apache/skywalking-oap-server:8.9.1 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of apache/skywalking-oap-server
apache/skywalking-oap-server:8.9.1 resolved to b4ec8c18d079, scanned 14 Sept 2026: 740 findings, 11 critical, 4 on KEV; deployed by 1 chart, among them skywalking-v1.
Radar Score
740 findings on digest b4ec8c18d079 · scanned 14 Sept 2026
KEV ×4 confirmed exploitedRadar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest b4ec8c18d079 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2026-6090 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2026-50813 | sqlite3 | no fix listed |
| Low | GO-2026-5038 | stdlib | 1.25.11 |
| Low | UBUNTU-CVE-2026-13757 | p11-kit | 0.23.20-1ubuntu0.1+esm1 |
| Low | GO-2026-5942 | golang.org/ | 0.56.0 |
| Low | GHSA-5mg8-w23w-74h3 | guava | 32.0.0-android |
| Low | GHSA-hvcg-qmg6-jm4c | netty-codec-http | 4.1.135.Final |
| Low | GHSA-qxp5-gwg8-xv66 | golang.org/ | 0.36.0 |
| Low | UBUNTU-CVE-2026-11850 | krb5 | no fix listed |
| Low | UBUNTU-CVE-2026-56132 | expat | no fix listed |
| Low | GO-2025-4012 | stdlib | 1.24.8 |
| Low | GO-2025-3956 | stdlib | 1.23.12 |
| Low | UBUNTU-CVE-2025-8058 | glibc | 2.31-0ubuntu9.18+esm1 |
| Low | GO-2026-4440 | golang.org/ | 0.45.0 |
| Low | GO-2025-4011 | stdlib | 1.24.8 |
| Low | GO-2025-4015 | stdlib | 1.24.8 |
| Low | GO-2026-6218 | stdlib | 1.25.13 |
| Low | GO-2026-4441 | golang.org/ | 0.45.0 |
| Low | UBUNTU-CVE-2026-40930 | libpng1.6 | 1.6.37-2ubuntu0.1~esm3 |
| Low | UBUNTU-CVE-2025-64506 | libpng1.6 | 1.6.37-2ubuntu0.1~esm1 |
| Low | UBUNTU-CVE-2013-4235 | shadow | 1:4.8.1-1ubuntu5.20.04.4 |
| Low | UBUNTU-CVE-2025-45582 | tar | no fix listed |
| Low | UBUNTU-CVE-2026-15534 | perl | 5.30.0-9ubuntu0.5+esm4 |
| Low | GO-2025-3373 | stdlib | 1.22.11 |
| Low | GO-2026-5970 | golang.org/ | 0.39.0 |
| Low | GO-2025-4155 | stdlib | 1.24.11 |
| Low | UBUNTU-CVE-2025-14017 | curl | 7.68.0-1ubuntu2.25+esm2 |
| Low | GO-2024-2888 | stdlib | 1.21.11 |
| Low | GO-2025-4008 | stdlib | 1.24.8 |
| Low | GO-2025-4010 | stdlib | 1.24.8 |
| Low | UBUNTU-CVE-2024-10041 | pam | no fix listed |
| Low | UBUNTU-CVE-2026-59850 | libssh | no fix listed |
| Low | GO-2023-1840 | stdlib | 1.19.10 |
| Low | UBUNTU-CVE-2026-50812 | sqlite3 | no fix listed |
| Low | GO-2025-4014 | stdlib | 1.24.8 |
| Low | UBUNTU-CVE-2023-4641 | shadow | 1:4.8.1-1ubuntu5.20.04.5 |
| Low | UBUNTU-CVE-2026-34757 | libpng1.6 | 1.6.37-2ubuntu0.1~esm3 |
| Low | GO-2025-3503 | stdlib | 1.23.7 |
| Low | UBUNTU-CVE-2026-18938 | p11-kit | 0.23.20-1ubuntu0.1+esm1 |
| Low | GHSA-wf8f-6423-gfxg | jackson-core | 2.13.0 |
| Low | GO-2026-4976 | stdlib | 1.25.10 |
| Low | GHSA-cj7v-27pg-wf7q | jetty-http | 9.4.47 |
| Low | UBUNTU-CVE-2025-5278 | coreutils | no fix listed |
| Low | GO-2026-5856 | stdlib | 1.25.12 |
| Low | UBUNTU-CVE-2026-22795 | openssl | 1.1.1f-1ubuntu2.24+esm2 |
| Low | GO-2025-4007 | stdlib | 1.24.9 |
| Low | GO-2026-6355 | golang.org/ | 0.56.0 |
| Low | GO-2026-4980 | stdlib | 1.25.10 |
| Low | GO-2026-5039 | stdlib | 1.25.11 |
| Low | GHSA-wh89-7897-x99h | netty-codec-haproxy | 4.1.136.Final |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| skywalking-v1huangchengwu-helm-chart | 0.1.0 | 8.9.1 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.