StackRadar

penpotapp/mcp:2.18.3 container image

Docker Hub

Scanned 7 Oct 2026

Deployed by 1 of 18,035 indexed charts (latest versions) at this tag.Docker Hub all tags of penpotapp/mcp

penpotapp/mcp:2.18.3 resolved to 5e811e6eeb17, scanned 7 Oct 2026: 54 findings, 0 critical; deployed by 1 chart, among them penpot.

Radar Score

56500846

54 findings on digest 5e811e6eeb17 · scanned 7 Oct 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.18.3resolves to5e811e6eeb171 charttoday00846565

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

46 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 5e811e6eeb17 as scanned on 7 Oct 2026 with syft 1.42.1 for linux/amd64, advisories as of 7 Oct 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-jqcg-44mw-7w3hproxy-addr@2.0.72.0.8
LowDEBIAN-CVE-2026-6791glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-84782openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-5928glibc@2.41-12+deb13u3+dhi22.41-12+deb13u4
LowDEBIAN-CVE-2026-54873openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-84784openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-95619gcc-14@14.2.0-19+dhi3no fix listed
LowGHSA-58mr-gqgx-xq4gfast-uri@3.1.63.1.7
LowDEBIAN-CVE-2026-5435glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-19499glibc@2.41-12+deb13u3+dhi2no fix listed
LowGHSA-2vr4-cq9g-pvrcip-address@10.5.010.5.1
LowDEBIAN-CVE-2026-6238glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-72897openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowGHSA-qw65-cvwx-89v3fast-uri@3.1.63.1.7
LowGHSA-rpw4-54j3-4h4qip-address@10.5.010.5.1
LowGHSA-j6r3-76f7-8jcvip-address@10.5.010.7.1
LowDEBIAN-CVE-2026-102010gcc-14@14.2.0-19+dhi3no fix listed
LowDEBIAN-CVE-2026-77117glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-80489glibc@2.41-12+deb13u3+dhi2no fix listed
LowGHSA-h3mg-xc3c-68pwip-address@10.5.010.7.1
LowGHSA-wq5f-xc86-pv6wsharp@0.35.40.35.5
LowGHSA-4mjr-xmp4-gh2gqs@6.15.36.16.0
LowDEBIAN-CVE-2026-75806openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-75804openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-8674glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-42772openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowGHSA-6qxp-vccf-f47h@modelcontextprotocol/sdk@1.30.01.31.0
LowDEBIAN-CVE-2026-35189openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-19542glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-75805openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-27171zlib@1:1.3.dfsg+really1.3.1-1+dhi3no fix listed
LowDEBIAN-CVE-2026-86805glibc@2.41-12+deb13u3+dhi2no fix listed
LowGHSA-hrr3-gc8f-f4qjfast-uri@3.1.63.1.8
LowGHSA-x5fp-wj9c-mxmxqs@6.15.36.16.0
LowGHSA-jggr-w7fw-pc2jfast-copy@4.0.44.1.0
LowGHSA-hxh3-vqpv-xpqvhono@4.13.54.13.7
LowDEBIAN-CVE-2010-4756glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-89092glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-35191openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-18374glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-54875openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-97399glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-54872openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-77696openssl@3.5.7-1~deb13u2+dhi03.5.7-1~deb13u3
LowDEBIAN-CVE-2026-95818glibc@2.41-12+deb13u3+dhi2no fix listed
LowDEBIAN-CVE-2026-6368glibc@2.41-12+deb13u3+dhi2no fix listed

Used by

1 chart
ChartVersionTagContainers
penpotpenpotOfficialVerified publisher1.11.32.18.31

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 7 Oct 2026 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.