gradiant/spark:2.4.4-python-alpine container image
Docker HubScanned 14 Sept 2026
Deployed by 2 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of gradiant/spark
gradiant/spark:2.4.4-python-alpine resolved to 97657d56e927, scanned 14 Sept 2026: 213 findings, 10 critical, 2 on KEV; deployed by 2 charts, among them spark-standalone and spark-standalone.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
213 distinct on this digest
Findings for digest 97657d56e927 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-98wm-3w3q-mw94 | snakeyaml | 1.31 |
| Medium | GHSA-5545-2q6w-2gh6 | numpy | 1.19 |
| Medium | GHSA-qw69-rqj8-6qw8 | jetty-server | 9.4.51.v20230217 |
| Medium | GHSA-h46c-h94j-95f3 | jackson-core | 2.15.0 |
| Medium | GHSA-hxp5-8pgq-mgv9 | calcite-core | 1.26.0 |
| Medium | GHSA-w37g-rhq8-7m4j | snakeyaml | 1.32 |
| Medium | GHSA-5mcr-gq6c-3hq2 | netty | no fix listed |
| Medium | GHSA-3cqm-mf7h-prrj | okhttp | 4.9.2 |
| Medium | GHSA-g5ww-5jh7-63cx | protobuf-java | 3.16.3 |
| Medium | GHSA-5xp3-jfq3-5q8x | pip | 21.1 |
| Medium | ALPINE-CVE-2020-29362 | p11-kit | 0.23.16.1-r1 |
| Low | GHSA-973x-65j7-xcf4 | aircompressor | 0.27 |
| Low | GHSA-77pm-w3hx-f8mj | spark-hive-thriftserver_2.11 | no fix listed |
| Low | ALPINE-CVE-2019-5188 | e2fsprogs | 1.45.5-r0 |
| Low | GHSA-4gg5-vx3j-xwc7 | protobuf-java | 3.16.3 |
| Low | GHSA-vx9q-rhv9-3jvg | aircompressor | 2.0.3 |
| Low | ALPINE-CVE-2020-14363 | libx11 | 1.6.12-r0 |
| Low | GHSA-w33c-445m-f8w7 | okio | 1.17.6 |
| Low | GHSA-8wv5-x4w7-5gww | libthrift | 0.24.0 |
| Low | GHSA-43xg-8wmj-cw8h | pyspark | 3.2.2 |
| Low | GHSA-43xg-8wmj-cw8h | spark-core_2.11 | no fix listed |
| Low | ALPINE-CVE-2020-8315 | python3 | 3.7.7-r0 |
| Low | GHSA-7pwc-h2j2-rjgj | libthrift | 0.23.0 |
| Low | GHSA-fpfv-jqm9-f5jm | numpy | 1.22 |
| Low | PYSEC-2020-108 | scikit-learn | 0.24.dev0 |
| Low | PYSEC-2020-73 | pandas | 1.0.4 |
| Low | GHSA-g8m5-722r-8whq | jetty-server | 9.4.56 |
| Low | GHSA-h4h5-3hr4-j3g2 | protobuf-java | 3.16.3 |
| Low | GHSA-hhhw-99gj-p3c3 | snakeyaml | 1.31 |
| Low | ALPINE-CVE-2019-1563 | openssl | 1.1.1d-r0 |
| Low | GHSA-wf93-45jw-7689 | pip | 26.1.2 |
| Low | GHSA-6p56-wp2h-9hxr | numpy | 1.21 |
| Low | GHSA-hmr7-m48g-48f6 | jetty-http | 9.4.52 |
| Low | ALPINE-CVE-2021-23839 | openssl | 1.1.1j-r0 |
| Low | GHSA-j26w-f9rq-mr2q | jetty-servlets | 9.4.54 |
| Low | ALPINE-CVE-2020-14344 | libx11 | 1.6.10-r0 |
| Low | ALPINE-CVE-2019-1547 | openssl | 1.1.1d-r0 |
| Low | ALPINE-CVE-2020-28928 | musl | 1.1.22-r4 |
| Low | GHSA-4xh5-x5gv-qwph | pip | 25.3 |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | GHSA-4g9r-vxhx-9pgx | commons-compress | 1.26.0 |
| Low | PYSEC-2023-114 | scipy | 1.8.0 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | GHSA-mq26-g339-26xf | pip | 23.3 |
| Low | GHSA-8wh2-6qhj-h7j9 | snappy | 0.5 |
| Low | GHSA-r7wm-3cxj-wff9 | jackson-core | 2.18.8 |
| Low | GHSA-f7c7-j99h-c22f | numpy | 1.19 |
| Low | PYSEC-2025-184 | pyspark | 3.4.4 |
| Low | GHSA-hgj6-7826-r7m5 | jackson-databind | 2.18.8 |
| Low | GHSA-qh8g-58pp-2wxh | jetty-http | 12.0.12 |
Used by
2 charts
| Chart | Version | Tag | Containers |
|---|---|---|---|
| spark-standalonedmwm-bigdataVerified publisher | 0.1.0 | 2.4.4-python-alpine | 2 |
| spark-standalonegradiant-bigdataVerified publisher | 0.1.0 | 2.4.4-python-alpine | 2 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.