pantsel/konga:latest container image
Docker HubScanned 14 Sept 2026
Deployed by 3 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of pantsel/konga
pantsel/konga:latest resolved to c8172b75607d, scanned 14 Sept 2026: 281 findings, 1 critical, 1 on KEV; deployed by 3 charts, among them konga, openapi and konga.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
129 distinct on this digest
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest c8172b75607d as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-c2qf-rxjj-qqgw | semver | 5.7.2 |
| Medium | ALPINE-CVE-2021-42380 | busybox | 1.31.1-r11 |
| Medium | GHSA-qm95-pgcg-qqfq | socket.io-parser | 3.3.3 |
| Medium | GHSA-xfhh-g9f5-x4m4 | socket.io-parser | 3.3.2 |
| Medium | GHSA-29mw-wpgm-hmr9 | lodash | 4.17.21 |
| Medium | ALPINE-CVE-2021-42379 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42381 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42385 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42378 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42382 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42384 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42386 | busybox | 1.31.1-r11 |
| Medium | GHSA-qq89-hq3f-393p | tar | 4.4.18 |
| Medium | GHSA-xf7w-r453-m56c | fstream | 1.0.12 |
| Medium | GHSA-gqgv-6jq5-jjj9 | qs | 6.0.4 |
| Medium | GHSA-6x77-rpqf-j6mw | ejs | 2.5.5 |
| Medium | GHSA-3wqf-4x89-9g79 | bootstrap | 3.4.0 |
| Medium | GHSA-pq67-2wwv-3xjx | tar-fs | 1.16.4 |
| Medium | GHSA-89mq-4x47-5v83 | angular | 1.7.9 |
| Medium | GHSA-4p24-vmcr-4gqj | bootstrap | 3.4.0 |
| Medium | GHSA-7mvr-5x2g-wfc8 | bootstrap | 3.4.0 |
| Medium | GHSA-wrvr-8mpx-r7pp | mime | 1.4.1 |
| Medium | GHSA-pc58-wgmc-hfjr | mout | 1.2.3 |
| Medium | GHSA-ph58-4vrj-w6hr | bootstrap | 3.4.0 |
| Medium | GHSA-vvv8-xw5f-3f88 | mout | 1.2.4 |
| Medium | GHSA-x2mc-8fgj-3wmr | tar-fs | 1.16.2 |
| Medium | GHSA-7mwh-4pqv-wmr8 | scss-tokenizer | 0.4.3 |
| Medium | GHSA-3mgp-fx93-9xv5 | bootstrap | 3.4.0 |
| Medium | GHSA-x5rq-j2xg-h7qm | lodash | 4.17.11 |
| Medium | GHSA-9vvw-cc9w-f27h | debug | 2.6.9 |
| Medium | ALPINE-CVE-2021-42383 | busybox | 1.31.1-r11 |
| Medium | GHSA-8462-q7x7-g2x4 | bson | 1.0.5 |
| Medium | GHSA-m5pj-vjjf-4m3h | grunt | 1.3.0 |
| Medium | GHSA-4w4v-5hc9-xrr2 | angular | no fix listed |
| Medium | GHSA-f8q6-p94x-37v3 | minimatch | 3.0.5 |
| Medium | GHSA-f7f4-hqp2-7prc | sails-hook-sockets | 1.5.5 |
| Medium | GHSA-hxm2-r34f-qmc5 | minimatch | 3.0.2 |
| Medium | GHSA-m2h2-264f-f486 | angular | no fix listed |
| Medium | GHSA-2m39-62fm-q8r3 | sshpk | 1.13.2 |
| Medium | GHSA-72xf-g2v4-qvf3 | tough-cookie | 4.1.3 |
| Medium | GHSA-5955-9wpr-37jh | tar | 4.4.18 |
| Medium | GHSA-rc47-6667-2j5j | http-cache-semantics | 4.1.1 |
| Medium | GHSA-9qj9-36jm-prpv | fresh | 0.5.2 |
| Medium | GHSA-4xc9-xhrj-v574 | lodash | 4.17.11 |
| Medium | GHSA-fvqr-27wr-82fm | lodash | 4.17.5 |
| Medium | GHSA-q75g-2496-mxpp | parsejson | no fix listed |
| Medium | GHSA-mf6x-7mm4-x2g7 | stringstream | 0.0.6 |
| Medium | GHSA-pp7h-53gx-mx7r | bl | 1.2.3 |
| Medium | GHSA-7mc5-chhp-fmc3 | negotiator | 0.6.1 |
| Medium | GHSA-c429-5p7v-vgjp | hoek | no fix listed |