owasp/dependency-track:3.8.0 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of owasp/dependency-track
owasp/dependency-track:3.8.0 resolved to efc65e702ee1, scanned 14 Sept 2026: 139 findings, 5 critical, 1 on KEV; deployed by 1 chart, among them dependency-track.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
139 distinct on this digest
Findings for digest efc65e702ee1 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | GHSA-j9h8-phrw-h4fhKEV | xstream | 1.4.18 |
| Critical | GHSA-45hx-wfhj-473x | h2 | 2.1.210 |
| Critical | GHSA-h376-j262-vhq6 | h2 | 2.0.206 |
| Critical | GHSA-mjmj-j48q-9wg2 | snakeyaml | 2.0 |
| Critical | GHSA-mw36-7c6c-q4q2 | xstream | 1.4.14-java7 |
| High | GHSA-2p3x-qw9c-25hh | xstream | 1.4.16 |
| High | GHSA-7chv-rrw6-w6fc | xstream | 1.4.17 |
| High | GHSA-jfvx-7wrx-43fh | xstream | 1.4.15 |
| High | GHSA-26vr-8j45-3r4w | jetty-server | 9.4.39 |
| High | ALPINE-CVE-2021-23840 | openssl | 1.1.1j-r0 |
| High | GHSA-4cch-wxpw-8p28 | xstream | 1.4.15 |
| High | GHSA-4hrm-m67v-5cxr | xstream | 1.4.16 |
| High | GHSA-hwpc-8xqv-jvj4 | xstream | 1.4.16 |
| High | GHSA-hrcp-8f3q-4w2c | xstream | 1.4.16 |
| High | ALPINE-CVE-2021-3449 | openssl | 1.1.1k-r0 |
| High | GHSA-m394-8rww-3jr7 | jetty-server | 9.4.37 |
| High | GHSA-59jw-jqf4-3wq3 | xstream | 1.4.16 |
| High | GHSA-rvwf-54qp-4r6v | snakeyaml | 1.26 |
| High | GHSA-f6hm-88x3-mfjv | xstream | 1.4.16 |
| High | GHSA-g5w6-mrj7-75h2 | xstream | 1.4.18 |
| High | GHSA-x3rh-m7vp-35f2 | jetty-server | 9.4.30.v20200611 |
| High | GHSA-p8pq-r894-fm8f | xstream | 1.4.18 |
| High | GHSA-288c-cq4h-88gq | jackson-databind | 2.10.5.1 |
| High | GHSA-hvv8-336g-rx3m | xstream | 1.4.16 |
| High | GHSA-xw4p-crpj-vjx2 | xstream | 1.4.18 |
| High | GHSA-74cv-f58x-f9wf | xstream | 1.4.16 |
| Medium | GHSA-4jrv-ppp4-jm57 | gson | 2.8.9 |
| Medium | GHSA-mc84-pj99-q6hh | commons-compress | 1.21 |
| Medium | GHSA-3f7h-mf4q-vrm4 | woodstox-core | 6.4.0 |
| Medium | GHSA-crv7-7245-f45f | commons-compress | 1.21 |
| Medium | GHSA-7hfm-57qf-j43q | commons-compress | 1.21 |
| Medium | GHSA-j563-grx4-pjpv | xstream | 1.4.20 |
| Medium | GHSA-24rp-q3w6-vc56 | postgresql | 42.2.28 |
| Medium | GHSA-mw3r-pfmg-xp92 | xmlbeans | 3.0.0 |
| Medium | GHSA-xqfj-vm6h-2x34 | commons-compress | 1.21 |
| Medium | GHSA-rmr5-cpv2-vgjf | xstream | 1.4.19 |
| Medium | GHSA-qpfq-ph7r-qv6f | xstream | 1.4.16 |
| Medium | GHSA-3ccq-5vw3-2p6x | xstream | 1.4.18 |
| Medium | GHSA-6w62-hx7r-mw68 | xstream | 1.4.18 |
| Medium | GHSA-h7v4-7xg3-hxcc | xstream | 1.4.18 |
| Medium | GHSA-hph2-m3g5-xxv4 | xstream | 1.4.18 |
| Medium | GHSA-qrx8-8545-4wg2 | xstream | 1.4.18 |
| Medium | GHSA-m72m-mhq2-9p6c | jsoup | 1.14.2 |
| Medium | GHSA-g2fg-mr77-6vrm | libthrift | 0.14.0 |
| Medium | GHSA-64xx-cq4q-mf44 | xstream | 1.4.18 |
| Medium | GHSA-2q8x-2p7f-574v | xstream | 1.4.18 |
| Medium | GHSA-8jrj-525p-826v | xstream | 1.4.18 |
| Medium | GHSA-43gc-mjxg-gvrq | xstream | 1.4.16 |
| Medium | ALPINE-CVE-2019-1551 | openssl | 1.1.1d-r2 |
| Medium | GHSA-cxfm-5m4g-x7xp | xstream | 1.4.18 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| dependency-tracknovum-rgi-charts | 0.1.8 | 3.8.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.