penpotapp/exporter:1.16.0-beta container image
Docker HubScanned 20 Sept 2026
Deployed by 1 of 17,813 indexed charts (latest versions) at this tag.Docker Hub all tags of penpotapp/exporter
penpotapp/exporter:1.16.0-beta resolved to fa7086ad92b1, scanned 20 Sept 2026: 1,106 findings, 9 critical, 4 on KEV; deployed by 1 chart, among them penpot.
Radar Score
14,599927247821
1,106 findings on digest fa7086ad92b1 · scanned 20 Sept 2026
KEV ×4 confirmed exploitedRadar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
1,106 distinct on this digest
Findings for digest fa7086ad92b1 as scanned on 20 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 20 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-0964 | libssh | 0.9.6-2ubuntu0.22.04.6 |
| Low | UBUNTU-CVE-2023-30086 | tiff | 4.3.0-6ubuntu0.2 |
| Low | UBUNTU-CVE-2026-8674 | glibc | no fix listed |
| Low | UBUNTU-CVE-2026-59848 | libssh | 0.9.6-2ubuntu0.22.04.8 |
| Low | UBUNTU-CVE-2024-56378 | poppler | 22.02.0-2ubuntu0.6 |
| Low | UBUNTU-CVE-2026-5704 | tar | 1.34+dfsg-1ubuntu0.1.22.04.6 |
| Low | UBUNTU-CVE-2023-6004 | libssh | 0.9.6-2ubuntu0.22.04.3 |
| Low | UBUNTU-CVE-2026-25971 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2024-46955 | ghostscript | 9.55.0~dfsg1-0ubuntu5.10 |
| Low | UBUNTU-CVE-2026-86142 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2023-30775 | tiff | 4.3.0-6ubuntu0.2 |
| Low | UBUNTU-CVE-2026-53467 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-19542 | glibc | 2.35-0ubuntu3.15 |
| Low | UBUNTU-CVE-2024-28835 | gnutls28 | 3.7.3-4ubuntu1.5 |
| Low | UBUNTU-CVE-2023-24752 | libde265 | 1.0.8-1ubuntu0.2 |
| Low | UBUNTU-CVE-2023-24754 | libde265 | 1.0.8-1ubuntu0.2 |
| Low | UBUNTU-CVE-2023-24755 | libde265 | 1.0.8-1ubuntu0.2 |
| Low | UBUNTU-CVE-2023-24756 | libde265 | 1.0.8-1ubuntu0.2 |
| Low | UBUNTU-CVE-2023-24757 | libde265 | 1.0.8-1ubuntu0.2 |
| Low | UBUNTU-CVE-2023-24758 | libde265 | 1.0.8-1ubuntu0.2 |
| Low | UBUNTU-CVE-2026-45446 | openssl | 3.0.2-0ubuntu1.25 |
| Low | UBUNTU-CVE-2026-25638 | imagemagick | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm10 |
| Low | UBUNTU-CVE-2026-89161 | pcre2 | no fix listed |
| Low | UBUNTU-CVE-2026-44663 | openexr | no fix listed |
| Low | UBUNTU-CVE-2026-6019 | python3.10 | 3.10.12-1~22.04.16 |
| Low | UBUNTU-CVE-2025-6069 | python3.10 | 3.10.12-1~22.04.11 |
| Low | UBUNTU-CVE-2026-48994 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-53462 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-72522 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-22695 | libpng1.6 | 1.6.37-3ubuntu0.3 |
| Low | UBUNTU-CVE-2024-56827 | openjpeg2 | 2.4.0-6ubuntu0.3 |
| Low | UBUNTU-CVE-2026-56403 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56406 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56407 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-78410 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-68515 | openexr | no fix listed |
| Low | GHSA-f7q4-pwc6-w24p | elliptic | 6.5.7 |
| Low | UBUNTU-CVE-2025-4516 | python3.10 | 3.10.12-1~22.04.10 |
| Low | UBUNTU-CVE-2025-55005 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2025-64505 | libpng1.6 | 1.6.37-3ubuntu0.1 |
| Low | UBUNTU-CVE-2026-50593 | graphite2 | 1.3.14-1ubuntu0.1 |
| Low | UBUNTU-CVE-2026-56109 | alsa-lib | 1.2.6.1-1ubuntu1.2 |
| Low | UBUNTU-CVE-2026-42014 | gnutls28 | 3.7.3-4ubuntu1.9 |
| Low | UBUNTU-CVE-2026-40169 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-78409 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2024-13176 | openssl | 3.0.2-0ubuntu1.19 |
| Low | UBUNTU-CVE-2023-2004 | freetype | 2.11.1+dfsg-1ubuntu0.2 |
| Low | UBUNTU-CVE-2025-52099 | sqlite3 | 3.37.2-2ubuntu0.4 |
| Low | UBUNTU-CVE-2026-40312 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2023-39327 | openjpeg2 | 2.4.0-6ubuntu0.1 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| penpotcodechemVerified publisher | 1.0.10 | 1.16.0-beta | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.