library/kibana:8.18.0 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of library/kibana
library/kibana:8.18.0 resolved to 04c0fc150f3a, scanned 14 Sept 2026: 448 findings, 4 critical; deployed by 1 chart, among them kibana.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
349 distinct on this digest
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest 04c0fc150f3a as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-6v7q-wjvx-w8wg | basic-ftp | 5.2.2 |
| Low | GHSA-fw9q-39r9-c252 | langsmith | 0.5.18 |
| Low | UBUNTU-CVE-2026-54369 | acl | no fix listed |
| Low | UBUNTU-CVE-2026-41989 | libgcrypt20 | no fix listed |
| Low | GHSA-3jxr-9vmj-r5cp | brace-expansion | 1.1.16 |
| Low | GHSA-gh4j-gqv2-49f6 | fast-xml-parser | 5.7.0 |
| Low | UBUNTU-CVE-2025-5372 | libssh | no fix listed |
| Low | UBUNTU-CVE-2026-13595 | util-linux | no fix listed |
| Low | GHSA-p88m-4jfj-68fv | undici | 6.27.0 |
| Low | UBUNTU-CVE-2026-54371 | attr | 1:2.4.48-5ubuntu0.1~esm1 |
| Low | GHSA-vmf3-w455-68vh | tar | 7.5.16 |
| Low | GHSA-8988-4f7v-96qf | @opentelemetry/ | 2.8.0 |
| Low | UBUNTU-CVE-2026-0964 | libssh | 0.9.3-2ubuntu2.5+esm3 |
| Low | UBUNTU-CVE-2026-59848 | libssh | no fix listed |
| Low | UBUNTU-CVE-2026-5704 | tar | 1.30+dfsg-7ubuntu0.20.04.4+esm3 |
| Low | GHSA-5c9x-8gcm-mpgx | axios | 1.15.1 |
| Low | GHSA-vf2m-468p-8v99 | axios | 1.15.1 |
| Low | GHSA-x426-x7cc-3fpc | @hapi/ | 18.1.2 |
| Low | UBUNTU-CVE-2026-72522 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-22695 | libpng1.6 | 1.6.37-2ubuntu0.1~esm2 |
| Low | UBUNTU-CVE-2026-56403 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56404 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56405 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56408 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56406 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56407 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56410 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56411 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-78410 | util-linux | no fix listed |
| Low | GHSA-q6x5-8v7m-xcrf | protobufjs | 7.5.6 |
| Low | GHSA-q6x5-8v7m-xcrf | @protobufjs/ | 1.1.1 |
| Low | GHSA-866g-f22w-33x8 | @ai-sdk/ | 3.0.28 |
| Low | UBUNTU-CVE-2025-14104 | util-linux | no fix listed |
| Low | GHSA-445q-vr5w-6q77 | axios | 1.15.1 |
| Low | UBUNTU-CVE-2025-64505 | libpng1.6 | 1.6.37-2ubuntu0.1~esm1 |
| Low | UBUNTU-CVE-2026-42014 | gnutls28 | 3.6.13-2ubuntu1.12+esm3 |
| Low | UBUNTU-CVE-2026-78409 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2024-13176 | openssl | 1.1.1f-1ubuntu2.fips.24 |
| Low | GHSA-2x7j-588g-ccc2 | nodemailer | 9.1.0 |
| Low | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.1 |
| Low | UBUNTU-CVE-2025-52099 | sqlite3 | 3.31.1-4ubuntu0.7 |
| Low | UBUNTU-CVE-2026-22801 | libpng1.6 | 1.6.37-2ubuntu0.1~esm2 |
| Low | UBUNTU-CVE-2026-58055 | nghttp2 | no fix listed |
| Low | GHSA-x7hr-w5r2-h6wg | prismjs | 1.30.0 |
| Low | GHSA-fx83-v9x8-x52w | protobufjs | 7.5.6 |
| Low | GHSA-jggg-4jg4-v7c6 | protobufjs | 7.5.8 |
| Low | UBUNTU-CVE-2025-29088 | sqlite3 | 3.31.1-4ubuntu0.7 |
| Low | UBUNTU-CVE-2026-40225 | systemd | 245.4-4ubuntu3.24+esm3 |
| Low | GHSA-48c2-rrv3-qjmp | yaml | 1.10.3 |
| Low | UBUNTU-CVE-2026-56409 | expat | no fix listed |