StackRadar

offchainlabs/nitro-node:v3.7.6-c0fe95e container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of offchainlabs/nitro-node

offchainlabs/nitro-node:v3.7.6-c0fe95e resolved to 9f779fa84b7b, scanned 14 Sept 2026: 677 findings, 0 critical; deployed by 1 chart, among them arbitrum.

Radar Score

6,9980298576

677 findings on digest 9f779fa84b7b · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v3.7.6-c0fe95eresolves to9f779fa84b7b1 chart8 days ago02985766,998

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

576 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 9f779fa84b7b as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-84890node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4no fix listed
LowDEBIAN-CVE-2024-43790vim@2:9.0.1378-2+deb12u2no fix listed
LowGO-2026-4977stdlib@go1.24.51.25.10
LowDEBIAN-CVE-2026-76957expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2023-31437systemd@252.39-1~deb12u1no fix listed
LowDEBIAN-CVE-2025-68973gnupg2@2.2.40-1.1+deb12u12.2.40-1.1+deb12u2
LowDEBIAN-CVE-2026-43619rsync@3.2.7-1+deb12u23.2.7-1+deb12u5
LowGO-2026-4986stdlib@go1.24.51.25.10
LowGO-2026-4918golang.org/x/net@v0.38.00.53.0
LowGO-2026-4918stdlib@go1.24.51.25.10
LowGO-2026-4337stdlib@go1.24.51.24.13
LowDEBIAN-CVE-2026-4438glibc@2.36-9+deb12u132.36-9+deb12u14
LowDEBIAN-CVE-2023-31438systemd@252.39-1~deb12u1no fix listed
LowDEBIAN-CVE-2026-16728node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4no fix listed
LowDEBIAN-CVE-2026-28419vim@2:9.0.1378-2+deb12u2no fix listed
LowDEBIAN-CVE-2026-1757libxml2@2.9.14+dfsg-1.3~deb12u42.9.14+dfsg-1.3~deb12u6
LowDEBIAN-CVE-2023-27116wabt@1.0.32-1no fix listed
LowDEBIAN-CVE-2023-31124c-ares@1.18.1-3no fix listed
LowDEBIAN-CVE-2023-30300wabt@1.0.32-1no fix listed
LowDEBIAN-CVE-2023-31669wabt@1.0.32-1no fix listed
LowGO-2026-4601stdlib@go1.24.51.25.8
LowDEBIAN-CVE-2025-24014vim@2:9.0.1378-2+deb12u2no fix listed
LowDEBIAN-CVE-2023-27119wabt@1.0.32-1no fix listed
LowDEBIAN-CVE-2026-72522expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2023-48706vim@2:9.0.1378-2+deb12u2no fix listed
LowDEBIAN-CVE-2026-56403expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2026-56404expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2026-56405expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2026-56408expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2026-56406expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2026-56407expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2026-56410expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2026-56411expat@2.5.0-1+deb12u22.5.0-1+deb12u3
LowDEBIAN-CVE-2026-78410util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-3787-6prv-h9w3undici@5.15.05.28.3
LowDEBIAN-CVE-2026-35177vim@2:9.0.1378-2+deb12u2no fix listed
LowDEBIAN-CVE-2023-46332wabt@1.0.32-1no fix listed
LowDEBIAN-CVE-2026-89161pcre2@10.42-110.42-1+deb12u1
LowDEBIAN-CVE-2025-4516python3.11@3.11.2-6+deb12u63.11.2-6+deb12u7
LowGO-2026-5026golang.org/x/net@v0.38.00.55.0
LowGO-2026-5026stdlib@go1.24.51.25.13
LowDEBIAN-CVE-2025-14104util-linux@2.38.1-5+deb12u3no fix listed
LowDEBIAN-CVE-2025-6069python3.11@3.11.2-6+deb12u63.11.2-6+deb12u7
LowGHSA-m4v8-wqvr-p9f7undici@5.15.05.28.4
LowDEBIAN-CVE-2026-86142libxml2@2.9.14+dfsg-1.3~deb12u4no fix listed
LowDEBIAN-CVE-2026-42014gnutls28@3.7.9-2+deb12u53.7.9-2+deb12u7
LowGO-2026-4342stdlib@go1.24.51.24.12
LowDEBIAN-CVE-2026-4105systemd@252.39-1~deb12u1252.39-1~deb12u2
LowDEBIAN-CVE-2026-78409util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-2v4p-qf9q-27wjgoogle.golang.org/grpc@v1.64.11.82.2

Used by

1 chart
ChartVersionTagContainers
arbitrumchronicleVerified publisher0.3.4v3.7.6-c0fe95e1

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.