rommapp/romm:4.4.1 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of rommapp/romm
rommapp/romm:4.4.1 resolved to b909e95d1aab, scanned 14 Sept 2026: 247 findings, 0 critical, 1 on KEV; deployed by 1 chart, among them romm.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
41 distinct on this digest
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest b909e95d1aab as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | ALPINE-CVE-2026-25243 | valkey | 8.1.7-r0 |
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-23631 | valkey | 8.1.7-r0 |
| Medium | GHSA-wp53-j4wj-2cfg | python-multipart | 0.0.22 |
| Medium | GHSA-38jv-5279-wg99 | urllib3 | 2.6.3 |
| Medium | ALPINE-CVE-2025-11187 | openssl | 3.5.5-r0 |
| Medium | ALPINE-CVE-2026-23479 | valkey | 8.1.7-r0 |
| Medium | ALPINE-CVE-2026-2005 | postgresql17 | 17.8-r0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-2004 | postgresql17 | 17.8-r0 |
| Medium | ALPINE-CVE-2026-2006 | postgresql17 | 17.8-r0 |
| Medium | ALPINE-CVE-2026-6473 | postgresql17 | 17.10-r0 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | PYSEC-2026-36 | cryptography | 46.0.7 |
| Medium | ALPINE-CVE-2025-58050 | pcre2 | 10.46-r0 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | PYSEC-2026-217 | mariadb | no fix listed |
| Medium | ALPINE-CVE-2026-25646 | libpng | 1.6.55-r0 |
| Medium | ALPINE-CVE-2026-42764 | openssl | 3.5.7-r0 |
| Medium | GHSA-2xpw-w6gg-jr37 | urllib3 | 2.6.0 |
| Medium | GHSA-gm62-xv2j-4w53 | urllib3 | 2.6.0 |
| Medium | ALPINE-CVE-2026-14669 | postgresql17 | 17.11-r0 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-33416 | libpng | 1.6.56-r0 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | GHSA-wvwj-cvrp-7pv5 | authlib | 1.6.9 |
| Medium | GHSA-2h4p-vjrc-8xpq | mako | 1.3.12 |
| Medium | PYSEC-2026-2118 | authlib | 1.6.7 |
| Medium | ALPINE-CVE-2026-66046 | expat | 2.8.4-r0 |
| Medium | GHSA-7gcm-g887-7qv7 | protobuf | 6.33.5 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.5.5-r0 |
| Medium | ALPINE-CVE-2026-16239 | postgresql17 | 17.11-r0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.5.6-r0 |
| Medium | GHSA-63hf-3vf5-4wqf | aiohttp | 3.13.4 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.5.6-r0 |