StackRadar

linuxserver/grocy:4.0.1 container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of linuxserver/grocy

linuxserver/grocy:4.0.1 resolved to f8f5f96b6ea8, scanned 14 Sept 2026: 105 findings, 8 critical, 4 on KEV; deployed by 1 chart, among them grocy.

Radar Score

2,4498103849

105 findings on digest f8f5f96b6ea8 · scanned 14 Sept 2026

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
4.0.1resolves tof8f5f96b6ea81 chart8 days ago81038492,449

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

49 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest f8f5f96b6ea8 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-m4ch-4m5f-2gp6bootbox@6.0.0no fix listed
LowALPINE-CVE-2023-38546curl@8.2.1-r08.4.0-r0
LowALPINE-CVE-2024-36387apache2@2.4.57-r32.4.60-r0
LowGHSA-hmw2-7cc7-3qxxform-data@2.3.32.5.6
LowALPINE-CVE-2024-50602expat@2.5.0-r12.6.4-r0
LowALPINE-CVE-2024-39884apache2@2.4.57-r32.4.61-r0
LowALPINE-CVE-2023-43787libx11@1.8.4-r41.8.7-r0
LowALPINE-CVE-2024-8096curl@8.2.1-r08.10.0-r0
LowGHSA-j3f9-p6hm-5w6qnesbot/carbon@2.68.12.72.6
LowALPINE-CVE-2023-46219curl@8.2.1-r08.5.0-r0
LowALPINE-CVE-2024-4603openssl@3.1.2-r03.1.5-r0
LowGHSA-2g4f-4pwh-qvx6ajv@6.12.66.14.0
LowALPINE-CVE-2024-0853curl@8.2.1-r08.6.0-r0
LowGHSA-p8p7-x288-28g6request@2.88.2no fix listed
LowGHSA-w5hq-g745-h8pquuid@3.4.011.1.1
LowALPINE-CVE-2025-26519musl@1.2.4-r11.2.4-r3
LowGHSA-cc55-mvqc-g9mgsummernote@0.8.20no fix listed
LowALPINE-CVE-2023-43785libx11@1.8.4-r41.8.7-r0
LowALPINE-CVE-2024-0684coreutils@9.3-r19.3-r2
LowGHSA-v5mv-p594-2x33guzzlehttp/guzzle@7.7.07.15.2
LowALPINE-CVE-2023-43786libx11@1.8.4-r41.8.7-r0
LowALPINE-CVE-2024-2004curl@8.2.1-r08.7.1-r0
LowALPINE-CVE-2023-42364busybox@1.36.1-r21.36.1-r7
LowALPINE-CVE-2023-42363busybox@1.36.1-r21.36.1-r7
LowALPINE-CVE-2023-42366busybox@1.36.1-r21.36.1-r6
LowALPINE-CVE-2023-42365busybox@1.36.1-r21.36.1-r7
LowALPINE-CVE-2024-6874curl@8.2.1-r08.9.0-r0
LowALPINE-CVE-2023-52426expat@2.5.0-r12.6.0-r0
LowALPINE-CVE-2023-49582apr@1.7.4-r01.7.5-r0
LowALPINE-CVE-2024-11053curl@8.2.1-r08.11.1-r0
LowGHSA-h95v-h523-3mw8guzzlehttp/guzzle@7.7.07.15.1
LowGHSA-wm3w-8rrp-j577guzzlehttp/guzzle@7.7.07.15.1
LowALPINE-CVE-2024-13176openssl@3.1.2-r03.1.8-r0
LowGHSA-cwxw-98qj-8qjxguzzlehttp/guzzle@7.7.07.12.1
LowGHSA-4mjr-xmp4-gh2gqs@6.5.36.16.0
LowGHSA-53h4-8rc4-f539slim/slim@4.12.04.15.2
LowGHSA-f7vp-7xgx-4w4rguzzlehttp/guzzle@7.7.07.15.2
LowGHSA-f283-ghqc-fg79guzzlehttp/guzzle@7.7.07.15.1
LowGHSA-94pj-82f3-465wguzzlehttp/guzzle@7.7.07.14.2
LowGHSA-wpwq-4j6v-78m3guzzlehttp/guzzle@7.7.07.12.1
LowGHSA-34xg-wgjx-8xphguzzlehttp/psr7@2.6.02.10.2
LowGHSA-hq7v-mx3g-29hwguzzlehttp/psr7@2.6.02.10.2
LowALPINE-CVE-2025-0167curl@8.2.1-r08.12.0-r0
LowGHSA-vm85-hxw5-5432guzzlehttp/psr7@2.6.02.12.1
LowGHSA-c2w2-prh8-qm98guzzlehttp/psr7@2.6.02.12.3
LowGHSA-6rw7-vpxm-498pqs@6.5.36.14.1
LowALPINE-CVE-2024-32020git@2.40.1-r02.40.3-r0
LowGHSA-g446-98w2-8p5wguzzlehttp/guzzle@7.7.07.12.3
LowALPINE-CVE-2023-4016procps-ng@4.0.3-r14.0.4-r0

Used by

1 chart
ChartVersionTagContainers
grocysarab97Verified publisher0.1.14.0.11

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.