StackRadar

bkimminich/juice-shop:v20.2.0 container image

Docker Hub

Scanned 7 Oct 2026

Deployed by 1 of 18,035 indexed charts (latest versions) at this tag.Docker Hub all tags of bkimminich/juice-shop

bkimminich/juice-shop:v20.2.0 resolved to 8739101ade29, scanned 7 Oct 2026: 156 findings, 0 critical; deployed by 1 chart, among them juice-shop.

Radar Score

2,0110241113

156 findings on digest 8739101ade29 · scanned 7 Oct 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v20.2.0resolves to8739101ade291 charttoday02411132,011

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

156 distinct on this digest

Findings for digest 8739101ade29 as scanned on 7 Oct 2026 with syft 1.42.1 for linux/amd64, advisories as of 7 Oct 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-rjqq-98f6-6j3rsanitize-html@1.4.22.3.1
LowGHSA-g5hg-p3ph-g8qgmulter@1.4.5-lts.22.0.1
LowGHSA-8g4m-cjm2-96wqnotevil@1.3.3no fix listed
LowGHSA-23hp-3jrh-7fpwtar@6.2.17.5.19
LowGHSA-8x88-c5mf-7j5wtar@6.2.17.5.18
LowGHSA-r635-g3xr-vw7xengine.io@4.1.26.6.7
LowGHSA-8cf7-32gw-wr33jsonwebtoken@0.4.09.0.0
LowGHSA-2m8v-j782-fhvrsocket.io-parser@4.0.54.2.7
LowDEBIAN-CVE-2026-54874openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
LowGHSA-mjxr-4v3x-q3m4sanitize-html@1.4.22.3.2
LowGHSA-vc2v-76pw-4v95compression@1.8.11.8.2
LowGHSA-7r86-cg39-jmmjminimatch@3.0.53.1.3
LowGHSA-jqcg-44mw-7w3hproxy-addr@2.0.72.0.8
LowDEBIAN-CVE-2026-6791glibc@2.41-12+deb13u3no fix listed
LowGHSA-2883-xcg3-v3hhjs-yaml@3.15.13.15.2
LowGHSA-xc6g-ggrc-qq4rsanitize-html@1.4.21.11.4
LowGHSA-ch52-4w7c-c8xphttp-cache-semantics@4.2.0no fix listed
LowGHSA-r292-9mhp-454mtar@6.2.17.5.21
LowGHSA-qffp-2rhf-9h96tar@6.2.17.5.10
LowDEBIAN-CVE-2026-84782openssl@3.5.6-1~deb13u23.5.7-1~deb13u3
LowGHSA-23c5-xmqv-rm74minimatch@3.0.53.1.4
LowGHSA-8qq5-rm4j-mr97tar@6.2.17.5.3
LowDEBIAN-CVE-2026-5928glibc@2.41-12+deb13u32.41-12+deb13u4
LowGHSA-x8mw-p69m-v3mx@fastify/busboy@2.1.13.2.1
LowGHSA-535w-7cp7-47q4multer@1.4.5-lts.22.3.0
LowGHSA-72gw-mp4g-v24jmulter@1.4.5-lts.22.2.0
LowGHSA-wc9g-mqfw-jrwmmulter@1.4.5-lts.22.3.0
LowDEBIAN-CVE-2026-54873openssl@3.5.6-1~deb13u23.5.7-1~deb13u3
LowGHSA-3j7m-hmh3-9jmpsanitize-html@1.4.21.4.3
LowGHSA-r6q2-hw4h-h46wtar@6.2.17.5.4
LowDEBIAN-CVE-2026-75803openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
LowDEBIAN-CVE-2026-84784openssl@3.5.6-1~deb13u23.5.7-1~deb13u3
LowDEBIAN-CVE-2026-95619gcc-14@14.2.0-19no fix listed
LowGHSA-w5hq-g745-h8pquuid@8.3.211.1.1
LowDEBIAN-CVE-2026-5435glibc@2.41-12+deb13u3no fix listed
LowGHSA-rm97-x556-q36hsanitize-html@1.4.22.12.1
LowGHSA-6j4f-fj2g-mc7pbrace-expansion@1.1.181.1.19
LowGHSA-qhr7-859c-m2p7brace-expansion@1.1.181.1.20
LowGHSA-qwph-4952-7xr6jsonwebtoken@0.4.09.0.0
LowGHSA-h39j-r5qq-r9mmdecompress@4.2.1no fix listed
LowDEBIAN-CVE-2026-19499glibc@2.41-12+deb13u3no fix listed
LowGHSA-2mjp-6q6p-2qxmundici@5.29.06.24.0
LowGHSA-2vr4-cq9g-pvrcip-address@10.5.010.5.1
LowDEBIAN-CVE-2026-6238glibc@2.41-12+deb13u3no fix listed
LowDEBIAN-CVE-2026-63074openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
LowDEBIAN-CVE-2026-72897openssl@3.5.6-1~deb13u23.5.7-1~deb13u3
LowGHSA-9ppj-qmqm-q256tar@6.2.17.5.11
LowGHSA-xfqm-j7pc-xrfcmessageformat@2.3.03.0.0-beta.0
LowGHSA-hjrf-2m68-5959jsonwebtoken@0.4.09.0.0
LowGHSA-rpw4-54j3-4h4qip-address@10.5.010.5.1

Used by

1 chart
ChartVersionTagContainers
juice-shopjuice-shop5.9.0v20.2.01

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 7 Oct 2026 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.