gocd/gocd-server:v26.1.0 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of gocd/gocd-server
gocd/gocd-server:v26.1.0 resolved to 720d1012b93f, scanned 14 Sept 2026: 64 findings, 4 critical, 2 on KEV; deployed by 1 chart, among them gocd.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
64 distinct on this digest
Findings for digest 720d1012b93f as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | GHSA-36p3-wjmg-h94xKEV | spring-beans | 5.2.20.RELEASE |
| Critical | GHSA-36p3-wjmg-h94xKEV | spring-webmvc | 5.2.20.RELEASE |
| Critical | GHSA-45hx-wfhj-473x | h2 | 2.1.210 |
| Critical | GHSA-h376-j262-vhq6 | h2 | 2.0.206 |
| High | GHSA-4wrc-f8pq-fpqp | spring-web | 6.0.0 |
| High | GHSA-g5vr-rgqm-vf78 | spring-webmvc | no fix listed |
| High | GHSA-hh32-7344-cg2f | spring-security-web | 5.4.11 |
| High | GHSA-hh32-7344-cg2f | spring-security-core | 5.4.11 |
| High | GHSA-558x-2xjg-6232 | spring-expression | 5.2.20.RELEASE |
| Medium | GHSA-g5mm-vmx4-3rg7 | spring-context | 5.2.21.RELEASE |
| Medium | GHSA-gq28-h5vg-8prx | spring-security-web | 5.2.9 |
| Medium | GHSA-ccgv-vj62-xf9h | spring-web | no fix listed |
| Medium | GHSA-7rpj-hg47-cx62 | h2 | 2.0.202 |
| Medium | GHSA-hgjh-9rj2-g67j | spring-web | 5.3.33 |
| Medium | GHSA-j8jw-g6fq-mp7h | hibernate-core | 5.3.20.Final |
| Medium | GHSA-hh26-6xwr-ggv7 | spring-beans | 5.2.22.RELEASE |
| Medium | GHSA-2wrp-6fg6-hmc5 | spring-web | 5.3.34 |
| Medium | GHSA-8grg-q944-cch5 | hibernate-core | 5.3.18 |
| Medium | GHSA-355h-qmc2-wpwf | jetty-http | 10.0.28 |
| Medium | GHSA-f3jh-qvm4-mg39 | spring-security-core | 5.7.12 |
| Medium | GHSA-wxqc-pxw9-g2p8 | spring-expression | 5.2.24.RELEASE |
| Medium | GHSA-mf92-479x-3373 | spring-security-web | no fix listed |
| Low | GHSA-2fvj-hgj9-j2gr | jetty-security | 10.0.31 |
| Low | CGA-35mx-c7ph-5wqg | openssl | 3.6.3-r5 |
| Low | GHSA-564r-hj7v-mcr5 | spring-expression | 5.2.23.RELEASE |
| Low | CGA-6ph6-75jp-484p | zlib | 1.3.3-r0 |
| Low | GHSA-x23c-287f-qqv5 | spring-webmvc | no fix listed |
| Low | GHSA-r5w3-xv2f-j59q | spring-expression | no fix listed |
| Low | CGA-pg7p-jc78-5qw9 | glibc | 2.43-r10 |
| Low | GHSA-22wj-vf5f-wrvj | h2 | 2.2.220 |
| Low | GHSA-2rmj-mq67-h97g | spring-web | 5.3.38 |
| Low | GHSA-775g-4xr8-78h8 | spring-expression | no fix listed |
| Low | CGA-6vrx-5w7p-6phj | openssl | 3.6.3-r4 |
| Low | GHSA-5gvw-p9qm-jgwh | jackson-databind | 2.22.1 |
| Low | GHSA-4gc7-5j7h-4qph | spring-web | no fix listed |
| Low | GHSA-4gc7-5j7h-4qph | spring-context | no fix listed |
| Low | GHSA-72pg-x5f8-j25j | spring-webmvc | no fix listed |
| Low | GHSA-mq64-j8f9-9gcj | spring-webmvc | no fix listed |
| Low | CGA-7g67-8qrj-cr3q | nghttp2 | 1.70.0-r0 |
| Low | GHSA-3chg-m5w7-qfv5 | spring-webmvc | no fix listed |
| Low | GHSA-wxpp-56q6-5pcg | spring-expression | no fix listed |
| Low | GHSA-5jmj-h7xm-6q6v | jackson-databind | 2.22.1 |
| Low | GHSA-6p4f-wcwh-5vvm | spring-webmvc | no fix listed |
| Low | GHSA-qh8g-58pp-2wxh | jetty-http | 12.0.12 |
| Low | GHSA-x2r2-rvhq-2mqv | spring-security-web | no fix listed |
| Low | GHSA-7p3p-8qv8-m2vh | jetty-server | no fix listed |
| Low | GHSA-9cmq-m9j5-mvww | spring-expression | 5.3.39 |
| Low | GHSA-293q-567p-wmwq | spring-security-web | no fix listed |
| Low | GHSA-q3v6-hm2v-pw99 | spring-security-core | 5.7.14 |
| Low | CGA-9f3f-x983-mfhp | curl | 8.22.0-r2 |