apachepulsar/pulsar:2.9.0 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,787 indexed charts (latest versions) at this tag.Docker Hub all tags of apachepulsar/pulsar
apachepulsar/pulsar:2.9.0 resolved to d056c89b7131, scanned 14 Sept 2026: 1,137 findings, 16 critical, 6 on KEV; deployed by 1 chart, among them chirpstack.
Radar Score
1,137 findings on digest d056c89b7131 · scanned 14 Sept 2026
KEV ×6 confirmed exploitedRadar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest d056c89b7131 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2025-13837 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm5 |
| Low | UBUNTU-CVE-2025-9714 | libxml2 | 2.9.10+dfsg-5ubuntu0.20.04.10+esm2 |
| Low | UBUNTU-CVE-2026-56409 | expat | no fix listed |
| Low | GHSA-r978-9m6m-6gm6 | zookeeper | no fix listed |
| Low | UBUNTU-CVE-2025-1390 | libcap2 | 1:2.32-1ubuntu0.2 |
| Low | UBUNTU-CVE-2026-50813 | sqlite3 | no fix listed |
| Low | UBUNTU-CVE-2026-86139 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-13757 | p11-kit | 0.23.20-1ubuntu0.1+esm1 |
| Low | GHSA-5mg8-w23w-74h3 | guava | 32.0.0-android |
| Low | UBUNTU-CVE-2026-27447 | cups | no fix listed |
| Low | GHSA-hvcg-qmg6-jm4c | netty-codec-http | 4.1.135.Final |
| Low | UBUNTU-CVE-2026-11850 | krb5 | no fix listed |
| Low | UBUNTU-CVE-2026-56132 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-34933 | avahi | 0.7-4ubuntu7.3+esm2 |
| Low | UBUNTU-CVE-2026-15588 | glib2.0 | no fix listed |
| Low | UBUNTU-CVE-2025-8058 | glibc | 2.31-0ubuntu9.18+esm1 |
| Low | UBUNTU-CVE-2024-11168 | python3.8 | 3.8.10-0ubuntu1~20.04.14 |
| Low | UBUNTU-CVE-2026-41079 | cups | no fix listed |
| Low | GHSA-45p5-v273-3qqr | vertx-web | 4.5.22 |
| Low | UBUNTU-CVE-2026-40930 | libpng1.6 | 1.6.37-2ubuntu0.1~esm3 |
| Low | UBUNTU-CVE-2025-64506 | libpng1.6 | 1.6.37-2ubuntu0.1~esm1 |
| Low | UBUNTU-CVE-2013-4235 | shadow | 1:4.8.1-1ubuntu5.20.04.4 |
| Low | UBUNTU-CVE-2025-45582 | tar | no fix listed |
| Low | UBUNTU-CVE-2026-15534 | perl | 5.30.0-9ubuntu0.5+esm4 |
| Low | PYSEC-2026-2275 | requests | 2.33.0 |
| Low | UBUNTU-CVE-2025-58436 | cups | 2.3.1-9ubuntu1.9+esm4 |
| Low | UBUNTU-CVE-2025-8291 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm3 |
| Low | UBUNTU-CVE-2025-59529 | avahi | no fix listed |
| Low | UBUNTU-CVE-2025-14017 | curl | 7.68.0-1ubuntu2.25+esm2 |
| Low | UBUNTU-CVE-2026-86144 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2023-22006 | openjdk-lts | 11.0.20+8-1ubuntu1~20.04 |
| Low | UBUNTU-CVE-2026-56288 | patch | no fix listed |
| Low | UBUNTU-CVE-2026-56289 | patch | no fix listed |
| Low | UBUNTU-CVE-2025-69645 | binutils | no fix listed |
| Low | UBUNTU-CVE-2024-10041 | pam | no fix listed |
| Low | UBUNTU-CVE-2026-59850 | libssh | no fix listed |
| Low | UBUNTU-CVE-2026-50812 | sqlite3 | no fix listed |
| Low | UBUNTU-CVE-2025-68276 | avahi | 0.7-4ubuntu7.3+esm1 |
| Low | UBUNTU-CVE-2023-4641 | shadow | 1:4.8.1-1ubuntu5.20.04.5 |
| Low | UBUNTU-CVE-2026-34757 | libpng1.6 | 1.6.37-2ubuntu0.1~esm3 |
| Low | UBUNTU-CVE-2026-87875 | cups | no fix listed |
| Low | UBUNTU-CVE-2026-18938 | p11-kit | 0.23.20-1ubuntu0.1+esm1 |
| Low | UBUNTU-CVE-2026-0989 | libxml2 | 2.9.10+dfsg-5ubuntu0.20.04.10+esm4 |
| Low | GHSA-wf8f-6423-gfxg | jackson-core | 2.13.0 |
| Low | UBUNTU-CVE-2026-21925 | openjdk-lts | 11.0.30+7-1ubuntu1~20.04 |
| Low | GHSA-cj7v-27pg-wf7q | jetty-http | 9.4.47 |
| Low | UBUNTU-CVE-2025-5278 | coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-22795 | openssl | 1.1.1f-1ubuntu2.24+esm2 |
| Low | UBUNTU-CVE-2024-7883 | llvm-toolchain-12 | no fix listed |
| Low | UBUNTU-CVE-2025-3360 | glib2.0 | 2.64.6-1~ubuntu20.04.9+esm1 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| chirpstackmosquitto-helm-chart | 0.5.0 | 2.9.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.