StackRadar

bitnamilegacy/elasticsearch:8.12.2 container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,787 indexed charts (latest versions) at this tag.Docker Hub all tags of bitnamilegacy/elasticsearch

bitnamilegacy/elasticsearch:8.12.2 resolved to 15d4647fd491, scanned 14 Sept 2026: 646 findings, 7 critical, 1 on KEV; deployed by 1 chart, among them clowder2.

Radar Score

7,5987695538

646 findings on digest 15d4647fd491 · scanned 14 Sept 2026

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
8.12.2resolves to15d4647fd4911 chart9 days ago76955387,598

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

538 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 15d4647fd491 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowBIT-java-2026-47021java@17.0.10-13-21.8.0
LowGHSA-563q-j3cm-6jxmnetty-codec-http2@4.1.94.Final4.1.135.Final
LowDEBIAN-CVE-2026-89161pcre2@10.42-110.42-1+deb12u1
LowBIT-elasticsearch-2025-68390elasticsearch@8.12.2-08.19.8
LowBIT-elasticsearch-2025-68390Elasticsearch@8.12.2-08.19.8
LowGHSA-gphj-4h6p-37xqx-pack-core@8.12.28.19.8
LowGO-2026-5026golang.org/x/net@v0.21.00.55.0
LowGO-2026-5026stdlib@go1.21.81.25.13
LowBIT-java-2025-30754Java@17.0.10-13-21.8.0
LowBIT-java-2025-30754java@17.0.10-13-21.8.0
LowDEBIAN-CVE-2025-14104util-linux@2.38.1-5+b1no fix listed
LowDEBIAN-CVE-2025-64505libpng1.6@1.6.39-21.6.39-2+deb12u1
LowGHSA-5x3r-wrvg-rp6qnetty-codec-http2@4.1.94.Final4.1.135.Final
LowDEBIAN-CVE-2026-42014gnutls28@3.7.9-2+deb12u23.7.9-2+deb12u7
LowBIT-java-2024-20945Java@17.0.10-13-21.8.0
LowBIT-java-2024-20945java@17.0.10-13-21.8.0
LowBIT-java-2026-46917Java@17.0.10-13-211.0.32
LowBIT-java-2026-46917java@17.0.10-13-211.0.32
LowBIT-java-2026-47027Java@17.0.10-13-21.8.0
LowBIT-java-2026-47027java@17.0.10-13-21.8.0
LowGO-2025-3420stdlib@go1.21.81.22.11
LowGO-2026-4342stdlib@go1.21.81.24.12
LowDEBIAN-CVE-2026-4105systemd@252.22-1~deb12u1252.39-1~deb12u2
LowGO-2025-3751stdlib@go1.21.81.23.10
LowDEBIAN-CVE-2026-78409util-linux@2.38.1-5+b1no fix listed
LowDEBIAN-CVE-2024-13176openssl@3.0.11-1~deb12u23.0.16-1~deb12u1
LowGHSA-xpw8-rcwv-8f8pnetty-codec-http2@4.1.94.Final4.1.100.Final
LowDEBIAN-CVE-2023-4641shadow@1:4.13+dfsg1-1+b11:4.13+dfsg1-1+deb12u1
LowGHSA-r3hx-qfh5-r9m7elasticsearch@8.12.28.13.0
LowBIT-java-2026-22013Java@17.0.10-13-21.8.0
LowBIT-java-2026-22013java@17.0.10-13-21.8.0
LowBIT-java-2026-70907Java@17.0.10-13-21.8.0
LowBIT-java-2026-70907java@17.0.10-13-21.8.0
LowDEBIAN-CVE-2026-45446openssl@3.0.11-1~deb12u23.0.20-1~deb12u2
LowBIT-java-2024-21210Java@17.0.10-13-21.8.0
LowBIT-java-2024-21210java@17.0.10-13-21.8.0
LowGO-2026-4870stdlib@go1.21.81.25.9
LowGO-2025-4009stdlib@go1.21.81.24.8
LowGO-2026-4947stdlib@go1.21.81.25.9
LowGO-2025-4006stdlib@go1.21.81.24.8
LowBIT-java-2024-21094java@17.0.10-13-21.8.0
LowBIT-java-2024-21094Java@17.0.10-13-21.8.0
LowGO-2026-5037stdlib@go1.21.81.25.11
LowDEBIAN-CVE-2026-40225systemd@252.22-1~deb12u1252.39-1~deb12u2
LowGO-2026-4971stdlib@go1.21.81.25.10
LowBIT-elasticsearch-2026-56143elasticsearch@8.12.2-08.19.20
LowBIT-elasticsearch-2026-56143Elasticsearch@8.12.2-08.19.20
LowGO-2026-5972stdlib@go1.21.81.25.13
LowGO-2026-6088stdlib@go1.21.81.25.13
LowGO-2026-6089stdlib@go1.21.81.25.13

Used by

1 chart
ChartVersionTagContainers
clowder2ncsaVerified publisher1.9.78.12.28

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.