lightbend/spark-history-server:2.4.0 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of lightbend/spark-history-server
lightbend/spark-history-server:2.4.0 resolved to 0bedf37f428a, scanned 14 Sept 2026: 166 findings, 8 critical; deployed by 1 chart, among them spark-history-server.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
166 distinct on this digest
Findings for digest 0bedf37f428a as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-3mc7-4q67-w48m | snakeyaml | 1.31 |
| Medium | GHSA-gwrp-pvrq-jmwv | commons-io | 2.7 |
| Medium | GHSA-mvr2-9pj6-7w5j | guava | 24.1.1-android |
| Medium | GHSA-f256-j965-7f32 | netty | no fix listed |
| Medium | ALPINE-CVE-2018-14048 | libpng | 1.6.37-r0 |
| Medium | GHSA-xc67-hjx6-cgg6 | jetty-server | 9.3.27.v20190418 |
| Medium | GHSA-hrmr-f5m6-m9pq | commons-compress | 1.18 |
| Medium | ALPINE-CVE-2018-14498 | libjpeg-turbo | 1.5.3-r5 |
| Medium | GHSA-vp98-w2p3-mv35 | log4j | 2.0 |
| Medium | GHSA-h24p-qwf4-84q8 | hadoop-common | 2.8.1 |
| Medium | GHSA-rhrv-645h-fjfh | avro | 1.11.3 |
| Medium | GHSA-qcwq-55hx-v3vh | snappy-java | 1.1.10.1 |
| Medium | GHSA-wx5j-54mm-rqqq | netty | no fix listed |
| Medium | GHSA-wrvw-hg22-4m67 | protobuf-java | 3.16.1 |
| Medium | GHSA-9w3m-gqgf-c4p9 | snakeyaml | 1.32 |
| Medium | GHSA-pvp8-3xj6-8c6x | commons-configuration | no fix listed |
| Medium | GHSA-c8cc-p3j7-4c7f | mesos | 1.4.2 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang | no fix listed |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | GHSA-r28m-g6j9-r2h5 | jetty-server | 9.3.27.v20190418 |
| Medium | GHSA-c4r9-r8fh-9vj2 | snakeyaml | 1.31 |
| Medium | GHSA-cgp8-4m63-fhh5 | commons-net | 3.9.0 |
| Medium | GHSA-78wr-2p64-hpwj | commons-io | 2.14.0 |
| Medium | ALPINE-CVE-2019-19242 | sqlite | 3.25.3-r3 |
| Medium | GHSA-98wm-3w3q-mw94 | snakeyaml | 1.31 |
| Medium | GHSA-qw69-rqj8-6qw8 | jetty-server | 9.4.51.v20230217 |
| Medium | ALPINE-CVE-2019-5094 | e2fsprogs | 1.44.2-r1 |
| Medium | GHSA-55g7-9cwv-5qfv | snappy-java | 1.1.10.4 |
| Medium | GHSA-h46c-h94j-95f3 | jackson-core | 2.15.0 |
| Medium | GHSA-hxp5-8pgq-mgv9 | calcite-core | 1.26.0 |
| Medium | GHSA-w37g-rhq8-7m4j | snakeyaml | 1.32 |
| Medium | GHSA-5mcr-gq6c-3hq2 | netty | no fix listed |
| Medium | GHSA-3cqm-mf7h-prrj | okhttp | 4.9.2 |
| Medium | GHSA-g5ww-5jh7-63cx | protobuf-java | 3.16.3 |
| Medium | GHSA-pqr6-cmr2-h8hf | snappy-java | 1.1.10.1 |
| Low | ALPINE-CVE-2018-1000654 | libtasn1 | 4.14-r0 |
| Low | GHSA-973x-65j7-xcf4 | aircompressor | 0.27 |
| Low | GHSA-77pm-w3hx-f8mj | spark-hive-thriftserver_2.11 | no fix listed |
| Low | ALPINE-CVE-2019-5188 | e2fsprogs | 1.44.2-r2 |
| Low | GHSA-fjpj-2g6w-x25r | snappy-java | 1.1.10.1 |
| Low | GHSA-4gg5-vx3j-xwc7 | protobuf-java | 3.16.3 |
| Low | ALPINE-CVE-2018-16435 | lcms2 | 2.9-r1 |
| Low | GHSA-vx9q-rhv9-3jvg | aircompressor | 2.0.3 |
| Low | GHSA-w33c-445m-f8w7 | okio | 1.17.6 |
| Low | GHSA-8wv5-x4w7-5gww | libthrift | 0.24.0 |
| Low | GHSA-43xg-8wmj-cw8h | spark-core_2.11 | no fix listed |
| Low | GHSA-7pwc-h2j2-rjgj | libthrift | 0.23.0 |
| Low | GHSA-g8m5-722r-8whq | jetty-server | 9.4.56 |
| Low | ALPINE-CVE-2018-20217 | krb5 | 1.15.4-r0 |
| Low | GHSA-h4h5-3hr4-j3g2 | protobuf-java | 3.16.3 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| spark-history-servercloudnativeapp | 1.0.0 | 2.4.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.