linuxserver/unifi-controller:8.0.24 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of linuxserver/unifi-controller
linuxserver/unifi-controller:8.0.24 resolved to 0ae315a3a456, scanned 14 Sept 2026: 789 findings, 12 critical, 4 on KEV; deployed by 1 chart, among them unifi-controller.
Radar Score
789 findings on digest 0ae315a3a456 · scanned 14 Sept 2026
KEV ×4 confirmed exploitedRadar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
Findings for digest 0ae315a3a456 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | UBUNTU-CVE-2024-45490 | expat | 2.2.9-1ubuntu0.7 |
| Medium | UBUNTU-CVE-2023-0464 | openssl | 1.1.1f-1ubuntu2.fips.18 |
| Medium | GHSA-gqp3-2cvr-x8m3 | tomcat-embed-core | 9.0.108 |
| Medium | GHSA-r29c-68gh-xp6x | tomcat-embed-core | 9.0.118 |
| Medium | UBUNTU-CVE-2024-37371 | krb5 | 1.17-6ubuntu4.6 |
| Medium | GHSA-q3mw-pvr8-9ggc | tomcat-embed-core | 9.0.80 |
| Medium | GHSA-hgjh-9rj2-g67j | spring-web | 5.3.33 |
| Medium | UBUNTU-CVE-2017-11164 | pcre3 | no fix listed |
| Medium | GHSA-wxr5-93ph-8wr9 | commons-beanutils | 1.11.0 |
| Medium | UBUNTU-CVE-2024-4741 | openssl | 1.1.1f-1ubuntu2.23 |
| Medium | UBUNTU-CVE-2024-52533 | glib2.0 | 2.64.6-1~ubuntu20.04.8 |
| Medium | GHSA-jjjh-jjxp-wpff | jackson-databind | 2.13.4.2 |
| Medium | GHSA-rgv9-q543-rqg4 | jackson-databind | 2.13.4 |
| Medium | GHSA-735f-pc8j-v9w8 | protobuf-java | 3.25.5 |
| Medium | GHSA-h6fc-48rj-7qqh | tomcat-embed-core | 9.0.118 |
| Medium | GHSA-3mc7-4q67-w48m | snakeyaml | 1.31 |
| Medium | GHSA-fccv-jmmp-qg76 | tomcat-embed-core | 9.0.83 |
| Medium | UBUNTU-CVE-2026-19931 | curl | no fix listed |
| Medium | GHSA-7jqf-v358-p8g7 | tomcat-embed-core | 9.0.90 |
| Medium | GHSA-rq2w-37h9-vg94 | tomcat-embed-core | 9.0.69 |
| Medium | UBUNTU-CVE-2021-33560 | libgcrypt20 | 1.8.5-5ubuntu1.fips.1.1 |
| Medium | UBUNTU-CVE-2023-3446 | openssl | 1.1.1f-1ubuntu2.fips.20 |
| Medium | UBUNTU-CVE-2017-11692 | yaml-cpp | no fix listed |
| Medium | UBUNTU-CVE-2016-20013 | glibc | no fix listed |
| Medium | UBUNTU-CVE-2023-31486 | perl | no fix listed |
| Medium | GHSA-wc4r-xq3c-5cf3 | tomcat-embed-core | 9.0.106 |
| Medium | UBUNTU-CVE-2018-5709 | krb5 | no fix listed |
| Medium | GHSA-r6j3-px5g-cq3x | tomcat-embed-core | 9.0.81 |
| Medium | GHSA-wr62-c79q-cv37 | tomcat-embed-core | 9.0.107 |
| Medium | GHSA-5m62-pw8w-7w9f | tomcat-embed-core | 9.0.118 |
| Medium | UBUNTU-CVE-2024-28757 | expat | no fix listed |
| Medium | GHSA-25xr-qj8w-c4vf | tomcat-embed-core | 9.0.107 |
| Medium | UBUNTU-CVE-2023-2953 | openldap | 2.4.49+dfsg-2ubuntu1.10 |
| Medium | GHSA-4j3c-42xv-3f84 | tomcat-embed-core | 9.0.107 |
| Medium | UBUNTU-CVE-2023-52425 | expat | no fix listed |
| Medium | UBUNTU-CVE-2023-25193 | harfbuzz | 2.6.4-1ubuntu4.3 |
| Medium | GHSA-c28r-hw5m-5gv3 | aws-java-sdk-s3 | 1.12.261 |
| Medium | GHSA-qcwq-55hx-v3vh | snappy-java | 1.1.10.1 |
| Medium | GHSA-h2fw-rfh5-95r3 | tomcat-embed-core | 9.0.105 |
| Medium | UBUNTU-CVE-2011-10043 | perl | no fix listed |
| Medium | GHSA-9xv2-5v5q-p794 | tomcat-embed-core | 9.0.121 |
| Medium | GHSA-wrvw-hg22-4m67 | protobuf-java | 3.16.1 |
| Medium | UBUNTU-CVE-2022-2097 | openssl | 1.1.1f-1ubuntu2.fips.16 |
| Medium | UBUNTU-CVE-2018-20573 | yaml-cpp | no fix listed |
| Medium | UBUNTU-CVE-2018-20574 | yaml-cpp | no fix listed |
| Medium | UBUNTU-CVE-2024-33599 | glibc | 2.31-0ubuntu9.16 |
| Medium | GHSA-9w3m-gqgf-c4p9 | snakeyaml | 1.32 |
| Medium | UBUNTU-CVE-2019-6285 | yaml-cpp | no fix listed |
| Medium | UBUNTU-CVE-2026-4176 | perl | no fix listed |
| Medium | UBUNTU-CVE-2024-0553 | gnutls28 | 3.6.13-2ubuntu1.10 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| unifi-controllerqonstruktVerified publisher | 2.6.1 | 8.0.24 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.