15.0 |
| Medium | GHSA-q6g2-g7f3-rr83 | jettison | 1.5.4 |
| Medium | GHSA-cm33-6792-r9fm | netty-codec-dns | 4.1.133.Final |
| Medium | GHSA-5mcr-gq6c-3hq2 | netty | no fix listed |
| Medium | DEBIAN-CVE-2024-33601 | glibc | 2.36-9+deb12u7 |
| Medium | GHSA-f6hv-jmp6-3vwv | netty-codec-http | 4.1.133.Final |
| Medium | GHSA-f6hv-jmp6-3vwv | netty-codec-http2 | 4.1.133.Final |
| Medium | DEBIAN-CVE-2026-58016 | glib2.0 | no fix listed |
| Medium | GHSA-jppx-w49h-x2qq | netty-codec-http | 4.1.136.Final |
| Medium | DEBIAN-CVE-2025-29070 | lcms2 | no fix listed |
| Medium | DEBIAN-CVE-2026-66046 | expat | no fix listed |
| Medium | DEBIAN-CVE-2026-21945 | openjdk-17 | 17.0.18+8-1~deb12u1 |
| Medium | GHSA-3cqm-mf7h-prrj | okhttp | 4.9.2 |
| Medium | GHSA-hf6x-8p5f-cgmf | httpcore5 | 5.4.3 |
| Medium | GHSA-v3jc-474w-2wm6 | httpcore5-h2 | 5.4.3 |
| Medium | GHSA-x4gw-5cx5-pgmh | netty-handler | 4.1.135.Final |
| Medium | GHSA-g5ww-5jh7-63cx | protobuf-java | 3.16.3 |
| Medium | GHSA-pqr6-cmr2-h8hf | snappy-java | 1.1.10.1 |
| Medium | GHSA-gvpg-vgmx-xg6w | nimbus-jose-jwt | 9.37.2 |
| Medium | GHSA-2x2g-32r7-p4x8 | kafka-clients | 3.7.1 |
| Medium | DEBIAN-CVE-2019-1010025 | glibc | no fix listed |