StackRadar

apache/skywalking-oap-server:6.5.0 container image

Docker Hub

Scanned 29 Sept 2026

Deployed by 1 of 17,939 indexed charts (latest versions) at this tag.Docker Hub all tags of apache/skywalking-oap-server

apache/skywalking-oap-server:6.5.0 resolved to c1ee839ccad0, scanned 29 Sept 2026: 266 findings, 12 critical, 2 on KEV; deployed by 1 chart, among them skywalking.

Radar Score

6,897123013589

266 findings on digest c1ee839ccad0 · scanned 29 Sept 2026

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
6.5.0resolves toc1ee839ccad01 chartyesterday1230135896,897

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

266 distinct on this digest

Findings for digest c1ee839ccad0 as scanned on 29 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 29 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
CriticalGHSA-jfh8-c2jp-5v3qKEVlog4j-core@2.9.02.12.2
CriticalGHSA-fjq5-5j5f-mvxhcommons-collections@3.2.13.2.2
CriticalGHSA-7rjr-3q55-vv33KEVlog4j-core@2.9.02.12.2
CriticalGHSA-2qrg-x229-3v8qlog4j@1.2.16no fix listed
CriticalGHSA-p6xc-xr62-6r2glog4j-core@2.9.02.12.3
CriticalGHSA-65fg-84f6-3jq3log4j@1.2.16no fix listed
CriticalGHSA-mjmj-j48q-9wg2snakeyaml@1.182.0
CriticalGHSA-f7vh-qwp3-x37mlog4j@1.2.16no fix listed
CriticalGHSA-w9p3-5cr8-m3jjlog4j@1.2.16no fix listed
CriticalALPINE-CVE-2019-8457sqlite@3.24.0-r03.25.3-r1
CriticalGHSA-36hp-jr8h-556fnacos-common@1.0.01.4.1
CriticalGHSA-xv5h-v7jh-p2qhnacos-common@1.0.01.4.1
HighGHSA-fp5r-v3w9-4333log4j@1.2.16no fix listed
HighGHSA-8489-44mv-ggj8log4j-core@2.9.02.12.4
HighGHSA-4w82-r329-3q67jackson-databind@2.9.52.9.10.3
HighGHSA-26vr-8j45-3r4wjetty-server@9.4.2.v201702209.4.39
HighGHSA-6x9x-8qw9-9pp6jetty-server@9.4.2.v201702209.4.11.v20180605
HighGHSA-q93h-jc49-78ggjackson-databind@2.9.52.9.10.4
HighGHSA-p43x-xfjf-5jhrjackson-databind@2.9.52.9.10.4
HighGHSA-xphj-m9cc-8fmqgroovy@2.4.5-indy2.4.8
HighGHSA-645p-88qh-w398jackson-databind@2.9.52.9.7
HighGHSA-rvwf-54qp-4r6vsnakeyaml@1.181.26
HighGHSA-9mxf-g3x6-wv74jackson-databind@2.9.52.9.7
HighGHSA-h822-r4r5-v8jgjackson-databind@2.9.52.9.10
HighGHSA-c8hm-7hpq-7jhgjackson-databind@2.9.52.9.8
HighGHSA-f9hv-mg5h-xcw9jackson-databind@2.9.52.9.8
HighGHSA-mx9v-gmh4-mgqwjackson-databind@2.9.52.9.8
HighGHSA-pv7h-hx5h-mgfjfastjson@1.2.471.2.83
HighGHSA-mph4-vhrx-mv67jackson-databind@2.9.52.9.9.1
HighGHSA-5ww9-j83m-q7qxjackson-databind@2.9.52.9.9
HighGHSA-4gq5-ch57-c2mgjackson-databind@2.9.52.9.7
HighGHSA-9gph-22xh-8x98jackson-databind@2.9.52.9.10.8
HighGHSA-gww7-p5w4-wrfvjackson-databind@2.9.52.9.10.2
HighGHSA-6hgm-866r-3cjvcommons-collections@3.2.13.2.2
HighGHSA-6fpp-rgj9-8rwcjackson-databind@2.9.52.9.9.2
HighALPINE-CVE-2019-12900bzip2@1.0.6-r61.0.6-r7
HighGHSA-288c-cq4h-88gqjackson-databind@2.9.52.9.10.7
HighGHSA-x2w5-5m2g-7h5mjackson-databind@2.9.52.9.7
HighGHSA-53x6-4x5p-rrvvcommons-compress@1.181.19
HighGHSA-cqqj-4p63-rrmmnetty@3.10.5.Finalno fix listed
HighGHSA-cqqj-4p63-rrmmnetty-codec-http@4.1.27.Final4.1.44
HighGHSA-5r5r-6hpj-8gg9jackson-databind@2.9.52.9.10.8
MediumGHSA-4jrv-ppp4-jm57gson@2.8.12.8.9
MediumALPINE-CVE-2018-20346sqlite@3.24.0-r03.25.3-r0
MediumGHSA-fqwf-pjwf-7vqvjackson-databind@2.9.52.9.10.4
MediumGHSA-mc84-pj99-q6hhcommons-compress@1.181.21
MediumGHSA-qr7j-h6gg-jmgcjackson-databind@2.9.52.9.6
MediumGHSA-mx7p-6679-8g3qjackson-databind@2.9.52.9.10.1
MediumGHSA-crv7-7245-f45fcommons-compress@1.181.21
MediumGHSA-2g86-r6w2-wqqrnacos-client@1.0.0no fix listed

Used by

1 chart
ChartVersionTagContainers
skywalkingkubesphere-carryon-experimental0.6.06.5.02

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 29 Sept 2026 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.