StackRadar

craigwillis/c2metadata-bd:latest container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of craigwillis/c2metadata-bd

craigwillis/c2metadata-bd:latest resolved to ae317d7e4724, scanned 14 Sept 2026: 306 findings, 14 critical, 5 on KEV; deployed by 1 chart, among them polyglot.

Radar Score

8,020144615393

306 findings on digest ae317d7e4724 · scanned 14 Sept 2026

KEV ×5 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
latestresolves toae317d7e47241 chart6 days ago1446153938,020

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

93 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest ae317d7e4724 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-wxpp-56q6-5pcgspring-expression@4.1.1.RELEASEno fix listed
LowGHSA-5jmj-h7xm-6q6vjackson-databind@2.8.62.18.9
LowGHSA-6p4f-wcwh-5vvmspring-webmvc@4.3.3.RELEASEno fix listed
LowGHSA-qccp-gfcp-xxvcurllib3@1.26.12.7.0
LowGHSA-qh8g-58pp-2wxhjetty-http@9.4.32.v2020093012.0.12
LowGHSA-x2r2-rvhq-2mqvspring-security-web@4.1.3.RELEASEno fix listed
LowGHSA-7p3p-8qv8-m2vhjetty-server@9.4.32.v20200930no fix listed
LowGHSA-9cmq-m9j5-mvwwspring-expression@4.1.1.RELEASE5.3.39
LowGHSA-2c6g-pfx3-w7h8resteasy-multipart-provider@3.0.9.Final3.15.5.Final
LowGHSA-3gh6-v5v9-6v9jjetty-servlets@9.4.32.v202009309.4.52
LowGHSA-293q-567p-wmwqspring-security-web@4.1.3.RELEASEno fix listed
LowGHSA-q3v6-hm2v-pw99spring-security-core@4.1.3.RELEASE5.7.14
LowGHSA-m6cp-vxjx-65j6jetty-server@9.4.32.v202009309.4.41
LowGHSA-7g45-4rm6-3mm3guava@20.032.0.0-android
LowGHSA-g4mx-q9vg-27p4urllib3@1.26.11.26.18
LowGHSA-25qh-j22f-pwp8logback-core@1.0.131.3.16
LowGHSA-5mg8-w23w-74h3guava@20.032.0.0-android
LowGHSA-pwh8-58vv-vw48jetty-openid@9.4.32.v202009309.4.52.v20230823
LowGHSA-957g-f97v-vppcspring-webmvc@4.3.3.RELEASEno fix listed
LowPYSEC-2026-2275requests@2.25.02.33.0
LowGHSA-cjpg-rgq5-fr37spring-webmvc@4.3.3.RELEASEno fix listed
LowPYSEC-2026-2151flask@1.1.23.1.3
LowGHSA-wf8f-6423-gfxgjackson-core@2.2.32.13.0
LowGHSA-cj7v-27pg-wf7qjetty-http@9.4.32.v202009309.4.47
LowGHSA-jp4c-xjxw-mgf9pip@20.1.126.1
LowGHSA-p26g-97m4-6q7cjetty-server@9.4.32.v202009309.4.51.v20230217
LowGHSA-3m2r-q8x3-xmf7Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv@2.0.02.0.3
LowGHSA-3m2r-q8x3-xmf7Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions@2.0.02.0.3
LowGHSA-3m2r-q8x3-xmf7Microsoft.AspNetCore.Server.Kestrel.Core@2.0.02.0.3
LowGHSA-cgpw-2gph-2r9gMicrosoft.AspNetCore.Server.Kestrel.Core@2.0.02.0.4
LowGHSA-659m-px2c-25wjspring-core@4.3.2.RELEASEno fix listed
LowGHSA-58qw-9mgm-455vpip@20.1.126.1
LowGHSA-4wp7-92pw-q264spring-context@4.1.1.RELEASEno fix listed
LowGHSA-h3qp-gqrc-q736spring-webmvc@4.3.3.RELEASEno fix listed
LowGHSA-9f52-rjqv-25qvspring-expression@4.1.1.RELEASEno fix listed
LowGHSA-px8h-6qxv-m22qwerkzeug@1.0.12.2.3
LowGHSA-wjpw-4j6x-6rwhjetty-http@9.4.32.v20200930no fix listed
LowGHSA-wg35-8jpf-2xv3spring-webmvc@4.3.3.RELEASEno fix listed
LowGHSA-58qw-p7qm-5rvhjetty-xml@9.4.32.v202009309.4.52.v20230823
LowGHSA-p47f-322f-whfhlogback-core@1.0.131.5.33
LowGHSA-6vgw-5pg2-w6jppip@20.1.126.0
LowGHSA-6v67-2wr5-gvf4logback-core@1.0.131.3.15
LowGHSA-qqpg-mvqg-649vlogback-core@1.0.131.5.25

Used by

1 chart
ChartVersionTagContainers
polyglotncsaVerified publisher0.1.1latest1

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.