StackRadar

craigwillis/c2metadata-bd:latest container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of craigwillis/c2metadata-bd

craigwillis/c2metadata-bd:latest resolved to ae317d7e4724, scanned 14 Sept 2026: 306 findings, 14 critical, 5 on KEV; deployed by 1 chart, among them polyglot.

Radar Score

8,020144615393

306 findings on digest ae317d7e4724 · scanned 14 Sept 2026

KEV ×5 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
latestresolves toae317d7e47241 chart6 days ago1446153938,020

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

306 distinct on this digest

Findings for digest ae317d7e4724 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
CriticalGHSA-36p3-wjmg-h94xKEVspring-webmvc@4.3.3.RELEASE5.2.20.RELEASE
CriticalGHSA-36p3-wjmg-h94xKEVspring-beans@4.1.1.RELEASE5.2.20.RELEASE
CriticalGHSA-2qrg-x229-3v8qlog4j@1.2.16no fix listed
CriticalGHSA-5rrx-jjjq-q2r5Microsoft.AspNetCore.Server.Kestrel.Core@2.0.02.3.6
CriticalGHSA-65fg-84f6-3jq3log4j@1.2.16no fix listed
CriticalGHSA-mjmj-j48q-9wg2snakeyaml@1.122.0
CriticalGHSA-f7vh-qwp3-x37mlog4j@1.2.16no fix listed
CriticalGHSA-rfx6-vp9g-rh7vjackson-databind@2.5.02.7.9.2
CriticalGHSA-w9p3-5cr8-m3jjlog4j@1.2.16no fix listed
CriticalGHSA-vmch-3w2x-vhgqKEVMicrosoft.AspNetCore.Server.Kestrel.Transport.Libuv@2.0.02.1.40
CriticalGHSA-p66x-2cv9-qq3vcommons-beanutils@1.8.31.9.4
CriticalGHSA-vv7r-c36w-3prjcommons-fileupload@1.3.11.6.0
CriticalGHSA-qxxx-2pp7-5hmxjackson-databind@2.5.02.6.7.1
CriticalGHSA-xx68-jfcg-xmmfcommons-fileupload@1.31.3.1
HighGHSA-fp5r-v3w9-4333log4j@1.2.16no fix listed
HighGHSA-7x9j-7223-rg5mcommons-fileupload@1.3.11.3.3
HighGHSA-4wrc-f8pq-fpqpspring-web@4.1.1.RELEASE6.0.0
HighGHSA-ghhp-997w-qr28System.Text.Encodings.Web@4.4.04.5.1
HighGHSA-4w82-r329-3q67jackson-databind@2.5.02.6.7.4
HighGHSA-g5vr-rgqm-vf78spring-webmvc@4.3.3.RELEASEno fix listed
HighGHSA-26vr-8j45-3r4wjetty-server@9.4.32.v202009309.4.39
HighGHSA-hfrx-6qgj-fp6ccommons-fileupload@1.3.11.5
HighGHSA-cggj-fvv3-cqwvjackson-databind@2.5.02.6.7.5
HighGHSA-6x9x-8qw9-9pp6jetty-server@9.2.10.v201503109.2.25.v20180606
HighGHSA-q93h-jc49-78ggjackson-databind@2.5.02.7.9.7
HighGHSA-p43x-xfjf-5jhrjackson-databind@2.5.02.7.9.7
HighGHSA-fvm3-cfvj-gxqqcommons-fileupload@1.3.11.3.2
HighGHSA-qppj-fm5r-hxr3KEVhttp2-server@9.4.32.v202009309.4.53
HighGHSA-qppj-fm5r-hxr3KEVhttp2-common@9.4.32.v202009309.4.53
HighGHSA-vgg8-72f2-qm23jetty-server@9.2.10.v201503109.2.25.v20180606
HighGHSA-5crp-9r3c-p9vrNewtonsoft.Json@10.0.313.0.1
HighGHSA-645p-88qh-w398jackson-databind@2.5.02.6.7.3
HighGHSA-gwcr-j4wh-j3cqjetty-servlets@9.4.32.v202009309.4.41
HighGHSA-hh32-7344-cg2fspring-security-core@4.1.3.RELEASE5.4.11
HighGHSA-hh32-7344-cg2fspring-security-web@4.1.3.RELEASE5.4.11
HighGHSA-m394-8rww-3jr7jetty-server@9.4.32.v202009309.4.37
HighGHSA-6phf-73q6-gh87commons-beanutils@1.8.31.9.4
HighGHSA-rvwf-54qp-4r6vsnakeyaml@1.121.26
HighGHSA-9gph-22xh-8x98jackson-databind@2.5.02.6.7.5
HighGHSA-9mxf-g3x6-wv74jackson-databind@2.8.62.8.11.3
HighGHSA-h822-r4r5-v8jgjackson-databind@2.5.02.6.7.3
HighGHSA-c8hm-7hpq-7jhgjackson-databind@2.5.02.6.7.3
HighGHSA-f9hv-mg5h-xcw9jackson-databind@2.8.62.8.11.3
HighGHSA-mx9v-gmh4-mgqwjackson-databind@2.8.62.8.11.3
HighGHSA-558x-2xjg-6232spring-expression@4.1.1.RELEASE5.2.20.RELEASE
HighGHSA-mph4-vhrx-mv67jackson-databind@2.5.02.6.7.3
HighGHSA-5ww9-j83m-q7qxjackson-databind@2.5.02.6.7.3
HighGHSA-4gq5-ch57-c2mgjackson-databind@2.5.02.7.9.5
HighGHSA-gww7-p5w4-wrfvjackson-databind@2.5.02.6.7.4
HighGHSA-h592-38cm-4ggpjackson-databind@2.5.02.6.7.3

Used by

1 chart
ChartVersionTagContainers
polyglotncsaVerified publisher0.1.1latest1

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.