StackRadar

joplin/server:3.7.2 container image

Docker Hub

Scanned 22 Sept 2026

Deployed by 2 of 17,832 indexed charts (latest versions) at this tag.Docker Hub all tags of joplin/server

joplin/server:3.7.2 resolved to 3f7b852959aa, scanned 22 Sept 2026: 226 findings, 0 critical; deployed by 2 charts, among them joplin-server and joplin-server.

Radar Score

2,5590134191

226 findings on digest 3f7b852959aa · scanned 22 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
3.7.2resolves to3f7b852959aa1 charttoday01341912,559

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

191 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 3f7b852959aa as scanned on 22 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 22 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-41992gzip@1.12-1no fix listed
LowGHSA-7q85-xj36-vmfcadm-zip@0.5.170.6.1
LowDEBIAN-CVE-2026-19499glibc@2.36-9+deb12u14no fix listed
LowGHSA-c2c7-rcm5-vvqjpicomatch@4.0.24.0.4
LowGHSA-2g4f-4pwh-qvx6ajv@6.12.66.14.0
LowGHSA-p8p7-x288-28g6request@2.88.2no fix listed
LowGHSA-2883-xcg3-v3hhjs-yaml@4.1.14.3.2
LowGHSA-r292-9mhp-454mtar@6.1.117.5.21
LowDEBIAN-CVE-2026-48959perl@5.36.0-7+deb12u3no fix listed
LowGHSA-fj3w-jwp8-x2g3fast-xml-parser@5.2.55.3.8
LowDEBIAN-CVE-2026-5928glibc@2.36-9+deb12u14no fix listed
LowDEBIAN-CVE-2026-6791glibc@2.36-9+deb12u14no fix listed
LowDEBIAN-CVE-2022-27943gcc-12@12.2.0-14+deb12u1no fix listed
LowGHSA-w5hq-g745-h8pquuid@13.0.013.0.1
LowGHSA-65x3-rw7q-gx94multiparty@4.2.34.3.0
LowGHSA-9ppj-qmqm-q256tar@6.1.117.5.11
LowGHSA-4xrf-jv44-h6hhip-address@10.2.010.2.2
LowGHSA-968p-4wvh-cqc8@babel/runtime@7.22.57.26.10
LowDEBIAN-CVE-2025-8941pam@1.5.2-6+deb12u2no fix listed
LowDEBIAN-CVE-2026-57432perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2016-2781coreutils@9.1-1no fix listed
LowGHSA-xwg4-73v4-xw9wnanoid@3.3.73.3.12
LowGHSA-f886-m6hf-6m8vbrace-expansion@2.0.12.0.3
LowGHSA-xh3c-6gcq-g4rvmultiparty@4.2.34.3.0
LowGHSA-6h8r-xr42-gp59@xmldom/xmldom@0.8.130.8.15
LowGHSA-22jq-vg5j-6vggip-address@10.2.010.2.1
LowDEBIAN-CVE-2026-48962perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2026-76642util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-83g3-92jg-28cxtar@6.1.117.5.8
LowDEBIAN-CVE-2026-48961perl@5.36.0-7+deb12u3no fix listed
LowGHSA-38c4-r59v-3vqwmarkdown-it@13.0.214.1.1
LowDEBIAN-CVE-2026-6238glibc@2.36-9+deb12u14no fix listed
LowGHSA-w8wr-v893-vjvptar@6.1.117.5.18
LowGHSA-jp2q-39xq-3w4gfast-xml-parser@5.2.55.5.7
LowDEBIAN-CVE-2026-5435glibc@2.36-9+deb12u14no fix listed
LowGHSA-p6gq-j5cr-w38fnodemailer@6.10.19.0.1
LowDEBIAN-CVE-2026-54369acl@2.3.1-3no fix listed
LowGHSA-6gmq-8vp8-gcm6@xmldom/xmldom@0.8.130.8.15
LowDEBIAN-CVE-2026-7017perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2026-89157pcre2@10.42-110.42-1+deb12u1
LowDEBIAN-CVE-2026-54371attr@1:2.5.1-4no fix listed
LowGHSA-vvjj-xcjg-gr5gnodemailer@6.10.18.0.5
LowMAL-2022-2944extraneous-detected@0.0.0no fix listed
LowMAL-2022-2945extraneous-dev-dep@0.0.0no fix listed
LowMAL-2022-4691monorepo-symlink-test@0.0.0no fix listed
LowDEBIAN-CVE-2026-77117glibc@2.36-9+deb12u14no fix listed
LowDEBIAN-CVE-2026-80489glibc@2.36-9+deb12u14no fix listed
LowGHSA-jxxr-4gwj-5jf2brace-expansion@5.0.55.0.6
LowGHSA-p9pc-299p-vxgpyargs-parser@7.0.013.1.2
LowGHSA-gvwx-54wh-qm9jtar@6.1.117.5.17

Used by

2 charts
ChartVersionTagContainers
joplin-serverdjjudas21Verified publisher6.0.03.7.21
joplin-serverschoenwald1.0.33.7.2unmeasured: HTTP 429 resolving manifest1

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 22 Sept 2026 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.