StackRadar

grafana/alloy:v1.20.1 container image

Docker Hub

Scanned 9 Oct 2026

Deployed by 1 of 18,071 indexed charts (latest versions) at this tag.Docker Hub all tags of grafana/alloy

grafana/alloy:v1.20.1 resolved to 2aa2099af76c, scanned 9 Oct 2026: 78 findings, 0 critical; deployed by 1 chart, among them alloy.

Radar Score

59100672

78 findings on digest 2aa2099af76c · scanned 9 Oct 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v1.20.1resolves to2aa2099af76c1 charttoday00672591

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

78 distinct on this digest

Findings for digest 2aa2099af76c as scanned on 9 Oct 2026 with syft 1.42.1 for linux/amd64, advisories as of 9 Oct 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2022-3219gnupg2@2.4.4-2ubuntu17.6no fix listed
LowUBUNTU-CVE-2026-102474dash@0.5.12-6ubuntu5no fix listed
LowUBUNTU-CVE-2026-89156pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-18477tar@1.35+dfsg-3ubuntu0.4no fix listed
LowGO-2026-5932golang.org/x/crypto@v0.57.0no fix listed
LowGO-2026-6599stdlib@go1.26.71.26.9
LowGO-2026-6600stdlib@go1.26.71.26.9
LowGO-2026-6603stdlib@go1.26.71.26.9
LowGO-2026-6603golang.org/x/net@v0.58.00.60.0
LowGO-2026-6604stdlib@go1.26.71.26.9
LowGO-2026-6605stdlib@go1.26.71.26.9
LowGO-2026-6607stdlib@go1.26.71.26.9
LowGO-2026-6608stdlib@go1.26.71.26.9
LowGO-2026-6609stdlib@go1.26.71.26.9
LowGO-2026-6610golang.org/x/net@v0.58.00.60.0
LowGO-2026-6610stdlib@go1.26.71.26.9
LowGO-2026-6611stdlib@go1.26.71.26.9
LowGO-2026-6611golang.org/x/net@v0.58.00.60.0
LowGO-2026-6612golang.org/x/net@v0.58.00.60.0
LowGO-2026-6612stdlib@go1.26.71.26.9
LowGO-2026-6613stdlib@go1.26.71.26.9
LowGO-2026-6617stdlib@go1.26.71.26.9
LowGO-2026-6617golang.org/x/net@v0.58.00.60.0
LowUBUNTU-CVE-2026-95818glibc@2.39-0ubuntu8.9no fix listed
LowUBUNTU-CVE-2026-105712gnupg2@2.4.4-2ubuntu17.6no fix listed
LowUBUNTU-CVE-2026-89162pcre2@10.42-4ubuntu2.1no fix listed
LowGO-2022-0635github.com/aws/aws-sdk-go@v1.55.8no fix listed
LowUBUNTU-CVE-2026-40228systemd@255.4-1ubuntu8.17no fix listed

Used by

1 chart
ChartVersionTagContainers
alloygrafana1.13.1v1.20.11

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 9 Oct 2026 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.