craigwillis/c2metadata-bd:latest container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of craigwillis/c2metadata-bd
craigwillis/c2metadata-bd:latest resolved to ae317d7e4724, scanned 14 Sept 2026: 306 findings, 14 critical, 5 on KEV; deployed by 1 chart, among them polyglot.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
306 distinct on this digest
Findings for digest ae317d7e4724 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-j6qj-j888-vvgq | jetty-deploy | 9.4.39 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | GHSA-mq26-g339-26xf | pip | 23.3 |
| Low | GHSA-cpwx-vrp4-4pq7 | jinja2 | 3.1.6 |
| Low | GHSA-72pg-x5f8-j25j | spring-webmvc | no fix listed |
| Low | GHSA-87hc-h4r5-73f7 | werkzeug | 3.1.5 |
| Low | GHSA-mq64-j8f9-9gcj | spring-webmvc | no fix listed |
| Low | GHSA-r7wm-3cxj-wff9 | jackson-core | 2.18.8 |
| Low | GHSA-pq67-6m6q-mj2v | urllib3 | 2.5.0 |
| Low | GHSA-65pc-fj4g-8rjx | idna | 3.15 |
| Low | GHSA-9wx4-h78v-vm56 | requests | 2.32.0 |
| Low | GHSA-3chg-m5w7-qfv5 | spring-webmvc | no fix listed |
| Low | GHSA-hgj6-7826-r7m5 | jackson-databind | 2.18.8 |
| Low | GHSA-wxpp-56q6-5pcg | spring-expression | no fix listed |
| Low | GHSA-5jmj-h7xm-6q6v | jackson-databind | 2.18.9 |
| Low | GHSA-6p4f-wcwh-5vvm | spring-webmvc | no fix listed |
| Low | GHSA-qccp-gfcp-xxvc | urllib3 | 2.7.0 |
| Low | GHSA-qh8g-58pp-2wxh | jetty-http | 12.0.12 |
| Low | GHSA-x2r2-rvhq-2mqv | spring-security-web | no fix listed |
| Low | GHSA-7p3p-8qv8-m2vh | jetty-server | no fix listed |
| Low | GHSA-9cmq-m9j5-mvww | spring-expression | 5.3.39 |
| Low | GHSA-2c6g-pfx3-w7h8 | resteasy-multipart-provider | 3.15.5.Final |
| Low | GHSA-3gh6-v5v9-6v9j | jetty-servlets | 9.4.52 |
| Low | GHSA-293q-567p-wmwq | spring-security-web | no fix listed |
| Low | GHSA-q3v6-hm2v-pw99 | spring-security-core | 5.7.14 |
| Low | GHSA-m6cp-vxjx-65j6 | jetty-server | 9.4.41 |
| Low | GHSA-7g45-4rm6-3mm3 | guava | 32.0.0-android |
| Low | GHSA-g4mx-q9vg-27p4 | urllib3 | 1.26.18 |
| Low | GHSA-25qh-j22f-pwp8 | logback-core | 1.3.16 |
| Low | GHSA-5mg8-w23w-74h3 | guava | 32.0.0-android |
| Low | GHSA-pwh8-58vv-vw48 | jetty-openid | 9.4.52.v20230823 |
| Low | GHSA-957g-f97v-vppc | spring-webmvc | no fix listed |
| Low | PYSEC-2026-2275 | requests | 2.33.0 |
| Low | GHSA-cjpg-rgq5-fr37 | spring-webmvc | no fix listed |
| Low | PYSEC-2026-2151 | flask | 3.1.3 |
| Low | GHSA-wf8f-6423-gfxg | jackson-core | 2.13.0 |
| Low | GHSA-cj7v-27pg-wf7q | jetty-http | 9.4.47 |
| Low | GHSA-jp4c-xjxw-mgf9 | pip | 26.1 |
| Low | GHSA-p26g-97m4-6q7c | jetty-server | 9.4.51.v20230217 |
| Low | GHSA-3m2r-q8x3-xmf7 | Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions | 2.0.3 |
| Low | GHSA-3m2r-q8x3-xmf7 | Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv | 2.0.3 |
| Low | GHSA-3m2r-q8x3-xmf7 | Microsoft.AspNetCore.Server.Kestrel.Core | 2.0.3 |
| Low | GHSA-cgpw-2gph-2r9g | Microsoft.AspNetCore.Server.Kestrel.Core | 2.0.4 |
| Low | GHSA-659m-px2c-25wj | spring-core | no fix listed |
| Low | GHSA-58qw-9mgm-455v | pip | 26.1 |
| Low | GHSA-4wp7-92pw-q264 | spring-context | no fix listed |
| Low | GHSA-h3qp-gqrc-q736 | spring-webmvc | no fix listed |
| Low | GHSA-9f52-rjqv-25qv | spring-expression | no fix listed |
| Low | GHSA-px8h-6qxv-m22q | werkzeug | 2.2.3 |
| Low | GHSA-wjpw-4j6x-6rwh | jetty-http | no fix listed |