library/ubuntu:latest container image
Docker HubScanned 14 Sept 2026
Deployed by 7 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of library/ubuntu
library/ubuntu:latest resolved to 2260313b31c8, scanned 14 Sept 2026: 88 findings, 0 critical; deployed by 7 charts, among them cronjob, jenkins and base-job.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
88 distinct on this digest
Findings for digest 2260313b31c8 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | UBUNTU-CVE-2026-63073 | openssl | 3.5.5-1ubuntu3.4 |
| Medium | UBUNTU-CVE-2026-18798 | openssl | 3.5.5-1ubuntu3.4 |
| Medium | UBUNTU-CVE-2026-63076 | openssl | 3.5.5-1ubuntu3.4 |
| Medium | UBUNTU-CVE-2026-14457 | openssl | 3.5.5-1ubuntu3.4 |
| Low | UBUNTU-CVE-2026-57433 | perl | 5.40.1-7ubuntu0.3 |
| Low | UBUNTU-CVE-2026-13221 | perl | 5.40.1-7ubuntu0.3 |
| Low | UBUNTU-CVE-2026-14456 | openssl | 3.5.5-1ubuntu3.4 |
| Low | UBUNTU-CVE-2026-12087 | perl | 5.40.1-7ubuntu0.3 |
| Low | UBUNTU-CVE-2026-63072 | openssl | 3.5.5-1ubuntu3.4 |
| Low | UBUNTU-CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1.1 |
| Low | UBUNTU-CVE-2026-54874 | openssl | 3.5.5-1ubuntu3.4 |
| Low | UBUNTU-CVE-2026-86145 | pcre2 | no fix listed |
| Low | UBUNTU-CVE-2026-63075 | openssl | 3.5.5-1ubuntu3.4 |
| Low | UBUNTU-CVE-2026-9538 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-85091 | zlib | no fix listed |
| Low | UBUNTU-CVE-2026-42497 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-75803 | openssl | 3.5.5-1ubuntu3.5 |
| Low | UBUNTU-CVE-2026-48959 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-6791 | glibc | 2.43-2ubuntu2.4 |
| Low | UBUNTU-CVE-2026-57432 | perl | 5.40.1-7ubuntu0.3 |
| Low | UBUNTU-CVE-2026-48962 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-48961 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-63074 | openssl | 3.5.5-1ubuntu3.4 |
| Low | UBUNTU-CVE-2026-7017 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-76642 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-35368 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-19487 | perl | 5.40.1-7ubuntu0.2 |
| Low | UBUNTU-CVE-2026-35341 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-78408 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-54369 | acl | no fix listed |
| Low | UBUNTU-CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2.2 |
| Low | UBUNTU-CVE-2026-54371 | attr | 1:2.5.2-4ubuntu0.1 |
| Low | UBUNTU-CVE-2026-35352 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-78410 | util-linux | no fix listed |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2026-78409 | util-linux | no fix listed |
| Low | GO-2026-5972 | stdlib | 1.25.13 |
| Low | GO-2026-6088 | stdlib | 1.25.13 |
| Low | GO-2026-6089 | stdlib | 1.25.13 |
| Low | GO-2026-6090 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2026-35350 | rust-coreutils | no fix listed |
| Low | GO-2026-5942 | stdlib | 1.26.6 |
| Low | GO-2026-6218 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2026-15534 | perl | 5.40.1-7ubuntu0.2 |
| Low | UBUNTU-CVE-2026-56391 | coreutils-from | 9.7-3ubuntu2.1 |
| Low | UBUNTU-CVE-2026-56391 | coreutils | 9.7-3ubuntu2.1 |
| Low | UBUNTU-CVE-2026-35363 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-35360 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2025-5278 | coreutils-from | 9.7-3ubuntu2.1 |
| Low | UBUNTU-CVE-2025-5278 | coreutils | 9.7-3ubuntu2.1 |
Used by
7 charts
| Chart | Version | Tag | Containers |
|---|---|---|---|
| cronjobclouddrove | 1.0.1 | latest | 1 |
| jenkinshuangchengwu-helm-chart | 0.1.0 | latest | 1 |
| base-jobnn-coVerified publisher | 0.1.0 | latest | 1 |
| jobopen-charts | 2.0.0 | latest | 1 |
| smarterproject-smarterOfficialVerified publisher | 0.13.222 | latestunmeasured: HTTP 429 resolving manifest | 1 |
| nadekobotryuunosukeds3 | 0.1.2 | latest | 1 |
| stresssudermanjr | 0.2.0 | latest | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.