StackRadar

grafana/oncall:v1.13.11 container image

Docker Hub

Scanned 19 Sept 2026

Deployed by 1 of 17,805 indexed charts (latest versions) at this tag.Docker Hub all tags of grafana/oncall

grafana/oncall:v1.13.11 resolved to 159b6b836fed, scanned 19 Sept 2026: 210 findings, 2 critical, 1 on KEV; deployed by 1 chart, among them oncall-hobby.

Radar Score

2,7802550153

210 findings on digest 159b6b836fed · scanned 19 Sept 2026

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v1.13.11resolves to159b6b836fed1 charttoday25501532,780

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

153 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 159b6b836fed as scanned on 19 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 19 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-qccp-gfcp-xxvcurllib3@1.26.192.7.0
LowGHSA-crhf-3pfg-w68wdjango@4.2.175.2.16
LowGHSA-7xr5-9hcq-chf9django@4.2.174.2.22
LowGHSA-pqhf-p39g-3x64uv@0.5.60.9.6
LowALPINE-CVE-2025-4516python3@3.12.6-r03.12.10-r1
LowGHSA-pw6j-qg29-8w7ftornado@6.4.26.5.7
LowALPINE-CVE-2024-13176openssl@3.3.2-r03.3.2-r2
LowGHSA-537c-gmf6-5ccfcryptography@43.0.148.0.1
LowALPINE-CVE-2026-27171zlib@1.3.1-r11.3.2-r0
LowALPINE-CVE-2026-32777expat@2.6.3-r02.7.5-r0
LowGHSA-27jp-wm6q-gp25sqlparse@0.5.00.5.4
LowALPINE-CVE-2025-5025curl@8.9.1-r28.14.0-r0
LowGHSA-3496-9g83-7v6xsqlparse@0.5.00.6.0
LowPYSEC-2026-2275requests@2.32.32.33.0
LowALPINE-CVE-2026-32778expat@2.6.3-r02.7.5-r0
LowGHSA-g47c-3xmw-q6m2djangorestframework@3.15.23.17.2
LowPYSEC-2026-2151flask@3.0.23.1.3
LowALPINE-CVE-2026-32776expat@2.6.3-r02.7.5-r0
LowGHSA-q95w-c7qg-hrffdjango@4.2.174.2.25
LowALPINE-CVE-2025-0167curl@8.9.1-r28.12.0-r0
LowALPINE-CVE-2026-6042musl@1.2.5-r01.2.5-r2
LowALPINE-CVE-2026-6472postgresql16@16.3-r016.14-r0
LowALPINE-CVE-2026-22795openssl@3.3.2-r03.3.6-r0
LowALPINE-CVE-2025-27613git@2.45.2-r02.45.4-r0
LowALPINE-CVE-2026-2003postgresql16@16.3-r016.12-r0
LowGHSA-m959-cc7f-wv43cryptography@43.0.146.0.6
LowGHSA-jp4c-xjxw-mgf9pip@24.226.1
LowGHSA-79v4-65xg-pq4gcryptography@43.0.144.0.1
LowALPINE-CVE-2024-10977postgresql16@16.3-r016.5-r0
LowGHSA-fhv5-28vv-h8m8pyjwt@2.8.02.13.0
LowGHSA-mjgh-79qc-68w3django@4.2.174.2.29
LowGHSA-cx3h-4qpv-8hc9tornado@6.4.26.5.6
LowALPINE-CVE-2026-6474postgresql16@16.3-r016.14-r0
LowALPINE-CVE-2025-68160openssl@3.3.2-r03.3.6-r0
LowGHSA-4gg8-gxpx-9rphuv@0.5.60.11.15
LowGHSA-cfqr-cjx5-5jcmsqlparse@0.5.00.6.0
LowGHSA-993g-76c3-p5m4pyjwt@2.8.02.13.0
LowGHSA-58qw-9mgm-455vpip@24.226.1
LowGHSA-3h9f-r86x-qvjxdjango@4.2.175.2.16
LowGHSA-923m-gv2p-w5qpdjango@4.2.175.2.15
LowALPINE-CVE-2026-41080expat@2.6.3-r02.8.1-r0
LowGHSA-8cjm-8mp7-r2xfdjango@4.2.175.2.15
LowALPINE-CVE-2025-69418openssl@3.3.2-r03.3.6-r0
LowGHSA-h7pc-vwp9-298gdjango@4.2.175.2.15
LowALPINE-CVE-2025-12817postgresql16@16.3-r016.11-r0
LowALPINE-CVE-2025-8713postgresql16@16.3-r016.10-r0
LowALPINE-CVE-2025-46394busybox@1.36.1-r291.36.1-r31
LowGHSA-mmwr-2jhp-mc7jdjango@4.2.174.2.30
LowGHSA-6vgw-5pg2-w6jppip@24.226.0
LowALPINE-CVE-2026-24515expat@2.6.3-r02.7.4-r0

Used by

1 chart
ChartVersionTagContainers
oncall-hobbylovemew67Verified publisher0.0.5v1.13.113

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 19 Sept 2026 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.