nacos/nacos-server:latest container image
Docker HubScanned 14 Sept 2026
Deployed by 2 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of nacos/nacos-server
nacos/nacos-server:latest resolved to 1c191c30c8cd, scanned 14 Sept 2026: 200 findings, 0 critical; deployed by 2 charts, among them nacos and nacos.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
200 distinct on this digest
Findings for digest 1c191c30c8cd as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-r29c-68gh-xp6x | tomcat-embed-core | 10.1.55 |
| Medium | GHSA-h6fc-48rj-7qqh | tomcat-embed-core | 10.1.55 |
| Medium | UBUNTU-CVE-2026-19931 | curl | no fix listed |
| Medium | GHSA-5m62-pw8w-7w9f | tomcat-embed-core | 10.1.55 |
| Medium | GHSA-9xv2-5v5q-p794 | tomcat-embed-core | 10.1.58 |
| Medium | UBUNTU-CVE-2026-18924 | curl | no fix listed |
| Medium | GHSA-c459-2m73-67hj | hessian | 3.5.5 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang | no fix listed |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | UBUNTU-CVE-2018-10126 | libjpeg-turbo | no fix listed |
| Medium | GHSA-h3x4-894j-xpx5 | tomcat-embed-core | 10.1.58 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.21.4 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.21.4 |
| Medium | GHSA-gcx9-497g-6cp6 | tomcat-embed-core | 10.1.58 |
| Medium | UBUNTU-CVE-2026-80229 | curl | no fix listed |
| Medium | GHSA-hf6x-8p5f-cgmf | httpcore5 | 5.4.3 |
| Medium | GHSA-v3jc-474w-2wm6 | httpcore5-h2 | 5.4.3 |
| Medium | UBUNTU-CVE-2026-11940 | python3.14 | no fix listed |
| Medium | GHSA-gx5v-xp9w-j4cg | tomcat-embed-core | 10.1.55 |
| Low | UBUNTU-CVE-2026-57433 | perl | 5.40.1-7ubuntu0.3 |
| Low | GHSA-g3pr-3p32-fp23 | micrometer-core | 1.15.12 |
| Low | UBUNTU-CVE-2026-13221 | perl | 5.40.1-7ubuntu0.3 |
| Low | UBUNTU-CVE-2026-66032 | libssh2 | 1.11.1-1ubuntu0.26.04.4 |
| Low | UBUNTU-CVE-2026-82209 | curl | no fix listed |
| Low | UBUNTU-CVE-2026-80255 | curl | no fix listed |
| Low | UBUNTU-CVE-2026-7210 | python3.14 | no fix listed |
| Low | UBUNTU-CVE-2026-12087 | perl | 5.40.1-7ubuntu0.3 |
| Low | UBUNTU-CVE-2026-15308 | python3.14 | 3.14.4-1ubuntu0.2 |
| Low | GHSA-w737-wx49-qj23 | micrometer-core | 1.15.12 |
| Low | UBUNTU-CVE-2026-13608 | curl | no fix listed |
| Low | GHSA-574f-3g2m-x479 | bcprov-jdk18on | 1.80.2 |
| Low | UBUNTU-CVE-2026-66046 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-66033 | libssh2 | 1.11.1-1ubuntu0.26.04.4 |
| Low | UBUNTU-CVE-2026-11972 | python3.14 | no fix listed |
| Low | UBUNTU-CVE-2026-80230 | curl | no fix listed |
| Low | GHSA-fv25-8xcx-gqjc | tomcat-embed-core | 10.1.55 |
| Low | UBUNTU-CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1.1 |
| Low | UBUNTU-CVE-2026-86145 | pcre2 | no fix listed |
| Low | GHSA-qv9r-c865-cp47 | log4j-api | 2.25.5 |
| Low | UBUNTU-CVE-2026-66035 | libssh2 | 1.11.1-1ubuntu0.26.04.4 |
| Low | GHSA-5mp6-jrq3-r938 | tomcat-embed-core | 10.1.55 |
| Low | UBUNTU-CVE-2026-47057 | openjdk-17 | no fix listed |
| Low | UBUNTU-CVE-2026-9538 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-85091 | zlib | no fix listed |
| Low | UBUNTU-CVE-2026-42497 | perl | no fix listed |
| Low | GHSA-c3fc-8qff-9hwx | bcprov-jdk18on | 1.84 |
| Low | GHSA-x23c-287f-qqv5 | spring-webmvc | 6.2.19 |
| Low | UBUNTU-CVE-2026-8932 | curl | 8.18.0-1ubuntu2.5 |
| Low | UBUNTU-CVE-2026-75803 | openssl | 3.5.5-1ubuntu3.5 |
| Low | GHSA-wg6q-6289-32hp | bcpkix-jdk18on | 1.84 |