apache/skywalking-oap-server:8.9.1 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of apache/skywalking-oap-server
apache/skywalking-oap-server:8.9.1 resolved to b4ec8c18d079, scanned 14 Sept 2026: 740 findings, 11 critical, 4 on KEV; deployed by 1 chart, among them skywalking-v1.
Radar Score
740 findings on digest b4ec8c18d079 · scanned 14 Sept 2026
KEV ×4 confirmed exploitedRadar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest b4ec8c18d079 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2024-33600 | glibc | 2.31-0ubuntu9.16 |
| Low | UBUNTU-CVE-2026-66046 | expat | no fix listed |
| Low | GHSA-7pwc-h2j2-rjgj | libthrift | 0.23.0 |
| Low | UBUNTU-CVE-2022-48303 | tar | 1.30+dfsg-7ubuntu0.20.04.3 |
| Low | GO-2023-2102 | stdlib | 1.20.10 |
| Low | UBUNTU-CVE-2025-5318 | libssh | 0.9.3-2ubuntu2.5+esm1 |
| Low | UBUNTU-CVE-2023-0466 | openssl | 1.1.1f-1ubuntu2.18 |
| Low | GHSA-6qvw-249j-h44c | jose4j | 0.9.4 |
| Low | GHSA-c4c3-7fpv-j4q5 | netty-handler | 4.1.137.Final |
| Low | UBUNTU-CVE-2026-80230 | curl | no fix listed |
| Low | UBUNTU-CVE-2023-0465 | openssl | 1.1.1f-1ubuntu2.18 |
| Low | UBUNTU-CVE-2026-42013 | gnutls28 | 3.6.13-2ubuntu1.12+esm3 |
| Low | UBUNTU-CVE-2026-0861 | glibc | 2.31-0ubuntu9.18+esm1 |
| Low | UBUNTU-CVE-2024-2236 | libgcrypt20 | no fix listed |
| Low | UBUNTU-CVE-2025-69419 | openssl | 1.1.1f-1ubuntu2.24+esm2 |
| Low | UBUNTU-CVE-2022-23491 | ca-certificates | 20211016ubuntu0.20.04.1 |
| Low | UBUNTU-CVE-2026-54874 | openssl | 1.1.1f-1ubuntu2.24+esm5 |
| Low | GHSA-fx2c-96vj-985v | netty-codec-haproxy | 4.1.86.Final |
| Low | UBUNTU-CVE-2026-42766 | openssl | 1.1.1f-1ubuntu2.24+esm4 |
| Low | UBUNTU-CVE-2025-32990 | gnutls28 | 3.6.13-2ubuntu1.12+esm1 |
| Low | UBUNTU-CVE-2024-50602 | expat | 2.2.9-1ubuntu0.8 |
| Low | GHSA-g8m5-722r-8whq | jetty-server | 9.4.56 |
| Low | GHSA-h4h5-3hr4-j3g2 | protobuf-java | 3.19.6 |
| Low | GO-2021-0264 | stdlib | 1.16.10 |
| Low | UBUNTU-CVE-2023-6918 | libssh | 0.9.3-2ubuntu2.5 |
| Low | GHSA-5pvg-856g-cp85 | netty-resolver-dns | 4.1.135.Final |
| Low | GO-2022-0969 | stdlib | 1.18.6 |
| Low | UBUNTU-CVE-2025-6020 | pam | no fix listed |
| Low | UBUNTU-CVE-2023-27538 | curl | 7.68.0-1ubuntu2.18 |
| Low | GHSA-hhhw-99gj-p3c3 | snakeyaml | 1.31 |
| Low | UBUNTU-CVE-2023-7104 | sqlite3 | 3.31.1-4ubuntu0.6 |
| Low | UBUNTU-CVE-2022-45142 | heimdal | 7.7.0+dfsg-1ubuntu1.4 |
| Low | UBUNTU-CVE-2026-86145 | pcre2 | no fix listed |
| Low | GHSA-5jpm-x58v-624v | netty-codec-http | 4.1.108.Final |
| Low | GHSA-qv9r-c865-cp47 | log4j-api | 2.25.5 |
| Low | GO-2021-0347 | stdlib | 1.16.15 |
| Low | UBUNTU-CVE-2024-8096 | curl | 7.68.0-1ubuntu2.24 |
| Low | GHSA-q4h4-gmj2-qvw2 | golang.org/ | 0.52.0 |
| Low | GO-2021-0319 | stdlib | 1.16.14 |
| Low | UBUNTU-CVE-2023-47039 | perl | no fix listed |
| Low | GHSA-3p8m-j85q-pgmj | netty-codec | 4.1.125.Final |
| Low | GHSA-w879-237q-wc7r | golang.org/ | 0.52.0 |
| Low | UBUNTU-CVE-2025-15281 | glibc | 2.31-0ubuntu9.18+esm1 |
| Low | GHSA-q4rv-gq96-w7c5 | jetty-server | 9.4.57.v20241219 |
| Low | UBUNTU-CVE-2025-6297 | dpkg | no fix listed |
| Low | GHSA-mj4r-2hfc-f8p6 | netty-codec | 4.1.133.Final |
| Low | UBUNTU-CVE-2026-42011 | gnutls28 | 3.6.13-2ubuntu1.12+esm3 |
| Low | GHSA-c653-97m9-rcg9 | netty-handler | 4.1.135.Final |
| Low | UBUNTU-CVE-2024-12243 | gnutls28 | 3.6.13-2ubuntu1.12 |
| Low | GHSA-vc5p-v9hr-52mj | log4j-core | 2.25.3 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| skywalking-v1huangchengwu-helm-chart | 0.1.0 | 8.9.1 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.