bkimminich/juice-shop:v20.2.0 container image
Docker HubScanned 7 Oct 2026
Deployed by 1 of 18,035 indexed charts (latest versions) at this tag.Docker Hub all tags of bkimminich/juice-shop
bkimminich/juice-shop:v20.2.0 resolved to 8739101ade29, scanned 7 Oct 2026: 156 findings, 0 critical; deployed by 1 chart, among them juice-shop.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
156 distinct on this digest
Findings for digest 8739101ade29 as scanned on 7 Oct 2026 with syft 1.42.1 for linux/amd64, advisories as of 7 Oct 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-rjqq-98f6-6j3r | sanitize-html | 2.3.1 |
| Low | GHSA-g5hg-p3ph-g8qg | multer | 2.0.1 |
| Low | GHSA-8g4m-cjm2-96wq | notevil | no fix listed |
| Low | GHSA-23hp-3jrh-7fpw | tar | 7.5.19 |
| Low | GHSA-8x88-c5mf-7j5w | tar | 7.5.18 |
| Low | GHSA-r635-g3xr-vw7x | engine.io | 6.6.7 |
| Low | GHSA-8cf7-32gw-wr33 | jsonwebtoken | 9.0.0 |
| Low | GHSA-2m8v-j782-fhvr | socket.io-parser | 4.2.7 |
| Low | DEBIAN-CVE-2026-54874 | openssl | 3.5.7-1~deb13u2 |
| Low | GHSA-mjxr-4v3x-q3m4 | sanitize-html | 2.3.2 |
| Low | GHSA-vc2v-76pw-4v95 | compression | 1.8.2 |
| Low | GHSA-7r86-cg39-jmmj | minimatch | 3.1.3 |
| Low | GHSA-jqcg-44mw-7w3h | proxy-addr | 2.0.8 |
| Low | DEBIAN-CVE-2026-6791 | glibc | no fix listed |
| Low | GHSA-2883-xcg3-v3hh | js-yaml | 3.15.2 |
| Low | GHSA-xc6g-ggrc-qq4r | sanitize-html | 1.11.4 |
| Low | GHSA-ch52-4w7c-c8xp | http-cache-semantics | no fix listed |
| Low | GHSA-r292-9mhp-454m | tar | 7.5.21 |
| Low | GHSA-qffp-2rhf-9h96 | tar | 7.5.10 |
| Low | DEBIAN-CVE-2026-84782 | openssl | 3.5.7-1~deb13u3 |
| Low | GHSA-23c5-xmqv-rm74 | minimatch | 3.1.4 |
| Low | GHSA-8qq5-rm4j-mr97 | tar | 7.5.3 |
| Low | DEBIAN-CVE-2026-5928 | glibc | 2.41-12+deb13u4 |
| Low | GHSA-x8mw-p69m-v3mx | @fastify/ | 3.2.1 |
| Low | GHSA-535w-7cp7-47q4 | multer | 2.3.0 |
| Low | GHSA-72gw-mp4g-v24j | multer | 2.2.0 |
| Low | GHSA-wc9g-mqfw-jrwm | multer | 2.3.0 |
| Low | DEBIAN-CVE-2026-54873 | openssl | 3.5.7-1~deb13u3 |
| Low | GHSA-3j7m-hmh3-9jmp | sanitize-html | 1.4.3 |
| Low | GHSA-r6q2-hw4h-h46w | tar | 7.5.4 |
| Low | DEBIAN-CVE-2026-75803 | openssl | 3.5.7-1~deb13u2 |
| Low | DEBIAN-CVE-2026-84784 | openssl | 3.5.7-1~deb13u3 |
| Low | DEBIAN-CVE-2026-95619 | gcc-14 | no fix listed |
| Low | GHSA-w5hq-g745-h8pq | uuid | 11.1.1 |
| Low | DEBIAN-CVE-2026-5435 | glibc | no fix listed |
| Low | GHSA-rm97-x556-q36h | sanitize-html | 2.12.1 |
| Low | GHSA-6j4f-fj2g-mc7p | brace-expansion | 1.1.19 |
| Low | GHSA-qhr7-859c-m2p7 | brace-expansion | 1.1.20 |
| Low | GHSA-qwph-4952-7xr6 | jsonwebtoken | 9.0.0 |
| Low | GHSA-h39j-r5qq-r9mm | decompress | no fix listed |
| Low | DEBIAN-CVE-2026-19499 | glibc | no fix listed |
| Low | GHSA-2mjp-6q6p-2qxm | undici | 6.24.0 |
| Low | GHSA-2vr4-cq9g-pvrc | ip-address | 10.5.1 |
| Low | DEBIAN-CVE-2026-6238 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-63074 | openssl | 3.5.7-1~deb13u2 |
| Low | DEBIAN-CVE-2026-72897 | openssl | 3.5.7-1~deb13u3 |
| Low | GHSA-9ppj-qmqm-q256 | tar | 7.5.11 |
| Low | GHSA-xfqm-j7pc-xrfc | messageformat | 3.0.0-beta.0 |
| Low | GHSA-hjrf-2m68-5959 | jsonwebtoken | 9.0.0 |
| Low | GHSA-rpw4-54j3-4h4q | ip-address | 10.5.1 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| juice-shopjuice-shop | 5.9.0 | v20.2.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.