tock/duckling:25.10.7 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of tock/duckling
tock/duckling:25.10.7 resolved to ac1f3f1a1e9c, scanned 14 Sept 2026: 85 findings, 0 critical; deployed by 1 chart, among them tock.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
85 distinct on this digest
Findings for digest ac1f3f1a1e9c as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | GHSA-jgxc-8mwq-9xqw | clojure | 1.9.0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | GHSA-w9fj-cfpg-grvv | netty-codec-http2 | 4.2.11.Final |
| Medium | GHSA-vr64-r9qj-h27f | clojure | 1.11.2 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | GHSA-3qp7-7mw8-wx86 | netty-handler | 4.2.15.Final |
| Medium | ALPINE-CVE-2026-42764 | openssl | 3.5.7-r0 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.21.4 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.21.4 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | GHSA-cm33-6792-r9fm | netty-codec-dns | 4.2.13.Final |
| Medium | GHSA-f6hv-jmp6-3vwv | netty-codec-http | 4.2.13.Final |
| Medium | GHSA-f6hv-jmp6-3vwv | netty-codec-http2 | 4.2.13.Final |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | GHSA-jppx-w49h-x2qq | netty-codec-http | 4.2.16.Final |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.5.6-r0 |
| Medium | GHSA-x4gw-5cx5-pgmh | netty-handler | 4.2.15.Final |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.5.6-r0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | GHSA-57rv-r2g8-2cj3 | netty-codec-http | 4.2.13.Final |
| Low | ALPINE-CVE-2026-9076 | openssl | 3.5.7-r0 |
| Low | GHSA-pwqr-wmgm-9rr8 | netty-codec-http | 4.2.10.Final |
| Low | GHSA-45q3-82m4-75jr | netty-handler-proxy | 4.2.13.Final |
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-45445 | openssl | 3.5.7-r0 |
| Low | GHSA-c4c3-7fpv-j4q5 | netty-handler | 4.2.17.Final |
| Low | ALPINE-CVE-2026-31789 | openssl | 3.5.6-r0 |
| Low | ALPINE-CVE-2026-54874 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-42766 | openssl | 3.5.7-r0 |
| Low | GHSA-5pvg-856g-cp85 | netty-resolver-dns | 4.2.15.Final |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-22184 | zlib | 1.3.2-r0 |
| Low | GHSA-mj4r-2hfc-f8p6 | netty-codec-compression | 4.2.13.Final |
| Low | GHSA-c653-97m9-rcg9 | netty-handler | 4.2.15.Final |
| Low | GHSA-93wv-jw9v-4972 | netty-codec-http2 | 4.2.16.Final |
| Low | GHSA-6jqx-86gh-f27w | netty-codec-http | 4.2.16.Final |
| Low | GHSA-mvh2-crg5-v77c | netty-codec-http | 4.2.16.Final |
| Low | GHSA-558v-64gr-wgg4 | netty-codec-compression | 4.2.16.Final |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | GHSA-676x-f7gg-47vc | netty-resolver-dns | 4.2.15.Final |
| Low | GHSA-xxqh-mfjm-7mv9 | netty-codec-http | 4.2.13.Final |
| Low | ALPINE-CVE-2026-2673 | openssl | 3.5.6-r0 |