heartexlabs/label-studio:latest container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of heartexlabs/label-studio
heartexlabs/label-studio:latest resolved to aa461572e8f9, scanned 14 Sept 2026: 248 findings, 1 critical; deployed by 1 chart, among them label-studio.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
248 distinct on this digest
Findings for digest aa461572e8f9 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-pwgv-4x5q-6m9f | sqlparse | 0.6.0 |
| Low | GHSA-8v84-f9pq-wr9x | pillow | 12.3.0 |
| Low | ALPINE-CVE-2026-40701 | nginx | 1.28.3-r1 |
| Low | ALPINE-CVE-2026-48142 | nginx | 1.28.3-r4 |
| Low | GHSA-p4rw-rvv2-7xwr | nltk | 3.10.3 |
| Low | ALPINE-CVE-2026-12064 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-8932 | curl | 8.22.0-r0 |
| Low | GHSA-6ww7-3frv-cqxh | nltk | 3.10.3 |
| Low | GHSA-jwv3-5hgf-82ww | cryptography | 49.0.0 |
| Low | ALPINE-CVE-2026-8286 | curl | 8.22.0-r0 |
| Low | GHSA-wf93-45jw-7689 | pip | 26.1.2 |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | GHSA-6r8x-57c9-28j4 | pillow | 12.3.0 |
| Low | GHSA-9hw9-ch79-4vh6 | pillow | 12.3.0 |
| Low | GHSA-jjj6-mw9f-p565 | pillow | 12.3.0 |
| Low | GHSA-xgmm-8j9v-c9wx | pyjwt | 2.13.0 |
| Low | PYSEC-2026-3728 | nltk | 3.10.0 |
| Low | GHSA-3gq4-3j92-5w49 | nltk | 3.10.3 |
| Low | ALPINE-CVE-2026-8458 | curl | 8.22.0-r0 |
| Low | PYSEC-2026-3740 | nltk | 3.10.3 |
| Low | ALPINE-CVE-2026-6253 | curl | 8.20.0-r0 |
| Low | GHSA-m4p7-r5rc-7g4j | pyasn1 | 0.6.4 |
| Low | GHSA-w3v8-gmh9-3wv7 | nltk | 3.10.3 |
| Low | GHSA-8ppf-4f7h-5ppj | pyasn1 | 0.6.4 |
| Low | GHSA-hm4w-wwcw-mr6r | pyasn1 | 0.6.4 |
| Low | GHSA-954p-556p-r752 | datamodel-code-generator | 0.61.0 |
| Low | GHSA-vfmq-68hx-4jfw | lxml | 6.1.0 |
| Low | GHSA-4jhm-jv67-739f | lxml-html-clean | 0.4.5 |
| Low | ALPINE-CVE-2026-9547 | curl | 8.22.0-r0 |
| Low | PYSEC-2026-3732 | nltk | 3.9.4 |
| Low | PYSEC-2026-3731 | nltk | 3.10.0 |
| Low | ALPINE-CVE-2026-6276 | curl | 8.20.0-r0 |
| Low | ALPINE-CVE-2026-40460 | nginx | 1.28.3-r1 |
| Low | ALPINE-CVE-2026-76956 | expat | 2.8.4-r0 |
| Low | ALPINE-CVE-2026-2673 | openssl | 3.5.6-r0 |
| Low | GHSA-prg7-hcfm-mfcr | sqlparse | 0.6.0 |
| Low | GHSA-8rrh-rw8j-w5fx | wheel | 0.46.2 |
| Low | GHSA-rfr2-mq9m-x2qx | datamodel-code-generator | 0.61.0 |
| Low | ALPINE-CVE-2026-9080 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-42767 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-5545 | curl | 8.20.0-r0 |
| Low | GHSA-752w-5fwx-jx9f | pyjwt | 2.12.0 |
| Low | ALPINE-CVE-2026-3784 | curl | 8.19.0-r0 |
| Low | ALPINE-CVE-2026-9545 | curl | 8.22.0-r0 |
| Low | PYSEC-2026-2085 | nltk | 3.9.4 |
| Low | ALPINE-CVE-2025-14819 | curl | 8.18.0-r0 |
| Low | ALPINE-CVE-2026-76642 | util-linux | 2.41.6-r0 |
| Low | ALPINE-CVE-2026-11822 | sqlite | 3.53.4-r0 |
| Low | ALPINE-CVE-2026-11824 | sqlite | 3.53.4-r0 |
| Low | GHSA-m2h6-j472-rp4c | cryptography | 49.0.0 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| label-studioinseefrlab | 2.3.1 | latest | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.