StackRadar

grafana/oncall:v1.16.5 container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of grafana/oncall

grafana/oncall:v1.16.5 resolved to 499851658393, scanned 14 Sept 2026: 223 findings, 0 critical; deployed by 1 chart, among them oncall.

Radar Score

2,5500437182

223 findings on digest 499851658393 · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v1.16.5resolves to4998516583931 chart8 days ago04371822,550

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Medium findings

37 distinct on this digest

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

Findings for digest 499851658393 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGHSA-38jv-5279-wg99urllib3@1.26.192.6.3
MediumALPINE-CVE-2025-49796libxml2@2.13.4-r62.13.9-r0
MediumALPINE-CVE-2026-2005postgresql17@17.6-r017.8-r0
MediumPYSEC-2025-109django@4.2.224.2.27
MediumALPINE-CVE-2026-2004postgresql17@17.6-r017.8-r0
MediumGHSA-qw25-v68c-qjf3django@4.2.224.2.26
MediumALPINE-CVE-2026-2006postgresql17@17.6-r017.8-r0
MediumALPINE-CVE-2026-6473postgresql17@17.6-r017.10-r0
MediumPYSEC-2026-2269pyopenssl@25.1.026.0.0
MediumALPINE-CVE-2025-9230openssl@3.3.4-r03.3.5-r0
MediumGHSA-gvg8-93h5-g6qqdjango@4.2.224.2.28
MediumALPINE-CVE-2025-9231openssl@3.3.4-r03.3.5-r0
MediumPYSEC-2025-106django@4.2.224.2.25
MediumALPINE-CVE-2025-49794libxml2@2.13.4-r62.13.9-r0
MediumALPINE-CVE-2025-6021libxml2@2.13.4-r62.13.9-r0
MediumALPINE-CVE-2025-59375expat@2.7.0-r02.7.2-r0
MediumGHSA-2xpw-w6gg-jr37urllib3@1.26.192.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@1.26.192.6.0
MediumALPINE-CVE-2026-14669postgresql17@17.6-r017.11-r0
MediumALPINE-CVE-2026-6100python3@3.12.11-r03.12.14-r0
MediumPYSEC-2026-43django@4.2.224.2.28
MediumPYSEC-2026-45django@4.2.224.2.28
MediumALPINE-CVE-2026-31790openssl@3.3.4-r03.3.7-r0
MediumPYSEC-2026-52django@4.2.224.2.30
MediumPYSEC-2026-3717django@4.2.225.2.17
MediumALPINE-CVE-2025-9232openssl@3.3.4-r03.3.5-r0
MediumALPINE-CVE-2026-66046expat@2.7.0-r02.8.4-r0
MediumGHSA-7gcm-g887-7qv7protobuf@4.25.85.29.6
MediumALPINE-CVE-2026-28388openssl@3.3.4-r03.3.7-r0
MediumALPINE-CVE-2025-69421openssl@3.3.4-r03.3.6-r0
MediumALPINE-CVE-2026-16239postgresql17@17.6-r017.11-r0
MediumALPINE-CVE-2026-28387openssl@3.3.4-r03.3.7-r0
MediumGHSA-58pv-8j8x-9vj2jaraco-context@5.3.06.1.0
MediumALPINE-CVE-2026-11940python3@3.12.11-r03.12.14-r0
MediumALPINE-CVE-2026-28389openssl@3.3.4-r03.3.7-r0
MediumALPINE-CVE-2026-28390openssl@3.3.4-r03.3.7-r0
MediumGHSA-jr27-m4p2-rc6rpyasn1@0.6.10.6.3

Used by

1 chart
ChartVersionTagContainers
oncallgrafana1.16.5v1.16.55

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.