StackRadar

iwakitakuma/gitlab-mcp:2.0.7 container image

Docker Hub

Scanned 20 Sept 2026

Deployed by 1 of 17,813 indexed charts (latest versions) at this tag.Docker Hub all tags of iwakitakuma/gitlab-mcp

iwakitakuma/gitlab-mcp:2.0.7 resolved to fb3e81aa6528, scanned 20 Sept 2026: 84 findings, 0 critical; deployed by 1 chart, among them mcp-gitlab.

Radar Score

1,050011865

84 findings on digest fb3e81aa6528 · scanned 20 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.0.7resolves tofb3e81aa65281 chartyesterday0118651,050

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

84 distinct on this digest

Findings for digest fb3e81aa6528 as scanned on 20 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 20 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2025-26519musl@1.2.5-r81.2.5-r9
LowGHSA-f886-m6hf-6m8vbrace-expansion@2.0.12.0.3
LowGHSA-83g3-92jg-28cxtar@7.4.37.5.8
LowGHSA-345p-7cg4-v4c7@modelcontextprotocol/sdk@1.13.31.26.0
LowGHSA-w8wr-v893-vjvptar@7.4.37.5.18
LowALPINE-CVE-2026-40200musl@1.2.5-r81.2.5-r11
LowALPINE-CVE-2025-66199openssl@3.3.2-r43.3.6-r0
LowGHSA-52v5-jr5w-gjxrsigstore@2.3.14.1.1
LowALPINE-CVE-2026-22796openssl@3.3.2-r43.3.6-r0
LowGHSA-gvwx-54wh-qm9jtar@7.4.37.5.17
LowGHSA-27v5-c462-wpq7path-to-regexp@8.2.08.4.0
LowGHSA-v2v4-37r5-5v8gip-address@9.0.510.1.1
LowGHSA-wqch-xfxh-vrr4body-parser@2.2.02.2.1
LowGHSA-3jxr-9vmj-r5cpbrace-expansion@2.0.12.1.2
LowGHSA-q8mj-m7cp-5q26qs@6.14.06.15.2
LowGHSA-5648-rgj9-v224@zereight/mcp-gitlab@2.0.72.1.30
LowGHSA-vmf3-w455-68vhtar@7.4.37.5.16
LowALPINE-CVE-2026-45446openssl@3.3.2-r43.3.7-r1
LowALPINE-CVE-2024-13176openssl@3.3.2-r43.3.2-r5
LowGHSA-jfc7-64v2-mr8c@sigstore/core@1.1.03.2.1
LowGHSA-4mjr-xmp4-gh2gqs@6.14.06.16.0
LowALPINE-CVE-2026-27171zlib@1.3.1-r21.3.2-r0
LowALPINE-CVE-2026-6042musl@1.2.5-r81.2.5-r10
LowGHSA-w9m9-85wc-3x92postcss-selector-parser@6.1.26.1.3
LowALPINE-CVE-2026-42770openssl@3.3.2-r43.3.7-r1
LowGHSA-w7fw-mjwx-w883qs@6.14.06.14.2
LowALPINE-CVE-2026-22795openssl@3.3.2-r43.3.6-r0
LowGHSA-6rw7-vpxm-498pqs@6.14.06.14.1
LowGHSA-v422-hmwv-36x6body-parser@2.2.02.3.0
LowGHSA-v6h2-p8h4-qcjwbrace-expansion@2.0.12.0.2
LowALPINE-CVE-2025-68160openssl@3.3.2-r43.3.6-r0
LowALPINE-CVE-2025-69418openssl@3.3.2-r43.3.6-r0
LowALPINE-CVE-2025-46394busybox@1.37.0-r91.37.0-r14
LowALPINE-CVE-2024-58251busybox@1.37.0-r91.37.0-r14

Used by

1 chart
ChartVersionTagContainers
mcp-gitlabmcp-helmVerified publisher0.3.42.0.71

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 20 Sept 2026 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.