StackRadar

apachepulsar/pulsar:2.6.1 container image

Docker Hub

Scanned 15 Sept 2026

Deployed by 1 of 17,787 indexed charts (latest versions) at this tag.Docker Hub all tags of apachepulsar/pulsar

apachepulsar/pulsar:2.6.1 resolved to 4db6ff0b4045, scanned 15 Sept 2026: 356 findings, 9 critical, 6 on KEV; deployed by 1 chart, among them pulsar.

Radar Score

6,650913141193

356 findings on digest 4db6ff0b4045 · scanned 15 Sept 2026

KEV ×6 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.6.1resolves to4db6ff0b40451 chart7 days ago9131411936,650

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

356 distinct on this digest

Findings for digest 4db6ff0b4045 as scanned on 15 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 15 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-mfg7-5gfp-c4w3netty-codec-dns@4.1.48.Final4.1.136.Final
LowGHSA-qccp-gfcp-xxvcurllib3@1.25.102.7.0
LowDLA-3583-1glib2.0@2.58.3-2+deb10u22.58.3-2+deb10u5
LowGHSA-qh8g-58pp-2wxhjetty-http@9.4.29.v2020052112.0.12
LowDLA-3814-1glib2.0@2.58.3-2+deb10u22.58.3-2+deb10u6
LowGHSA-7p3p-8qv8-m2vhjetty-server@9.4.11.v20180605no fix listed
LowGHSA-gcjf-9mgh-3p7gnetty-codec-http@4.1.48.Final4.1.136.Final
LowGHSA-v8h7-rr48-vmmvnetty-codec-http@4.1.48.Final4.1.133.Final
LowGHSA-563q-j3cm-6jxmnetty-codec-http2@4.1.48.Final4.1.135.Final
LowGHSA-5x3r-wrvg-rp6qnetty-codec-http2@4.1.48.Final4.1.135.Final
LowGHSA-3gh6-v5v9-6v9jjetty-servlets@9.4.29.v202005219.4.52
LowGHSA-xpw8-rcwv-8f8pnetty-codec-http2@4.1.48.Final4.1.100.Final
LowGHSA-m6cp-vxjx-65j6jetty-server@9.4.11.v201806059.4.41
LowGHSA-7g45-4rm6-3mm3guava@25.1-jre32.0.0-android
LowDLA-3602-1libx11@2:1.6.7-12:1.6.7-1+deb10u4
LowGHSA-g4mx-q9vg-27p4urllib3@1.25.101.26.18
LowGHSA-25qh-j22f-pwp8logback-core@1.2.31.3.16
LowDLA-3110-1glib2.0@2.58.3-2+deb10u22.58.3-2+deb10u4
LowGHSA-5mg8-w23w-74h3guava@25.1-jre32.0.0-android
LowGHSA-hvcg-qmg6-jm4cnetty-codec-http@4.1.48.Final4.1.135.Final
LowGHSA-45p5-v273-3qqrvertx-web@3.4.14.5.22
LowPYSEC-2026-2275requests@2.24.02.33.0
LowDSA-4850-1libzstd@1.3.8+dfsg-31.3.8+dfsg-3+deb10u1
LowDLA-3474-1systemd@241-7~deb10u3241-7~deb10u10
LowGHSA-wf8f-6423-gfxgjackson-core@2.11.12.13.0
LowGHSA-cj7v-27pg-wf7qjetty-http@9.4.29.v202005219.4.47
LowDSA-4808-1apt@1.8.21.8.2.2
LowDLA-3603-1libxpm@1:3.5.12-11:3.5.12-1+deb10u2
LowDSA-4859-1libzstd@1.3.8+dfsg-31.3.8+dfsg-3+deb10u2
LowDLA-3771-1python2.7@2.7.16-2+deb10u12.7.16-2+deb10u4
LowDLA-3772-1python3.7@3.7.3-2+deb10u23.7.3-2+deb10u7
LowGHSA-m452-q8c9-rg2fasync-http-client@2.12.12.16.0
LowGHSA-jp4c-xjxw-mgf9pip@20.2.226.1
LowDLA-3755-1tar@1.30+dfsg-61.30+dfsg-6+deb10u1
LowGHSA-p26g-97m4-6q7cjetty-server@9.4.11.v201806059.4.51.v20230217
LowDLA-3579-1elfutils@0.176-1.10.176-1.1+deb10u1
LowGHSA-58qw-9mgm-455vpip@20.2.226.1
LowGHSA-w573-9ffj-6ff9netty-transport-native-kqueue@4.1.48.Final4.1.135.Final
LowGHSA-w573-9ffj-6ff9netty-transport-native-epoll@4.1.48.Final4.1.135.Final
LowGHSA-wjpw-4j6x-6rwhjetty-http@9.4.29.v20200521no fix listed
LowDLA-3112-1bzip2@1.0.6-9.2~deb10u11.0.6-9.2~deb10u2
LowDLA-3134-1tzdata@2019c-0+deb10u12021a-0+deb10u7
LowDLA-3161-1tzdata@2019c-0+deb10u12021a-0+deb10u8
LowDLA-3366-1tzdata@2019c-0+deb10u12021a-0+deb10u10
LowDLA-3412-1tzdata@2019c-0+deb10u12021a-0+deb10u11
LowDLA-3482-1debian-archive-keyring@2019.12019.1+deb10u2
LowDLA-3684-1tzdata@2019c-0+deb10u12021a-0+deb10u12
LowDLA-3788-1tzdata@2019c-0+deb10u12024a-0+deb10u1
LowDSA-5085-2expat@2.2.6-2+deb10u12.2.6-2+deb10u4
LowGHSA-58qw-p7qm-5rvhjetty-xml@9.4.29.v202005219.4.52.v20230823

Used by

1 chart
ChartVersionTagContainers
pulsarcnieg1.0.82.6.117

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.