StackRadar

grafana/oncall:v1.13.11 container image

Docker Hub

Scanned 19 Sept 2026

Deployed by 1 of 17,805 indexed charts (latest versions) at this tag.Docker Hub all tags of grafana/oncall

grafana/oncall:v1.13.11 resolved to 159b6b836fed, scanned 19 Sept 2026: 210 findings, 2 critical, 1 on KEV; deployed by 1 chart, among them oncall-hobby.

Radar Score

2,7802550153

210 findings on digest 159b6b836fed · scanned 19 Sept 2026

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v1.13.11resolves to159b6b836fed1 charttoday25501532,780

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

153 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 159b6b836fed as scanned on 19 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 19 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-9hjg-9r4m-mvj7requests@2.32.32.32.4
LowALPINE-CVE-2025-5222icu@74.2-r074.2-r1
LowGHSA-8ppf-4f7h-5ppjpyasn1@0.5.10.6.4
LowGHSA-hm4w-wwcw-mr6rpyasn1@0.5.10.6.4
LowGHSA-8qvm-5x2c-j2w7protobuf@4.25.24.25.8
LowGHSA-29vq-49wr-vm6xwerkzeug@3.0.63.1.6
LowGHSA-vfmq-68hx-4jfwlxml@5.2.26.1.0
LowGHSA-8423-8fgw-73vqtornado@6.4.26.5.8
LowGHSA-6426-9fv3-65x8django@4.2.174.2.28
LowGHSA-hgf8-39gv-g3f2werkzeug@3.0.63.1.4
LowALPINE-CVE-2026-6638postgresql16@16.3-r016.14-r0
LowALPINE-CVE-2024-10976postgresql16@16.3-r016.5-r0
LowALPINE-CVE-2025-26519musl@1.2.5-r01.2.5-r1
LowGHSA-prg7-hcfm-mfcrsqlparse@0.5.00.6.0
LowGHSA-8rrh-rw8j-w5fxwheel@0.45.10.46.2
LowALPINE-CVE-2024-12718python3@3.12.6-r03.12.11-r0
LowGHSA-752w-5fwx-jx9fpyjwt@2.8.02.12.0
LowGHSA-wv4w-6qv2-qqfgsocial-auth-app-django@5.4.15.6.0
LowPYSEC-2026-3554cryptography@43.0.149.0.0
LowGHSA-p3fp-8748-vqfqdjango@4.2.174.2.20
LowALPINE-CVE-2025-48386git@2.45.2-r02.45.4-r0
LowGHSA-4xh5-x5gv-qwphpip@24.225.3
LowALPINE-CVE-2026-25210expat@2.6.3-r02.7.4-r0
LowGHSA-h35f-9h28-mq5csetuptools@75.6.083.0.0
LowGHSA-fqwm-6jpj-5wxctornado@6.4.26.5.5
LowALPINE-CVE-2026-40200musl@1.2.5-r01.2.5-r3
LowALPINE-CVE-2025-66199openssl@3.3.2-r03.3.6-r0
LowPYSEC-2026-3721pip@24.226.2
LowALPINE-CVE-2025-4947curl@8.9.1-r28.14.0-r0
LowGHSA-cpwx-vrp4-4pq7jinja2@3.1.43.1.6
LowALPINE-CVE-2026-22796openssl@3.3.2-r03.3.6-r0
LowGHSA-8qcx-xf44-272xdjango@4.2.175.2.16
LowGHSA-rqw2-ghq9-44m7django@4.2.174.2.27
LowGHSA-87hc-h4r5-73f7werkzeug@3.0.63.1.5
LowALPINE-CVE-2025-12818postgresql16@16.3-r016.11-r0
LowALPINE-CVE-2024-50349git@2.45.2-r02.45.3-r0
LowALPINE-CVE-2026-34743xz@5.6.2-r05.8.3-r0
LowGHSA-gjv8-xp57-g29csoupsieve@2.52.9.0
LowGHSA-pq67-6m6q-mj2vurllib3@1.26.192.5.0
LowGHSA-9xwg-3r6f-jcx2pymdown-extensions@10.011.0.0
LowGHSA-8qf3-x8v5-2pj8uv@0.5.60.8.6
LowGHSA-65pc-fj4g-8rjxidna@3.73.15
LowGHSA-vp96-hxj8-p424pyopenssl@24.2.126.0.0
LowGHSA-2m8g-3cmr-wg3wdjangorestframework@3.15.23.17.2
LowPYSEC-2025-183pyjwt@2.8.0no fix listed
LowGHSA-w7vc-732c-9m39pyjwt@2.8.02.13.0
LowPYSEC-2025-265tornado@6.4.26.5.3
LowALPINE-CVE-2024-11053curl@8.9.1-r28.11.1-r0
LowGHSA-j934-xhv5-fg8fsoupsieve@2.52.9.0
LowALPINE-CVE-2024-10978postgresql16@16.3-r016.5-r0

Used by

1 chart
ChartVersionTagContainers
oncall-hobbylovemew67Verified publisher0.0.5v1.13.113

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 19 Sept 2026 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.