mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of mintproject/model-catalog-endpoint
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04 resolved to ffbb13f20465, scanned 14 Sept 2026: 181 findings, 12 critical, 1 on KEV; deployed by 1 chart, among them MINT.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
181 distinct on this digest
Findings for digest ffbb13f20465 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2020-15999KEV | freetype | 2.9.1-r3 |
| Critical | GHSA-v98j-7crc-wvrj | shiro-web | 1.7.1 |
| Critical | GHSA-f6jp-j6w3-w9hm | shiro-core | 1.8.0 |
| Critical | GHSA-2qrg-x229-3v8q | log4j | no fix listed |
| Critical | GHSA-65fg-84f6-3jq3 | log4j | no fix listed |
| Critical | GHSA-f7vh-qwp3-x37m | log4j | no fix listed |
| Critical | GHSA-rfx6-vp9g-rh7v | jackson-databind | 2.7.9.2 |
| Critical | GHSA-w9p3-5cr8-m3jj | log4j | no fix listed |
| Critical | ALPINE-CVE-2019-8457 | sqlite | 3.28.0-r0 |
| Critical | GHSA-p66x-2cv9-qq3v | commons-beanutils | 1.9.4 |
| Critical | GHSA-vv7r-c36w-3prj | commons-fileupload | 1.6.0 |
| Critical | GHSA-qxxx-2pp7-5hmx | jackson-databind | 2.6.7.1 |
| High | GHSA-fp5r-v3w9-4333 | log4j | no fix listed |
| High | GHSA-4cf5-xmhp-3xj7 | shiro-core | 1.9.1 |
| High | GHSA-4w82-r329-3q67 | jackson-databind | 2.6.7.4 |
| High | GHSA-72w9-fcj5-3fcg | shiro-core | 1.5.3 |
| High | GHSA-26vr-8j45-3r4w | jetty-server | 9.4.39 |
| High | GHSA-26gr-cvq3-qxgf | shiro-core | 1.5.2 |
| High | ALPINE-CVE-2021-23840 | openssl | 1.1.1j-r0 |
| High | GHSA-hfrx-6qgj-fp6c | commons-fileupload | 1.5 |
| High | GHSA-2vgm-wxr3-6w2j | shiro-core | 1.6.0 |
| High | GHSA-cggj-fvv3-cqwv | jackson-databind | 2.6.7.5 |
| High | GHSA-q93h-jc49-78gg | jackson-databind | 2.7.9.7 |
| High | GHSA-p43x-xfjf-5jhr | jackson-databind | 2.7.9.7 |
| High | ALPINE-CVE-2021-3449 | openssl | 1.1.1k-r0 |
| High | GHSA-645p-88qh-w398 | jackson-databind | 2.6.7.3 |
| High | GHSA-gwcr-j4wh-j3cq | jetty-servlets | 9.4.41 |
| High | GHSA-m394-8rww-3jr7 | jetty-server | 9.4.37 |
| High | GHSA-6phf-73q6-gh87 | commons-beanutils | 1.9.4 |
| High | GHSA-9gph-22xh-8x98 | jackson-databind | 2.6.7.5 |
| High | GHSA-9mxf-g3x6-wv74 | jackson-databind | 2.9.7 |
| High | GHSA-h822-r4r5-v8jg | jackson-databind | 2.6.7.3 |
| High | GHSA-c8hm-7hpq-7jhg | jackson-databind | 2.6.7.3 |
| High | GHSA-f9hv-mg5h-xcw9 | jackson-databind | 2.9.8 |
| High | GHSA-mx9v-gmh4-mgqw | jackson-databind | 2.9.8 |
| High | GHSA-mph4-vhrx-mv67 | jackson-databind | 2.6.7.3 |
| High | GHSA-5ww9-j83m-q7qx | jackson-databind | 2.6.7.3 |
| High | GHSA-4gq5-ch57-c2mg | jackson-databind | 2.7.9.5 |
| High | GHSA-gww7-p5w4-wrfv | jackson-databind | 2.6.7.4 |
| High | GHSA-h592-38cm-4ggp | jackson-databind | 2.6.7.3 |
| High | GHSA-6fpp-rgj9-8rwc | jackson-databind | 2.7.9.6 |
| High | GHSA-288c-cq4h-88gq | jackson-databind | 2.9.10.7 |
| High | ALPINE-CVE-2019-12900 | bzip2 | 1.0.6-r7 |
| High | GHSA-x2w5-5m2g-7h5m | jackson-databind | 2.9.7 |
| High | GHSA-vmfg-rjjm-rjrj | logback-core | 1.2.0 |
| High | GHSA-vmfg-rjjm-rjrj | logback-classic | 1.2.0 |
| High | GHSA-53x6-4x5p-rrvv | commons-compress | 1.19 |
| High | GHSA-5r5r-6hpj-8gg9 | jackson-databind | 2.9.10.8 |
| Medium | GHSA-f9xh-2qgp-cq57 | jackson-databind | 2.6.7.5 |
| Medium | GHSA-m6x4-97wx-4q27 | jackson-databind | 2.9.10.8 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| MINTmint | 8.0.2 | 29256555a6fbaefae4729d5cd259564708a4ab04 | 2 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.