StackRadar

library/sonarqube:9.1.0-datacenter-app container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of library/sonarqube

library/sonarqube:9.1.0-datacenter-app resolved to a9bc5a3a1fc3, scanned 14 Sept 2026: 186 findings, 8 critical, 3 on KEV; deployed by 1 chart, among them sonarqube-dce.

Radar Score

4,0518108088

186 findings on digest a9bc5a3a1fc3 · scanned 14 Sept 2026

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
9.1.0-datacenter-appresolves toa9bc5a3a1fc31 chart8 days ago81080884,051

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

186 distinct on this digest

Findings for digest a9bc5a3a1fc3 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGHSA-xmc8-26q4-qjhxjackson-dataformat-cbor@2.10.42.11.4
MediumGHSA-668q-qrv7-99fmlogback-core@1.2.31.2.9
MediumALPINE-CVE-2022-27405freetype@2.10.4-r12.10.4-r3
MediumALPINE-CVE-2022-40674expat@2.4.1-r02.4.9-r0
MediumGHSA-jjjh-jjxp-wpffjackson-databind@2.11.32.12.7.1
MediumGHSA-rgv9-q543-rqg4jackson-databind@2.11.32.12.7.1
MediumGHSA-735f-pc8j-v9w8protobuf-java@3.11.43.25.5
MediumGHSA-3mc7-4q67-w48msnakeyaml@1.261.31
MediumGHSA-mvr2-9pj6-7w5jguava@19.024.1.1-android
MediumGHSA-v7wg-cpwc-24m4postgresql@42.2.1942.2.25
MediumALPINE-CVE-2022-43680expat@2.4.1-r02.5.0-r0
MediumGHSA-fg2v-w576-w4v3json-smart@1.3.21.3.3
MediumALPINE-CVE-2022-25313expat@2.4.1-r02.4.5-r0
MediumGHSA-hh26-6xwr-ggv7spring-beans@5.3.75.3.20
MediumGHSA-c5hg-mr8r-f6jphazelcast@4.24.2.6
MediumGHSA-r38f-c4h4-hqq2postgresql@42.2.1942.2.26
MediumGHSA-wx5j-54mm-rqqqnetty-codec-http@4.1.49.Final4.1.71.Final
MediumGHSA-wrvw-hg22-4m67protobuf-java@3.11.43.16.1
MediumALPINE-CVE-2022-2097openssl@1.1.1l-r01.1.1q-r0
MediumGHSA-9w3m-gqgf-c4p9snakeyaml@1.261.32
MediumGHSA-6mjq-h674-j845netty-handler@4.1.49.Final4.1.94.Final
MediumGHSA-j288-q9x7-2f5vcommons-lang@2.6no fix listed
MediumGHSA-j288-q9x7-2f5vcommons-lang3@3.103.18.0
MediumGHSA-4jq9-2xhw-jpx7json@2020111520231013
MediumGHSA-c4r9-r8fh-9vj2snakeyaml@1.261.31
MediumGHSA-78wr-2p64-hpwjcommons-io@2.8.02.14.0
MediumGHSA-3qp7-7mw8-wx86netty-handler@4.1.49.Final4.1.135.Final
MediumGHSA-2cqf-6xv9-f22welasticsearch@7.14.17.17.13
MediumGHSA-98wm-3w3q-mw94snakeyaml@1.261.31
MediumGHSA-673j-qm5f-xpv8postgresql@42.2.1942.3.3
MediumGHSA-3vqj-43w4-2q58json@2020111520230227
MediumALPINE-CVE-2022-29458ncurses@6.2_p20210612-r06.2_p20210612-r1
MediumGHSA-3x8x-79m2-3w2wjackson-databind@2.11.32.12.6
MediumGHSA-rmj7-2vxq-3g9fjackson-databind@2.11.32.18.8
MediumGHSA-wxqc-pxw9-g2p8spring-expression@5.3.75.3.27
MediumGHSA-493p-pfq6-5258json-smart@1.3.22.4.9
MediumGHSA-j3rv-43j4-c7qmjackson-databind@2.11.32.18.8
MediumGHSA-h46c-h94j-95f3jackson-core@2.10.42.15.0
MediumGHSA-w37g-rhq8-7m4jsnakeyaml@1.261.32
MediumGHSA-5mcr-gq6c-3hq2netty-codec-http@4.1.49.Final4.1.59.Final
MediumGHSA-f6hv-jmp6-3vwvnetty-codec-http@4.1.49.Final4.1.133.Final
MediumGHSA-vwqq-5vrc-xw9hlog4j-core@2.11.12.12.3
MediumGHSA-jppx-w49h-x2qqnetty-codec-http@4.1.49.Final4.1.136.Final
MediumGHSA-3cqm-mf7h-prrjokhttp@3.14.24.9.2
MediumGHSA-m494-w24q-6f7wmssql-jdbc@9.2.010.2.4.jre11
MediumGHSA-x4gw-5cx5-pgmhnetty-handler@4.1.49.Final4.1.135.Final
MediumGHSA-g5ww-5jh7-63cxprotobuf-java@3.11.43.16.3
MediumGHSA-gvpg-vgmx-xg6wnimbus-jose-jwt@9.8.19.37.2
LowGHSA-xfrj-6vvc-3xm2xmlsec@2.1.42.2.6
LowGHSA-9342-92gg-6v29jakarta.mail@1.6.31.6.8

Used by

1 chart
ChartVersionTagContainers
sonarqube-dcesonarqubeVerified publisher0.1.2+1219.1.0-datacenter-app1

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.