StackRadar

iwakitakuma/gitlab-mcp:2.0.7 container image

Docker Hub

Scanned 20 Sept 2026

Deployed by 1 of 17,813 indexed charts (latest versions) at this tag.Docker Hub all tags of iwakitakuma/gitlab-mcp

iwakitakuma/gitlab-mcp:2.0.7 resolved to fb3e81aa6528, scanned 20 Sept 2026: 84 findings, 0 critical; deployed by 1 chart, among them mcp-gitlab.

Radar Score

1,050011865

84 findings on digest fb3e81aa6528 · scanned 20 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.0.7resolves tofb3e81aa65281 chartyesterday0118651,050

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

84 distinct on this digest

Findings for digest fb3e81aa6528 as scanned on 20 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 20 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
HighALPINE-CVE-2025-15467openssl@3.3.2-r43.3.6-r0
MediumALPINE-CVE-2026-45447openssl@3.3.2-r43.3.7-r1
MediumGHSA-5j98-mcp5-4vw2glob@10.4.510.5.0
MediumGHSA-cv3r-c5h8-f4g5@zereight/mcp-gitlab@2.0.72.1.27
MediumALPINE-CVE-2025-9230openssl@3.3.2-r43.3.5-r0
MediumALPINE-CVE-2024-12797openssl@3.3.2-r43.3.3-r0
MediumALPINE-CVE-2025-9231openssl@3.3.2-r43.3.5-r0
MediumALPINE-CVE-2026-63076openssl@3.3.2-r43.3.7-r1
MediumALPINE-CVE-2026-34182openssl@3.3.2-r43.3.7-r1
MediumALPINE-CVE-2026-31790openssl@3.3.2-r43.3.7-r0
MediumALPINE-CVE-2025-9232openssl@3.3.2-r43.3.5-r0
MediumALPINE-CVE-2025-69421openssl@3.3.2-r43.3.6-r0
MediumALPINE-CVE-2026-28388openssl@3.3.2-r43.3.7-r0
MediumGHSA-3xgq-45jj-v275cross-spawn@7.0.37.0.5
MediumALPINE-CVE-2026-28387openssl@3.3.2-r43.3.7-r0
MediumGHSA-3ppc-4f35-3m26minimatch@9.0.59.0.6
MediumALPINE-CVE-2025-69420openssl@3.3.2-r43.3.6-r0
MediumALPINE-CVE-2026-28389openssl@3.3.2-r43.3.7-r0
MediumALPINE-CVE-2026-28390openssl@3.3.2-r43.3.7-r0
LowGHSA-j3q9-mxjg-w52fpath-to-regexp@8.2.08.4.0
LowGHSA-34x7-hfp2-rc4vtar@7.4.37.5.7
LowALPINE-CVE-2026-9076openssl@3.3.2-r43.3.7-r1
LowALPINE-CVE-2026-45445openssl@3.3.2-r43.3.7-r1
LowGHSA-8r9q-7v3j-jr4g@modelcontextprotocol/sdk@1.13.31.25.2
LowALPINE-CVE-2026-63072openssl@3.3.2-r43.3.7-r1
LowGHSA-vmp7-252j-cwp7@zereight/mcp-gitlab@2.0.72.1.30
LowGHSA-mh99-v99m-4gvgbrace-expansion@2.0.12.1.3
LowGHSA-rgw5-rvv9-x895brace-expansion@2.0.12.1.4
LowGHSA-qffp-2rhf-9h96tar@7.4.37.5.10
LowGHSA-2h44-8472-frjj@zereight/mcp-gitlab@2.0.72.1.27
LowGHSA-23hp-3jrh-7fpwtar@7.4.37.5.19
LowALPINE-CVE-2025-69419openssl@3.3.2-r43.3.6-r0
LowGHSA-mwp4-54f8-5fhrip-address@9.0.510.3.1
LowALPINE-CVE-2026-31789openssl@3.3.2-r43.3.7-r0
LowGHSA-hmw2-7cc7-3qxxform-data@4.0.44.0.6
LowGHSA-w48q-cv73-mx4w@modelcontextprotocol/sdk@1.13.31.24.0
LowGHSA-7r86-cg39-jmmjminimatch@9.0.59.0.7
LowALPINE-CVE-2026-42766openssl@3.3.2-r43.3.7-r1
LowGHSA-8qq5-rm4j-mr97tar@7.4.37.5.3
LowGHSA-73rr-hh4g-fpgxdiff@5.2.05.2.2
LowALPINE-CVE-2026-22184zlib@1.3.1-r21.3.2-r0
LowGHSA-23c5-xmqv-rm74minimatch@9.0.59.0.7
LowGHSA-8x88-c5mf-7j5wtar@7.4.37.5.18
LowGHSA-r6q2-hw4h-h46wtar@7.4.37.5.4
LowALPINE-CVE-2026-75803openssl@3.3.2-r43.3.7-r1
LowGHSA-2g4f-4pwh-qvx6ajv@6.12.66.14.0
LowGHSA-r292-9mhp-454mtar@7.4.37.5.21
LowALPINE-CVE-2025-15468openssl@3.3.2-r43.3.6-r0
LowGHSA-w4pp-8pjf-rmxwpacote@19.0.021.5.1
LowGHSA-9ppj-qmqm-q256tar@7.4.37.5.11

Used by

1 chart
ChartVersionTagContainers
mcp-gitlabmcp-helmVerified publisher0.3.42.0.71

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 20 Sept 2026 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.