StackRadar

apache/ranger:2.7.0 container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of apache/ranger

apache/ranger:2.7.0 resolved to 76c176e8a0e4, scanned 14 Sept 2026: 639 findings, 3 critical, 1 on KEV; deployed by 1 chart, among them apache-ranger.

Radar Score

7,74039128499

639 findings on digest 76c176e8a0e4 · scanned 14 Sept 2026

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.7.0resolves to76c176e8a0e41 chart8 days ago391284997,740

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

639 distinct on this digest

Findings for digest 76c176e8a0e4 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGHSA-wr62-c79q-cv37tomcat-embed-core@9.0.989.0.107
MediumGHSA-5m62-pw8w-7w9ftomcat-embed-core@9.0.989.0.118
MediumGHSA-25xr-qj8w-c4vftomcat-embed-core@9.0.989.0.107
MediumGHSA-4j3c-42xv-3f84tomcat-embed-core@9.0.989.0.107
MediumUBUNTU-CVE-2016-20012openssh@1:8.9p1-3ubuntu0.13no fix listed
MediumGHSA-crhr-qqj8-rpxczookeeper@3.8.43.8.6
MediumGHSA-rhrv-645h-fjfhavro@1.8.21.11.3
MediumGHSA-r38f-c4h4-hqq2postgresql@42.2.16.jre742.2.26
MediumGHSA-qcwq-55hx-v3vhsnappy-java@1.1.8.21.1.10.1
MediumGHSA-w9fj-cfpg-grvvnetty-codec-http2@4.1.100.Final4.1.132.Final
MediumGHSA-h2fw-rfh5-95r3tomcat-embed-core@9.0.989.0.105
MediumGHSA-9xv2-5v5q-p794tomcat-embed-core@9.0.989.0.121
MediumGHSA-wrvw-hg22-4m67protobuf-java@3.7.13.16.1
MediumUBUNTU-CVE-2025-13836python3.10@3.10.12-1~22.04.103.10.12-1~22.04.13
MediumUBUNTU-CVE-2026-18924curl@7.81.0-1ubuntu1.20no fix listed
MediumUBUNTU-CVE-2023-32681python-pip@22.0.2+dfsg-1ubuntu0.622.0.2+dfsg-1ubuntu0.7
MediumUBUNTU-CVE-2022-4899libzstd@1.4.8+dfsg-3build1no fix listed
MediumUBUNTU-CVE-2023-5678openssl@3.0.2-0ubuntu1.19no fix listed
MediumUBUNTU-CVE-2025-9230openssl@3.0.2-0ubuntu1.193.0.2-0ubuntu1.20
MediumGHSA-pvp8-3xj6-8c6xcommons-configuration@1.6no fix listed
MediumUBUNTU-CVE-2026-11856curl@7.81.0-1ubuntu1.207.81.0-1ubuntu1.26
MediumUBUNTU-CVE-2023-6129openssl@3.0.2-0ubuntu1.19no fix listed
MediumUBUNTU-CVE-2026-8925curl@7.81.0-1ubuntu1.207.81.0-1ubuntu1.25
MediumGHSA-g93m-8x6h-g5gvzookeeper@3.9.23.9.3
MediumGHSA-j288-q9x7-2f5vcommons-lang@2.6no fix listed
MediumGHSA-j288-q9x7-2f5vcommons-lang3@3.14.03.18.0
MediumGHSA-rggv-cv7r-mw98http2-common@9.4.53.v202310099.4.54
MediumUBUNTU-CVE-2025-49794libxml2@2.9.13+dfsg-1ubuntu0.72.9.13+dfsg-1ubuntu0.8
MediumUBUNTU-CVE-2025-6021libxml2@2.9.13+dfsg-1ubuntu0.72.9.13+dfsg-1ubuntu0.8
MediumGHSA-xjp4-hw94-mvp5commons-configuration2@2.8.02.10.1
MediumGHSA-cgp8-4m63-fhh5commons-net@3.13.9.0
MediumUBUNTU-CVE-2026-42009gnutls28@3.7.3-4ubuntu1.63.7.3-4ubuntu1.9
MediumUBUNTU-CVE-2026-63076openssl@3.0.2-0ubuntu1.193.0.2-0ubuntu1.29
MediumGHSA-78wr-2p64-hpwjcommons-io@2.11.02.14.0
MediumUBUNTU-CVE-2025-59375expat@2.4.7-1ubuntu0.62.4.7-1ubuntu0.7
MediumGHSA-3qp7-7mw8-wx86netty-handler@4.1.108.Final4.1.135.Final
MediumUBUNTU-CVE-2023-37920python-pip@22.0.2+dfsg-1ubuntu0.6no fix listed
MediumUBUNTU-CVE-2026-33846gnutls28@3.7.3-4ubuntu1.63.7.3-4ubuntu1.9
MediumUBUNTU-CVE-2024-0727openssl@3.0.2-0ubuntu1.19no fix listed
MediumUBUNTU-CVE-2025-7424libxslt@1.1.34-4ubuntu0.22.04.41.1.34-4ubuntu0.22.04.5
MediumGHSA-2cqf-6xv9-f22welasticsearch@7.10.27.17.13
MediumGHSA-673j-qm5f-xpv8postgresql@42.2.16.jre742.3.3
MediumUBUNTU-CVE-2025-13151libtasn1-6@4.18.0-4ubuntu0.14.18.0-4ubuntu0.2
MediumGHSA-2xpw-w6gg-jr37urllib3@2.5.02.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@2.5.02.6.0
MediumGHSA-h3x4-894j-xpx5tomcat-embed-core@9.0.989.0.121
MediumGHSA-9w38-p64v-xpmvcommons-configuration2@2.8.02.10.1
MediumGHSA-rmj7-2vxq-3g9fjackson-databind@2.17.22.18.8
MediumUBUNTU-CVE-2023-6237openssl@3.0.2-0ubuntu1.19no fix listed
MediumUBUNTU-CVE-2022-41409pcre2@10.39-3ubuntu0.1no fix listed

Used by

1 chart
ChartVersionTagContainers
apache-rangerapache-ranger0.1.02.7.01

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.