StackRadar

penpotapp/mcp:2.18.1 container image

Docker Hub

Scanned 2 Oct 2026

Deployed by 1 of 17,985 indexed charts (latest versions) at this tag.Docker Hub all tags of penpotapp/mcp

penpotapp/mcp:2.18.1 resolved to 710505af665d, scanned 2 Oct 2026: 49 findings, 0 critical; deployed by 1 chart, among them penpot.

Radar Score

51700841

49 findings on digest 710505af665d · scanned 2 Oct 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.18.1resolves to710505af665d1 charttoday00841517

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

41 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 710505af665d as scanned on 2 Oct 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Oct 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-6791glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-84782openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-5928glibc@2.41-12+deb13u3+dhi22.41-12+deb13u4
LowDEBIAN-CVE-2026-54873openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-84784openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowGHSA-58mr-gqgx-xq4gfast-uri@3.1.63.1.7
LowDEBIAN-CVE-2026-5435glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-19499glibc@2.41-12+deb13u3+dhi2no fix listed
LowGHSA-2vr4-cq9g-pvrcip-address@10.5.010.5.1
LowDEBIAN-CVE-2026-6238glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-72897openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowGHSA-qw65-cvwx-89v3fast-uri@3.1.63.1.7
LowGHSA-rpw4-54j3-4h4qip-address@10.5.010.5.1
LowGHSA-j6r3-76f7-8jcvip-address@10.5.010.7.1
LowDEBIAN-CVE-2026-77117glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-80489glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-102010gcc-14@14.2.0-19+dhi3no fix listed
LowGHSA-h3mg-xc3c-68pwip-address@10.5.010.7.1
LowGHSA-4mjr-xmp4-gh2gqs@6.15.36.16.0
LowDEBIAN-CVE-2026-75806openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-75804openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-8674glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-42772openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-35189openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-19542glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-75805openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-27171zlib@1:1.3.dfsg+really1.3.1-1+dhi3no fix listed
LowDEBIAN-CVE-2026-86805glibc@2.41-12+deb13u3+dhi2no fix listed
LowGHSA-hrr3-gc8f-f4qjfast-uri@3.1.63.1.8
LowGHSA-x5fp-wj9c-mxmxqs@6.15.36.16.0
LowGHSA-hxh3-vqpv-xpqvhono@4.13.54.13.7
LowDEBIAN-CVE-2010-4756glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-89092glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-35191openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-18374glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-54875openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-97399glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-54872openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-77696openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-95818glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-6368glibc@2.41-12+deb13u3+dhi2no fix listed

Used by

1 chart
ChartVersionTagContainers
penpotpenpotOfficialVerified publisher1.11.12.18.11

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 2 Oct 2026 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.