StackRadar

broadinstitute/dsde-toolbox:master container image

Docker Hub

Scanned 28 Sept 2026

Deployed by 1 of 17,926 indexed charts (latest versions) at this tag.Docker Hub all tags of broadinstitute/dsde-toolbox

broadinstitute/dsde-toolbox:master resolved to 656131886a08, scanned 28 Sept 2026: 407 findings, 0 critical, 1 on KEV; deployed by 1 chart, among them sqlbackup.

Radar Score

5,376011104292

407 findings on digest 656131886a08 · scanned 28 Sept 2026

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
masterresolves to656131886a081 charttoday0111042925,376

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

407 distinct on this digest

Findings for digest 656131886a08 as scanned on 28 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 28 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGHSA-7gcm-g887-7qv7protobuf@5.27.25.29.6
MediumGHSA-hcg3-q754-cr77golang.org/x/crypto@v0.0.0-20210817164053-32db794688a50.35.0
MediumGHSA-jr27-m4p2-rc6rpyasn1@0.6.00.6.3
MediumGHSA-5m6q-g25r-mvwxnode-forge@0.7.61.4.0
MediumGHSA-pf86-5x62-jrwfaxios@0.18.00.31.1
MediumGO-2022-1144stdlib@go1.16.101.18.9
MediumGHSA-6v2p-p543-phr9golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d0.27.0
MediumGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.0.0-20210817164053-32db794688a50.52.0
MediumGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.0.0-20210817164053-32db794688a50.52.0
MediumGHSA-3xgq-45jj-v275cross-spawn@5.1.06.0.6
MediumGHSA-pfrx-2q88-qq97got@6.7.111.8.5
MediumGHSA-3ppc-4f35-3m26minimatch@3.0.43.1.3
MediumGHSA-8449-7gc2-pwrpgithub.com/hashicorp/consul-template@v0.27.2-0.20211014231529-4ff55381f1c40.27.3
MediumGHSA-34x7-hfp2-rc4vtar@4.4.197.5.7
MediumGHSA-5xp3-jfq3-5q8xpip@20.1.121.1
LowGHSA-vcc3-ghjq-m6frdecode-uri-component@0.2.00.5.0
LowGHSA-cfm4-qjh2-4765node-forge@0.7.61.3.0
LowGHSA-j5f8-grm9-p9fcaxios@0.18.00.32.0
LowGHSA-vg3r-rm7w-2xghrexml@3.2.3.13.2.7
LowGHSA-wpfp-cm49-9m9qgithub.com/hashicorp/go-slug@v0.7.00.16.3
LowGO-2023-1571stdlib@go1.16.101.19.6
LowGHSA-cxjh-pqwp-8mfpfollow-redirects@1.5.101.15.6
LowGHSA-554w-wpv2-vw27node-forge@0.7.61.3.2
LowGHSA-hmw2-7cc7-3qxxform-data@2.3.32.5.6
LowGHSA-j5g9-f88f-gfj3httplib2@0.22.00.32.0
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowGHSA-23hp-3jrh-7fpwtar@4.4.197.5.19
LowGHSA-8x88-c5mf-7j5wtar@4.4.197.5.18
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.111.1.17
LowGHSA-r4q5-vmmm-2653follow-redirects@1.5.101.16.0
LowGHSA-7vpp-9cxj-q8gvgithub.com/mholt/archiver@v3.1.1+incompatibleno fix listed
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.0.0-20210817164053-32db794688a50.52.0
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.0.0-20210817164053-32db794688a50.52.0
LowGO-2022-0435stdlib@go1.16.101.17.9
LowGHSA-8ppf-4f7h-5ppjpyasn1@0.6.00.6.4
LowGHSA-hm4w-wwcw-mr6rpyasn1@0.6.00.6.4
LowGHSA-m4p7-r5rc-7g4jpyasn1@0.6.00.6.4
LowGHSA-pw2r-vq6v-hr8cfollow-redirects@1.5.101.14.8
LowGHSA-f5x3-32g6-xq36tar@4.4.196.2.1
LowGO-2022-0288golang.org/x/net@v0.0.0-20210226172049-e18ecbb051100.0.0-20211209124913-491a49abca63
LowGO-2022-0288stdlib@go1.16.101.16.12
LowGHSA-hww2-5g85-429muri@0.10.00.10.0.3
LowGHSA-7r86-cg39-jmmjminimatch@3.0.43.1.3
LowGHSA-vmwr-mc7x-5vc3rexml@3.2.3.13.3.6
LowGO-2023-2102stdlib@go1.16.101.20.10
LowGHSA-xqr8-7jwr-rhp7certifi@2020.4.5.12023.7.22
LowGHSA-wf93-45jw-7689pip@20.1.126.1.2
LowGHSA-j4pr-3wm6-xx2ruri@0.10.00.12.5
LowGHSA-r292-9mhp-454mtar@4.4.197.5.21
LowGHSA-pjcq-xvwq-hhpjgithub.com/Azure/go-ntlmssp@v0.0.0-20200615164410-66371956d46c0.1.1

Used by

1 chart
ChartVersionTagContainers
sqlbackupdatarepo0.0.3master2

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 28 Sept 2026 · advisories as of 28 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.