joplin/server:latest container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of joplin/server
joplin/server:latest resolved to 3f7b852959aa, scanned 14 Sept 2026: 223 findings, 0 critical; deployed by 1 chart, among them joplin.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
223 distinct on this digest
Findings for digest 3f7b852959aa as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| Medium | GHSA-hrpp-h998-j3pp | qs | 6.5.3 |
| Medium | GHSA-2p57-rm9w-gvfp | ip | no fix listed |
| Medium | DEBIAN-CVE-2019-1010022 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2023-45853 | zlib | no fix listed |
| Medium | GHSA-x3cc-x39p-42qx | fast-xml-parser | 4.1.2 |
| Medium | DEBIAN-CVE-2018-20796 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2019-1010023 | glibc | no fix listed |
| Medium | GHSA-93q8-gq69-wqmw | ansi-regex | 3.0.1 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 2.5.4 |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | GHSA-c2qf-rxjj-qqgw | semver | 7.5.2 |
| Medium | DEBIAN-CVE-2019-9192 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2023-31486 | perl | no fix listed |
| Medium | GHSA-f8q6-p94x-37v3 | minimatch | 3.0.5 |
| Medium | DEBIAN-CVE-2018-6829 | libgcrypt20 | no fix listed |
| Medium | GHSA-72xf-g2v4-qvf3 | tough-cookie | 4.1.3 |
| Medium | GHSA-rc47-6667-2j5j | http-cache-semantics | 4.1.1 |
| Medium | GHSA-grv7-fg5c-xmjg | braces | 3.0.3 |
| Medium | DEBIAN-CVE-2011-3389 | gnutls28 | no fix listed |
| Medium | GHSA-pfq8-rq6v-vf5m | html-minifier | no fix listed |
| Medium | DEBIAN-CVE-2025-13151 | libtasn1-6 | no fix listed |
| Medium | DEBIAN-CVE-2019-1010024 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2026-5450 | glibc | no fix listed |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-2v35-w6hq-6mfw | @xmldom/ | 0.8.13 |
| Medium | DEBIAN-CVE-2026-8376 | perl | no fix listed |
| Medium | GHSA-m7jm-9gc2-mpf2 | fast-xml-parser | 5.3.5 |
| Medium | GHSA-3xgq-45jj-v275 | cross-spawn | 7.0.5 |
| Medium | GHSA-jmr7-xgp7-cmfj | fast-xml-parser | 5.3.6 |
| Medium | GHSA-f6ww-3ggp-fr8h | @xmldom/ | 0.8.13 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 3.1.3 |
| Medium | DEBIAN-CVE-2019-1010025 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-57433 | perl | no fix listed |
| Low | GHSA-vcc3-ghjq-m6fr | decode-uri-component | 0.5.0 |
| Low | GHSA-7h2j-956f-4vf2 | @isaacs/ | 5.0.1 |
| Low | DEBIAN-CVE-2026-13221 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-42496 | perl | no fix listed |
| Low | GHSA-x6wf-f3px-wcqx | @xmldom/ | 0.8.13 |
| Low | GHSA-34x7-hfp2-rc4v | tar | 7.5.7 |
| Low | DEBIAN-CVE-2026-12087 | perl | no fix listed |
| Low | DEBIAN-CVE-2023-50495 | ncurses | no fix listed |
| Low | GHSA-rgw5-rvv9-x895 | brace-expansion | 2.1.4 |
| Low | GHSA-xcpc-8h2w-3j85 | adm-zip | 0.6.0 |
| Low | GHSA-f5x3-32g6-xq36 | tar | 6.2.1 |
| Low | DEBIAN-CVE-2026-85091 | zlib | no fix listed |
| Low | GHSA-8gc5-j5rx-235r | fast-xml-parser | 5.5.6 |
| Low | GHSA-qffp-2rhf-9h96 | tar | 7.5.10 |
| Low | GHSA-22p9-wv53-3rq4 | linkify-it | 5.0.1 |