StackRadar

nacos/nacos-server:latest container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 2 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of nacos/nacos-server

nacos/nacos-server:latest resolved to 1c191c30c8cd, scanned 14 Sept 2026: 200 findings, 0 critical; deployed by 2 charts, among them nacos and nacos.

Radar Score

1,7670019181

200 findings on digest 1c191c30c8cd · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
latestresolves to1c191c30c8cd2 charts8 days ago00191811,767

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

200 distinct on this digest

Findings for digest 1c191c30c8cd as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGHSA-r29c-68gh-xp6xtomcat-embed-core@10.1.5410.1.55
MediumGHSA-h6fc-48rj-7qqhtomcat-embed-core@10.1.5410.1.55
MediumUBUNTU-CVE-2026-19931curl@8.18.0-1ubuntu2.4no fix listed
MediumGHSA-5m62-pw8w-7w9ftomcat-embed-core@10.1.5410.1.55
MediumGHSA-9xv2-5v5q-p794tomcat-embed-core@10.1.5410.1.58
MediumUBUNTU-CVE-2026-18924curl@8.18.0-1ubuntu2.4no fix listed
MediumGHSA-c459-2m73-67hjhessian@3.3.63.5.5
MediumGHSA-j288-q9x7-2f5vcommons-lang@2.6no fix listed
MediumGHSA-j288-q9x7-2f5vcommons-lang3@3.17.03.18.0
MediumUBUNTU-CVE-2018-10126libjpeg-turbo@2.1.5-4ubuntu4no fix listed
MediumGHSA-h3x4-894j-xpx5tomcat-embed-core@10.1.5410.1.58
MediumGHSA-rmj7-2vxq-3g9fjackson-databind@2.21.22.21.4
MediumGHSA-j3rv-43j4-c7qmjackson-databind@2.21.22.21.4
MediumGHSA-gcx9-497g-6cp6tomcat-embed-core@10.1.5410.1.58
MediumUBUNTU-CVE-2026-80229curl@8.18.0-1ubuntu2.4no fix listed
MediumGHSA-hf6x-8p5f-cgmfhttpcore5@5.3.65.4.3
MediumGHSA-v3jc-474w-2wm6httpcore5-h2@5.3.65.4.3
MediumUBUNTU-CVE-2026-11940python3.14@3.14.4-1ubuntu0.1no fix listed
MediumGHSA-gx5v-xp9w-j4cgtomcat-embed-core@10.1.5410.1.55
LowUBUNTU-CVE-2026-57433perl@5.40.1-7ubuntu0.15.40.1-7ubuntu0.3
LowGHSA-g3pr-3p32-fp23micrometer-core@1.15.111.15.12
LowUBUNTU-CVE-2026-13221perl@5.40.1-7ubuntu0.15.40.1-7ubuntu0.3
LowUBUNTU-CVE-2026-66032libssh2@1.11.1-1ubuntu0.26.04.31.11.1-1ubuntu0.26.04.4
LowUBUNTU-CVE-2026-82209curl@8.18.0-1ubuntu2.4no fix listed
LowUBUNTU-CVE-2026-80255curl@8.18.0-1ubuntu2.4no fix listed
LowUBUNTU-CVE-2026-7210python3.14@3.14.4-1ubuntu0.1no fix listed
LowUBUNTU-CVE-2026-12087perl@5.40.1-7ubuntu0.15.40.1-7ubuntu0.3
LowUBUNTU-CVE-2026-15308python3.14@3.14.4-1ubuntu0.13.14.4-1ubuntu0.2
LowGHSA-w737-wx49-qj23micrometer-core@1.15.111.15.12
LowUBUNTU-CVE-2026-13608curl@8.18.0-1ubuntu2.4no fix listed
LowGHSA-574f-3g2m-x479bcprov-jdk18on@1.791.80.2
LowUBUNTU-CVE-2026-66046expat@2.7.4-1no fix listed
LowUBUNTU-CVE-2026-66033libssh2@1.11.1-1ubuntu0.26.04.31.11.1-1ubuntu0.26.04.4
LowUBUNTU-CVE-2026-11972python3.14@3.14.4-1ubuntu0.1no fix listed
LowUBUNTU-CVE-2026-80230curl@8.18.0-1ubuntu2.4no fix listed
LowGHSA-fv25-8xcx-gqjctomcat-embed-core@10.1.5410.1.55
LowUBUNTU-CVE-2024-2236libgcrypt20@1.12.0-2ubuntu11.12.0-2ubuntu1.1
LowUBUNTU-CVE-2026-86145pcre2@10.46-1build1no fix listed
LowGHSA-qv9r-c865-cp47log4j-api@2.25.42.25.5
LowUBUNTU-CVE-2026-66035libssh2@1.11.1-1ubuntu0.26.04.31.11.1-1ubuntu0.26.04.4
LowGHSA-5mp6-jrq3-r938tomcat-embed-core@10.1.5410.1.55
LowUBUNTU-CVE-2026-47057openjdk-17@17.0.20+8-1~26.04no fix listed
LowUBUNTU-CVE-2026-9538perl@5.40.1-7ubuntu0.1no fix listed
LowUBUNTU-CVE-2026-85091zlib@1:1.3.dfsg+really1.3.1-1ubuntu3no fix listed
LowUBUNTU-CVE-2026-42497perl@5.40.1-7ubuntu0.1no fix listed
LowGHSA-c3fc-8qff-9hwxbcprov-jdk18on@1.791.84
LowGHSA-x23c-287f-qqv5spring-webmvc@6.2.186.2.19
LowUBUNTU-CVE-2026-8932curl@8.18.0-1ubuntu2.48.18.0-1ubuntu2.5
LowUBUNTU-CVE-2026-75803openssl@3.5.5-1ubuntu3.43.5.5-1ubuntu3.5
LowGHSA-wg6q-6289-32hpbcpkix-jdk18on@1.791.84

Used by

2 charts
ChartVersionTagContainers
nacosgujunxiang0.1.5latest1
nacosbytectl0.1.6latest1

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.