consensys/web3signer:latest container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of consensys/web3signer
consensys/web3signer:latest resolved to f146a51a1ba3, scanned 14 Sept 2026: 195 findings, 0 critical; deployed by 1 chart, among them web3signer.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
195 distinct on this digest
Findings for digest f146a51a1ba3 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-19487 | perl | 5.40.1-7ubuntu0.2 |
| Low | GHSA-cmm3-54f8-px4j | netty-codec-classes-quic | 4.2.15.Final |
| Low | UBUNTU-CVE-2026-35341 | rust-coreutils | no fix listed |
| Low | GHSA-5hh8-q8hv-fr38 | jackson-databind | 2.21.4 |
| Low | UBUNTU-CVE-2026-78408 | util-linux | no fix listed |
| Low | GHSA-hgj6-7826-r7m5 | jackson-databind | 2.21.4 |
| Low | UBUNTU-CVE-2026-54369 | acl | no fix listed |
| Low | UBUNTU-CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2.2 |
| Low | UBUNTU-CVE-2026-54371 | attr | 1:2.5.2-4ubuntu0.1 |
| Low | GHSA-5jmj-h7xm-6q6v | jackson-databind | 2.21.5 |
| Low | UBUNTU-CVE-2026-35352 | rust-coreutils | no fix listed |
| Low | GO-2026-4918 | golang.org/ | 0.53.0 |
| Low | GHSA-mfg7-5gfp-c4w3 | netty-codec-dns | 4.2.16.Final |
| Low | GHSA-gcjf-9mgh-3p7g | netty-codec-http | 4.2.16.Final |
| Low | GHSA-v8h7-rr48-vmmv | netty-codec-http | 4.2.13.Final |
| Low | UBUNTU-CVE-2026-78410 | util-linux | no fix listed |
| Low | GHSA-wc96-39fc-566f | netty-handler-ssl-ocsp | 4.2.16.Final |
| Low | GHSA-563q-j3cm-6jxm | netty-codec-http2 | 4.2.15.Final |
| Low | GO-2026-5026 | golang.org/ | 0.55.0 |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | GHSA-5x3r-wrvg-rp6q | netty-codec-http2 | 4.2.15.Final |
| Low | UBUNTU-CVE-2026-78409 | util-linux | no fix listed |
| Low | GO-2026-5972 | stdlib | 1.25.13 |
| Low | GO-2026-6088 | stdlib | 1.25.13 |
| Low | GO-2026-6089 | stdlib | 1.25.13 |
| Low | GO-2026-6090 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2026-35350 | rust-coreutils | no fix listed |
| Low | GHSA-3g76-f9xq-8vp6 | vertx-core | 4.5.27 |
| Low | UBUNTU-CVE-2026-13757 | p11-kit | no fix listed |
| Low | GO-2026-5942 | golang.org/ | 0.56.0 |
| Low | GO-2026-5942 | stdlib | 1.26.6 |
| Low | GHSA-hvcg-qmg6-jm4c | netty-codec-http | 4.2.15.Final |
| Low | GO-2026-4440 | golang.org/ | 0.45.0 |
| Low | GO-2026-6218 | stdlib | 1.25.13 |
| Low | GHSA-w67g-5rqw-f597 | github.com/ | 1.5.3 |
| Low | GO-2026-4441 | golang.org/ | 0.45.0 |
| Low | UBUNTU-CVE-2026-15534 | perl | 5.40.1-7ubuntu0.2 |
| Low | UBUNTU-CVE-2026-56391 | coreutils-from | 9.7-3ubuntu2.1 |
| Low | UBUNTU-CVE-2026-56391 | coreutils | 9.7-3ubuntu2.1 |
| Low | UBUNTU-CVE-2026-35363 | rust-coreutils | no fix listed |
| Low | GHSA-mhm7-754m-9p8w | jackson-databind | 2.21.5 |
| Low | UBUNTU-CVE-2026-35360 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-18938 | p11-kit | no fix listed |
| Low | UBUNTU-CVE-2025-5278 | coreutils-from | 9.7-3ubuntu2.1 |
| Low | UBUNTU-CVE-2025-5278 | coreutils | 9.7-3ubuntu2.1 |
| Low | GO-2026-5856 | stdlib | 1.25.12 |
| Low | GHSA-wh89-7897-x99h | netty-codec-haproxy | 4.2.16.Final |
| Low | UBUNTU-CVE-2026-35364 | rust-coreutils | no fix listed |
| Low | GHSA-cq4q-cv5g-r8q5 | netty-codec-classes-quic | 4.2.15.Final |
| Low | UBUNTU-CVE-2026-35348 | rust-coreutils | no fix listed |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| web3signerethereum-helm-chartsVerified publisher | 1.0.6 | latest | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.