apache/shenyu-bootstrap:2.4.2 container image
Docker HubScanned 14 Sept 2026
Deployed by 3 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of apache/shenyu-bootstrap
apache/shenyu-bootstrap:2.4.2 resolved to 0bd3b25c4be4, scanned 14 Sept 2026: 276 findings, 11 critical, 5 on KEV; deployed by 3 charts, among them shenyu, shenyu and shenyu.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
276 distinct on this digest
Findings for digest 0bd3b25c4be4 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-mf92-479x-3373 | spring-security-web | no fix listed |
| Medium | GHSA-x4gw-5cx5-pgmh | netty-handler | 4.1.135.Final |
| Medium | GHSA-7pm4-g2qj-j85x | spring-webflux | 5.2.3 |
| Medium | GHSA-g5ww-5jh7-63cx | protobuf-java | 3.16.3 |
| Medium | GHSA-wx54-3278-m5g4 | spring-security-core | 5.5.7 |
| Medium | GHSA-264p-99wq-f4j6 | ion-java | no fix listed |
| Medium | GHSA-gvpg-vgmx-xg6w | nimbus-jose-jwt | 9.37.2 |
| Medium | GHSA-rmrm-75hp-phr2 | hibernate-validator | 6.0.20.Final |
| Medium | GHSA-2x2g-32r7-p4x8 | kafka-clients | 3.7.1 |
| Low | GHSA-g3pr-3p32-fp23 | micrometer-core | no fix listed |
| Low | ALPINE-CVE-2018-1000654 | libtasn1 | 4.14-r0 |
| Low | GHSA-vmq6-5m68-f53m | logback-classic | 1.2.13 |
| Low | GHSA-vmq6-5m68-f53m | logback-core | 1.2.13 |
| Low | GHSA-v6w3-2prq-h95f | jakarta.el | 3.0.4 |
| Low | ALPINE-CVE-2019-5188 | e2fsprogs | 1.44.5-r2 |
| Low | GHSA-57rv-r2g8-2cj3 | netty-codec-http | 4.1.133.Final |
| Low | GHSA-4gg5-vx3j-xwc7 | protobuf-java | 3.16.3 |
| Low | GHSA-7v6m-28jr-rg84 | hibernate-validator | 6.2.0.CR1 |
| Low | GHSA-rqfh-9r24-8c9r | assertj-core | 3.27.7 |
| Low | GHSA-cm59-pr5q-cw85 | spring-boot | 2.2.11.RELEASE |
| Low | ALPINE-CVE-2020-14363 | libx11 | 1.6.12-r0 |
| Low | GHSA-pwqr-wmgm-9rr8 | netty-codec-http | 4.1.132.Final |
| Low | GHSA-564r-hj7v-mcr5 | spring-expression | 5.2.23.RELEASE |
| Low | GHSA-45q3-82m4-75jr | netty-handler-proxy | 4.1.133.Final |
| Low | GHSA-3wrr-7qpf-2prh | jackson-databind | 2.14.0 |
| Low | GHSA-w33c-445m-f8w7 | okio | 1.17.6 |
| Low | GHSA-c4c3-7fpv-j4q5 | netty-handler | 4.1.137.Final |
| Low | GHSA-mg83-c7gq-rv5c | spring-security-crypto | 5.7.16 |
| Low | GHSA-7w8v-5fcq-pvqw | shenyu-common | 2.6.0 |
| Low | GHSA-h4h5-3hr4-j3g2 | protobuf-java | 3.16.3 |
| Low | GHSA-hhhw-99gj-p3c3 | snakeyaml | 1.31 |
| Low | GHSA-5jpm-x58v-624v | netty-codec-http | 4.1.108.Final |
| Low | GHSA-6xx3-rg99-gc3p | bcprov-jdk15on | 1.66 |
| Low | GHSA-mgvc-8q2h-5pgc | spring-boot-starter-actuator | no fix listed |
| Low | GHSA-3p8m-j85q-pgmj | netty-codec | 4.1.125.Final |
| Low | GHSA-mj4r-2hfc-f8p6 | netty-codec | 4.1.133.Final |
| Low | ALPINE-CVE-2019-1563 | openssl | 1.1.1d-r0 |
| Low | GHSA-c653-97m9-rcg9 | netty-handler | 4.1.135.Final |
| Low | GHSA-4gr7-qw2q-jxh6 | nacos-common | 2.1.0-BETA |
| Low | GHSA-gfwj-fwqj-fp3v | spring-web | 5.2.15 |
| Low | GHSA-93wv-jw9v-4972 | netty-codec-http2 | 4.1.136.Final |
| Low | GHSA-6jqx-86gh-f27w | netty-codec-http | 4.1.136.Final |
| Low | GHSA-v435-xc8x-wvr9 | bcprov-jdk15on | 1.78 |
| Low | GHSA-jjfh-589g-3hjx | spring-boot-actuator | 2.7.18 |
| Low | GHSA-mvh2-crg5-v77c | netty-codec-http | 4.1.136.Final |
| Low | GHSA-hr32-mgpm-qf2f | resteasy-client | 3.14.0.Final |
| Low | GHSA-269q-hmxg-m83q | netty-codec-http | 4.1.77.Final |
| Low | GHSA-558v-64gr-wgg4 | netty-codec | 4.1.136.Final |
| Low | GHSA-x23c-287f-qqv5 | spring-webflux | no fix listed |
| Low | GHSA-xwmg-2g98-w7v9 | nimbus-jose-jwt | 9.37.4 |