StackRadar

penpotapp/exporter:2.18.1 container image

Docker Hub

Scanned 2 Oct 2026

Deployed by 1 of 17,985 indexed charts (latest versions) at this tag.Docker Hub all tags of penpotapp/exporter

penpotapp/exporter:2.18.1 resolved to 3b6f9d808c77, scanned 2 Oct 2026: 341 findings, 0 critical; deployed by 1 chart, among them penpot.

Radar Score

3,6310058282

341 findings on digest 3b6f9d808c77 · scanned 2 Oct 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.18.1resolves to3b6f9d808c771 charttoday00582823,631

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

341 distinct on this digest

Findings for digest 3b6f9d808c77 as scanned on 2 Oct 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Oct 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2025-1365elfutils@0.192-4+dhi1no fix listed
LowDEBIAN-CVE-2023-39329openjpeg2@2.5.3-2.1~deb13u2+dhi2no fix listed
LowDEBIAN-CVE-2025-64181openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2023-37769pixman@0.44.0-3+dhi0no fix listed
LowDEBIAN-CVE-2026-53532openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2026-80230curl@8.14.1-2+deb13u5+dhi0no fix listed
LowDEBIAN-CVE-2026-5435glibc@2.41-12+deb13u4+dhi1no fix listed
LowDEBIAN-CVE-2017-15131xdg-user-dirs@0.18-2no fix listed
LowDEBIAN-CVE-2026-59189openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2026-59981openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2026-59982openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2026-59186openexr@3.1.13-2+dhi4no fix listed
LowGHSA-6j4f-fj2g-mc7pbrace-expansion@5.0.95.0.10
LowGHSA-qhr7-859c-m2p7brace-expansion@5.0.95.0.11
LowDEBIAN-CVE-2022-24106poppler@25.03.0-5+deb13u4no fix listed
LowDEBIAN-CVE-2026-88373libde265@1.0.15-1+deb13u2+dhi2no fix listed
LowDEBIAN-CVE-2026-59184openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2026-59187openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2026-34980cups@2.4.10-3+deb13u2+dhi4no fix listed
LowDEBIAN-CVE-2025-61915cups@2.4.10-3+deb13u2+dhi4no fix listed
LowDEBIAN-CVE-2025-8177tiff@4.7.0-3+deb13u3+dhi3no fix listed
LowDEBIAN-CVE-2026-19499glibc@2.41-12+deb13u4+dhi1no fix listed
LowDEBIAN-CVE-2018-1000021git@1:2.47.3-0+deb13u1+dhi2no fix listed
LowDEBIAN-CVE-2026-76642util-linux@2.41.5-0+deb13u1+dhi3no fix listed
LowDEBIAN-CVE-2021-45346sqlite3@3.46.1-7+deb13u2+dhi1no fix listed
LowDEBIAN-CVE-2025-8941pam@1.7.0-5+dhi1no fix listed
LowDEBIAN-CVE-2025-70873sqlite3@3.46.1-7+deb13u2+dhi1no fix listed
LowGHSA-2vr4-cq9g-pvrcip-address@10.3.110.5.1
LowDEBIAN-CVE-2026-68516openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2026-6238glibc@2.41-12+deb13u4+dhi1no fix listed
LowDEBIAN-CVE-2024-26458krb5@1.21.3-5+dhi2no fix listed
LowDEBIAN-CVE-2026-76956expat@2.8.3-1~deb13u1+dhi4no fix listed
LowDEBIAN-CVE-2025-8176tiff@4.7.0-3+deb13u3+dhi3no fix listed
LowDEBIAN-CVE-2026-34978cups@2.4.10-3+deb13u2+dhi4no fix listed
LowDEBIAN-CVE-2026-52491tiff@4.7.0-3+deb13u3+dhi3no fix listed
LowDEBIAN-CVE-2025-68471avahi@0.8-16+dhi3no fix listed
LowDEBIAN-CVE-2026-89157pcre2@10.46-1~deb13u1+dhi110.46-1~deb13u2
LowDEBIAN-CVE-2026-72897openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-11824sqlite3@3.46.1-7+deb13u1+dhi23.46.1-7+deb13u2
LowDEBIAN-CVE-2026-54371attr@1:2.5.2-3+dhi1no fix listed
LowDEBIAN-CVE-2025-68468avahi@0.8-16+dhi3no fix listed
LowDEBIAN-CVE-2026-27622openexr@3.1.13-2+dhi4no fix listed
LowDEBIAN-CVE-2026-0775npm@11.19.1-0no fix listed
LowDEBIAN-CVE-2025-61144tiff@4.7.0-3+deb13u3+dhi3no fix listed
LowDEBIAN-CVE-2026-8458curl@8.14.1-2+deb13u5+dhi0no fix listed
LowDEBIAN-CVE-2026-93543libxi@2:1.8.2-1+dhi0no fix listed
LowDEBIAN-CVE-2024-52616avahi@0.8-16+dhi3no fix listed
LowGHSA-rpw4-54j3-4h4qip-address@10.3.110.5.1
LowGHSA-j6r3-76f7-8jcvip-address@10.3.110.7.1
LowDEBIAN-CVE-2026-3184util-linux@2.41.5-0+deb13u1+dhi3no fix listed

Used by

1 chart
ChartVersionTagContainers
penpotpenpotOfficialVerified publisher1.11.12.18.11

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 2 Oct 2026 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.