mojaloop/reporting-events-processor-svc:v3.5.1 container image
Docker HubScanned 14 Sept 2026
Deployed by 2 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of mojaloop/reporting-events-processor-svc
mojaloop/reporting-events-processor-svc:v3.5.1 resolved to 1e0d24d28512, scanned 14 Sept 2026: 213 findings, 0 critical; deployed by 2 charts, among them finance-portal and reporting-events-processor-svc.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
213 distinct on this digest
Findings for digest 1e0d24d28512 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | ALPINE-CVE-2025-15467 | openssl | 3.5.5-r0 |
| High | GHSA-phwq-j96m-2c2q | ejs | 3.1.7 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 3.0.4 |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | GHSA-43fc-jf86-j433 | axios | 1.13.5 |
| Medium | ALPINE-CVE-2025-11187 | openssl | 3.5.5-r0 |
| Medium | GHSA-wf6x-7x77-mvgw | immutable | 5.1.5 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | GHSA-xq3m-2v4x-88gg | protobufjs | 7.5.5 |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.5.4-r0 |
| Medium | GHSA-rf6f-7fwh-wjgh | flatted | 3.4.2 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.5.4-r0 |
| Medium | GHSA-cgfm-xwp7-2cvr | sanitize-html | 2.7.1 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-42764 | openssl | 3.5.7-r0 |
| Medium | GHSA-vrm6-8vpv-qv8q | undici | 7.24.0 |
| Medium | GHSA-4hjh-wcwx-xvwj | axios | 1.12.0 |
| Medium | GHSA-282f-qqgm-c34q | jsonpointer | 5.0.0 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | GHSA-xvcm-6775-5m9r | immutable | 5.1.8 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.5.4-r0 |
| Medium | GHSA-v88g-cgmw-v5xw | ajv | 6.12.3 |
| Medium | GHSA-37ch-88jc-xwx2 | path-to-regexp | 0.1.13 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.5.6-r0 |
| Medium | GHSA-99f4-grh7-6pcq | @grpc/ | 1.13.5 |
| Medium | GHSA-m7jm-9gc2-mpf2 | fast-xml-parser | 4.5.4 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.5.5-r0 |
| Medium | GHSA-v9p9-hfj2-hcw8 | undici | 7.24.0 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 1.16.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.5.6-r0 |
| Medium | GHSA-jmr7-xgp7-cmfj | fast-xml-parser | 4.5.4 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 9.0.6 |
| Medium | GHSA-25h7-pfq9-p65f | flatted | 3.4.0 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.5.6-r0 |
| Medium | GHSA-pf86-5x62-jrwf | axios | 1.15.1 |
| Low | ALPINE-CVE-2025-69420 | openssl | 3.5.5-r0 |
| Low | GHSA-vxpw-j846-p89q | undici | 7.28.0 |
| Low | GHSA-6vfc-qv3f-vr6c | markdown-it | 12.3.2 |
Used by
2 charts
| Chart | Version | Tag | Containers |
|---|---|---|---|
| finance-portalmojaloop | 5.1.4 | v3.5.1 | 1 |
| reporting-events-processor-svcmojaloop | 3.5.3 | v3.5.1 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.