StackRadar

grafana/oncall:v1.13.11 container image

Docker Hub

Scanned 19 Sept 2026

Deployed by 1 of 17,805 indexed charts (latest versions) at this tag.Docker Hub all tags of grafana/oncall

grafana/oncall:v1.13.11 resolved to 159b6b836fed, scanned 19 Sept 2026: 210 findings, 2 critical, 1 on KEV; deployed by 1 chart, among them oncall-hobby.

Radar Score

2,7802550153

210 findings on digest 159b6b836fed · scanned 19 Sept 2026

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v1.13.11resolves to159b6b836fed1 charttoday25501532,780

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

153 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 159b6b836fed as scanned on 19 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 19 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowPYSEC-2026-2132click@8.1.78.3.3
LowALPINE-CVE-2025-46835git@2.45.2-r02.45.4-r0
LowGHSA-933h-hp56-hf7mdjango@4.2.174.2.30
LowALPINE-CVE-2025-0840binutils@2.42-r02.42-r1
LowGHSA-7cx3-6m66-7c5mtornado@6.4.26.5
LowGHSA-8p8v-wh79-9r56django@4.2.174.2.29
LowALPINE-CVE-2026-6477postgresql16@16.3-r016.14-r0
LowALPINE-CVE-2024-9287python3@3.12.6-r03.12.8-r0
LowALPINE-CVE-2025-8715postgresql16@16.3-r016.10-r0
LowALPINE-CVE-2026-2007postgresql16@16.3-r016.12-r0
LowGHSA-gm37-52c6-37mwpymdown-extensions@10.011.0.1
LowALPINE-CVE-2026-6637postgresql16@16.3-r016.14-r0
LowGHSA-q2x7-8rv6-6q7hjinja2@3.1.43.1.5
LowGHSA-2mcm-79hx-8fxwdjango@4.2.174.2.28
LowGHSA-5mf9-h53q-7mhqdjango@4.2.174.2.30
LowGHSA-mgf9-4vpg-hj56tornado@6.4.26.5.6
LowGHSA-5wmx-573v-2qwqmarkdown@3.5.23.8.1
LowALPINE-CVE-2025-27614git@2.45.2-r02.45.4-r0
LowGHSA-c98p-7wgm-6p64tornado@6.4.26.5.3
LowALPINE-CVE-2025-69419openssl@3.3.2-r03.3.6-r0
LowALPINE-CVE-2026-31789openssl@3.3.2-r03.3.7-r0
LowGHSA-jhmp-mqwm-3gq8tornado@6.4.26.5.3
LowALPINE-CVE-2026-6475postgresql16@16.3-r016.14-r0
LowGHSA-2wc2-fm75-p42xsoupsieve@2.52.8.4
LowGHSA-836r-79rf-4m37soupsieve@2.52.8.4
LowALPINE-CVE-2025-29087sqlite@3.45.3-r13.45.3-r2
LowALPINE-CVE-2024-50602expat@2.6.3-r02.6.4-r0
LowGHSA-gmj6-6f8f-6699jinja2@3.1.43.1.5
LowALPINE-CVE-2025-46334git@2.45.2-r02.45.4-r0
LowGHSA-6v7p-g79w-8964msgpack@1.0.71.2.1
LowGHSA-3x9g-8vmp-wqvftornado@6.4.26.5.6
LowALPINE-CVE-2026-22184zlib@1.3.1-r11.3.2-r0
LowALPINE-CVE-2024-8096curl@8.9.1-r28.10.0-r0
LowALPINE-CVE-2026-6479postgresql16@16.3-r016.14-r0
LowALPINE-CVE-2026-45186expat@2.6.3-r02.8.1-r0
LowGHSA-r6ph-v2qm-q3c2cryptography@43.0.146.0.5
LowGHSA-mvfq-ggxm-9mc5django@4.2.174.2.30
LowGHSA-j5g9-f88f-gfj3httplib2@0.22.00.32.0
LowGHSA-f2ff-p2ww-7p4psqlparse@0.5.00.6.0
LowGHSA-pwgv-4x5q-6m9fsqlparse@0.5.00.6.0
LowGHSA-jwv3-5hgf-82wwcryptography@43.0.149.0.0
LowGHSA-wf93-45jw-7689pip@24.226.1.2
LowGHSA-xgmm-8j9v-c9wxpyjwt@2.8.02.13.0
LowALPINE-CVE-2025-15468openssl@3.3.2-r03.3.6-r0
LowGHSA-r6h4-mm7h-8pmqpymdown-extensions@10.010.16.1
LowGHSA-qjxf-f2mg-c6mctornado@6.4.26.5.5
LowALPINE-CVE-2026-6478postgresql16@16.3-r016.14-r0
LowALPINE-CVE-2025-4207postgresql16@16.3-r016.9-r0
LowGHSA-mpf4-983q-p7j4tornado@6.4.26.5.8
LowGHSA-m4p7-r5rc-7g4jpyasn1@0.5.10.6.4

Used by

1 chart
ChartVersionTagContainers
oncall-hobbylovemew67Verified publisher0.0.5v1.13.113

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 19 Sept 2026 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.