penpotapp/backend:2.2.1 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of penpotapp/backend
penpotapp/backend:2.2.1 resolved to 47853d9bb9dd, scanned 14 Sept 2026: 731 findings, 4 critical, 1 on KEV; deployed by 1 chart, among them penpot.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
601 distinct on this digest
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest 47853d9bb9dd as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-25971 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-53467 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-6390 | nano | no fix listed |
| Low | UBUNTU-CVE-2026-25638 | imagemagick | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm10 |
| Low | UBUNTU-CVE-2026-48994 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-53462 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-72522 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-22695 | libpng1.6 | 1.6.37-3ubuntu0.3 |
| Low | UBUNTU-CVE-2024-56827 | openjpeg2 | 2.4.0-6ubuntu0.3 |
| Low | UBUNTU-CVE-2026-56403 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56404 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56405 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56408 | expat | no fix listed |
| Low | GHSA-gcjf-9mgh-3p7g | netty-codec-http | 4.1.136.Final |
| Low | GHSA-v8h7-rr48-vmmv | netty-codec-http | 4.1.133.Final |
| Low | UBUNTU-CVE-2026-56406 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56407 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56410 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56411 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-78410 | util-linux | no fix listed |
| Low | GHSA-563q-j3cm-6jxm | netty-codec-http2 | 4.1.135.Final |
| Low | UBUNTU-CVE-2025-4516 | python3.10 | 3.10.12-1~22.04.10 |
| Low | UBUNTU-CVE-2025-55005 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2025-64505 | libpng1.6 | 1.6.37-3ubuntu0.1 |
| Low | UBUNTU-CVE-2026-50593 | graphite2 | 1.3.14-1ubuntu0.1 |
| Low | UBUNTU-CVE-2025-6069 | python3.10 | 3.10.12-1~22.04.11 |
| Low | GHSA-5x3r-wrvg-rp6q | netty-codec-http2 | 4.1.135.Final |
| Low | UBUNTU-CVE-2026-86142 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-42014 | gnutls28 | 3.7.3-4ubuntu1.9 |
| Low | UBUNTU-CVE-2026-40169 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-78409 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2024-13176 | openssl | 3.0.2-0ubuntu1.19 |
| Low | UBUNTU-CVE-2025-52099 | sqlite3 | 3.37.2-2ubuntu0.4 |
| Low | UBUNTU-CVE-2026-40312 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-45446 | openssl | 3.0.2-0ubuntu1.25 |
| Low | GHSA-7g45-4rm6-3mm3 | guava | 32.0.0-android |
| Low | UBUNTU-CVE-2026-4360 | python3.10 | 3.10.12-1~22.04.18 |
| Low | UBUNTU-CVE-2026-22801 | libpng1.6 | 1.6.37-3ubuntu0.3 |
| Low | UBUNTU-CVE-2026-25970 | imagemagick | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9 |
| Low | UBUNTU-CVE-2026-3446 | python3.10 | no fix listed |
| Low | UBUNTU-CVE-2023-39328 | openjpeg2 | no fix listed |
| Low | UBUNTU-CVE-2026-58055 | nghttp2 | 1.43.0-1ubuntu0.4 |
| Low | UBUNTU-CVE-2026-54240 | libde265 | 1.0.8-1ubuntu0.3+esm2 |
| Low | UBUNTU-CVE-2026-54241 | libde265 | 1.0.8-1ubuntu0.3+esm2 |
| Low | UBUNTU-CVE-2026-86138 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-2297 | python3.10 | 3.10.12-1~22.04.16 |
| Low | UBUNTU-CVE-2026-86143 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-28494 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-33165 | libde265 | 1.0.8-1ubuntu0.3+esm2 |
| Low | UBUNTU-CVE-2026-56371 | imagemagick | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14 |