chatwoot/chatwoot:v4.15.1 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of chatwoot/chatwoot
chatwoot/chatwoot:v4.15.1 resolved to 67ebc751c171, scanned 14 Sept 2026: 288 findings, 0 critical; deployed by 1 chart, among them chatwoot.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
288 distinct on this digest
Findings for digest 67ebc751c171 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | GHSA-xr9x-r78c-5hrm | activestorage | 7.2.3.2 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| High | GHSA-w573-4hg7-7wgq | decode-uri-component | 0.2.1 |
| High | GHSA-3jfq-g458-7qm9 | tar | 3.2.2 |
| Medium | GHSA-hrpp-h998-j3pp | qs | 6.5.3 |
| Medium | GHSA-2p57-rm9w-gvfp | ip | no fix listed |
| Medium | GHSA-xvch-5gv4-984h | minimist | 1.2.6 |
| Medium | GHSA-r628-mhmh-qjhw | tar | 6.1.2 |
| Medium | GHSA-896r-f27r-55mw | json-schema | 0.4.0 |
| Medium | GHSA-9c47-m6qq-7p4h | json5 | 1.0.2 |
| Medium | GHSA-76p3-8jx3-jpfq | loader-utils | 2.0.3 |
| Medium | GHSA-vx3p-948g-6vhq | ssri | 7.1.1 |
| Medium | GHSA-9r2w-394v-53qc | tar | 6.1.7 |
| Medium | GHSA-fwr7-v2mv-hh25 | async | 2.6.4 |
| Medium | GHSA-93q8-gq69-wqmw | ansi-regex | 3.0.1 |
| Medium | GHSA-6h5x-7c5m-7cr7 | eventsource | 1.1.1 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 2.5.4 |
| Medium | GHSA-hgjh-723h-mx2j | url-parse | 1.5.8 |
| Medium | GHSA-4wf5-vphf-c2xc | terser | 4.8.1 |
| Medium | ALPINE-CVE-2021-27219 | glib | 2.66.6-r0 |
| Medium | GHSA-74fj-2j2h-c42q | follow-redirects | 1.14.7 |
| Medium | GHSA-7p7h-4mm5-852v | trim-newlines | 3.0.1 |
| Medium | GHSA-c2qf-rxjj-qqgw | semver | 5.7.2 |
| Medium | GHSA-qq89-hq3f-393p | tar | 6.1.9 |
| Medium | GHSA-hhq3-ff78-jv3g | loader-utils | 2.0.4 |
| Medium | GHSA-3rfm-jhwj-7488 | loader-utils | 2.0.4 |
| Medium | GHSA-rp65-9cf3-cjxr | nth-check | 2.0.1 |
| Medium | GHSA-7mwh-4pqv-wmr8 | scss-tokenizer | 0.4.3 |
| Medium | GHSA-whgm-jr23-g3j9 | ansi-html | 0.0.8 |
| Medium | GHSA-f8q6-p94x-37v3 | minimatch | 3.0.5 |
| Medium | GHSA-72xf-g2v4-qvf3 | tough-cookie | 4.1.3 |
| Medium | GHSA-5955-9wpr-37jh | tar | 4.4.18 |
| Medium | GHSA-3wcq-x3mq-6r9p | dns-packet | 1.3.2 |
| Medium | GHSA-rf6f-7fwh-wjgh | flatted | 3.4.2 |
| Medium | GHSA-grv7-fg5c-xmjg | braces | 3.0.3 |
| Medium | GHSA-jf5r-8hm2-f872 | url-parse | 1.5.9 |
| Medium | ALPINE-CVE-2025-54874 | openjpeg | 2.5.4-r0 |
| Medium | GHSA-q339-8rmv-2mhv | erb | 4.0.4.1 |
| Medium | GHSA-3h5v-q93c-6h6q | ws | 6.2.3 |
| Medium | GHSA-g857-hhfv-j68w | zlib | 3.2.3 |
| Medium | GHSA-hwj9-h5mp-3pm3 | postcss | 7.0.36 |
| Medium | GHSA-95m3-7q98-8xr5 | sha.js | 2.4.12 |
| Medium | GHSA-wr3j-pwj9-hqq6 | webpack-dev-middleware | 5.3.4 |
| Medium | GHSA-5gfm-wpxj-wjgq | node-forge | 1.3.2 |
| Medium | GHSA-x4jg-mjrx-434g | node-forge | 1.3.0 |
| Medium | ALPINE-CVE-2026-14669 | postgresql17 | 17.11-r0 |
| Medium | GHSA-9xrj-h377-fr87 | activestorage | 7.2.3.1 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-c7qv-q95q-8v27 | http-proxy-middleware | 2.0.7 |