n8nio/n8n:0.136.0 container image
Docker HubScanned 29 Sept 2026
Deployed by 1 of 17,939 indexed charts (latest versions) at this tag.Docker Hub all tags of n8nio/n8n
n8nio/n8n:0.136.0 resolved to e8302e8bd402, scanned 29 Sept 2026: 436 findings, 4 critical; deployed by 1 chart, among them n8n.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
436 distinct on this digest
Findings for digest e8302e8bd402 as scanned on 29 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 29 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-8qq5-rm4j-mr97 | tar | 7.5.3 |
| Low | GHSA-776f-qx25-q3cc | xml2js | 0.5.0 |
| Low | GHSA-f3f2-mcxc-pwjx | n8n | 2.4.0 |
| Low | GHSA-c2c7-rcm5-vvqj | picomatch | 2.3.2 |
| Low | GHSA-px8p-9vwx-vf98 | fflate | 0.7.5 |
| Low | GHSA-xwx6-jjhv-84p8 | n8n | 1.123.67 |
| Low | GHSA-mqr2-w7wj-jjgr | mysql2 | 3.9.3 |
| Low | GHSA-35q8-9mj6-wjmf | n8n | 1.123.64 |
| Low | GHSA-6h8r-xr42-gp59 | xmldom | no fix listed |
| Low | GHSA-qpx9-hpmf-5gmw | underscore | 1.13.8 |
| Low | GHSA-j535-v25q-vx3q | n8n | 1.123.76 |
| Low | ALPINE-CVE-2020-8284 | curl | 7.79.0-r0 |
| Low | GHSA-mp4j-h6gh-f6mp | n8n | 1.123.32 |
| Low | GHSA-6h4j-wcr9-2vg7 | n8n | 1.123.43 |
| Low | GHSA-jchw-25xp-jwwc | follow-redirects | 1.15.4 |
| Low | GHSA-rv95-896h-c2vc | express | 4.19.2 |
| Low | GHSA-mm7p-fcc7-pg87 | nodemailer | 7.0.7 |
| Low | GHSA-r6q2-hw4h-h46w | tar | 7.5.4 |
| Low | GHSA-rm2v-h48j-895m | n8n | 1.123.55 |
| Low | GHSA-mhxj-85r3-2x55 | file-type | 16.5.4 |
| Low | GHSA-f886-m6hf-6m8v | brace-expansion | 1.1.13 |
| Low | GHSA-2g4f-4pwh-qvx6 | ajv | 6.14.0 |
| Low | GHSA-p3rg-hrf9-w9gj | n8n | 1.123.64 |
| Low | GHSA-p8p7-x288-28g6 | request | no fix listed |
| Low | GHSA-4jrm-c32x-w4jf | convict | 6.2.4 |
| Low | GHSA-h44j-f5r5-ph73 | n8n | 2.27.4 |
| Low | GHSA-w5hq-g745-h8pq | uuid | 11.1.1 |
| Low | GHSA-9cmh-xcqm-5hqr | n8n | 1.123.67 |
| Low | GHSA-6qc9-mqvw-jg7x | n8n | 1.123.67 |
| Low | GHSA-756q-gq9h-fp22 | n8n | 1.123.32 |
| Low | GHSA-jpq7-226w-6cxx | n8n | 2.24.0 |
| Low | GHSA-6chq-wfr3-2hj9 | axios | 0.31.1 |
| Low | GHSA-wf5p-g6vw-rhxx | axios | 0.28.0 |
| Low | ALPINE-CVE-2021-23839 | openssl | 1.1.1j-r0 |
| Low | GHSA-34ff-336r-5q23 | n8n | 1.123.76 |
| Low | GHSA-33q9-f52j-gc75 | n8n | 2.27.4 |
| Low | GHSA-6gmq-8vp8-gcm6 | xmldom | no fix listed |
| Low | GHSA-825q-w924-xhgx | n8n | 1.122.5 |
| Low | GHSA-fvcv-3m26-pcqx | axios | 0.31.0 |
| Low | GHSA-9wcp-9r3j-383q | n8n | 1.123.64 |
| Low | GHSA-q3j5-8vrg-4p9q | n8n | 1.123.61 |
| Low | GHSA-qwph-4952-7xr6 | jsonwebtoken | 9.0.0 |
| Low | GHSA-mpwj-fcr6-x34c | yarn | 1.22.13 |
| Low | GHSA-ggjm-f3g4-rwmm | n8n | 1.106.0 |
| Low | GHSA-cj9h-qx8g-pq2g | n8n | 1.123.67 |
| Low | GHSA-968p-4wvh-cqc8 | @babel/ | 7.26.10 |
| Low | GHSA-3p68-rc4w-qgx5 | axios | 0.31.0 |
| Low | GHSA-64xh-79j6-r5v8 | n8n | 2.31.5 |
| Low | GHSA-679f-58pq-4v2c | n8n | 2.37.7 |
| Low | GHSA-xvh5-5qg4-x9qp | n8n | 1.123.22 |