StackRadar

xetusoss/archiva:v2.2.5 container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of xetusoss/archiva

xetusoss/archiva:v2.2.5 resolved to 88f25242b9ee, scanned 14 Sept 2026: 232 findings, 12 critical, 4 on KEV; deployed by 1 chart, among them archiva.

Radar Score

6,907123713845

232 findings on digest 88f25242b9ee · scanned 14 Sept 2026

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v2.2.5resolves to88f25242b9ee1 chart6 days ago1237138456,907

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

232 distinct on this digest

Findings for digest 88f25242b9ee as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
CriticalGHSA-jfh8-c2jp-5v3qKEVlog4j-core@2.8.22.12.2
CriticalGHSA-36p3-wjmg-h94xKEVspring-beans@4.2.1.RELEASE5.2.20.RELEASE
CriticalALPINE-CVE-2020-15999KEVfreetype@2.9.1-r22.9.1-r3
CriticalGHSA-fjq5-5j5f-mvxhcommons-collections@3.2.13.2.2
CriticalGHSA-7rjr-3q55-vv33KEVlog4j-core@2.8.22.12.2
CriticalGHSA-p6xc-xr62-6r2glog4j-core@2.8.22.12.3
CriticalGHSA-mjmj-j48q-9wg2snakeyaml@1.112.0
CriticalGHSA-rfx6-vp9g-rh7vjackson-databind@2.3.02.7.9.2
CriticalALPINE-CVE-2019-8457sqlite@3.26.0-r33.28.0-r0
CriticalGHSA-p66x-2cv9-qq3vcommons-beanutils@1.8.31.9.4
CriticalGHSA-8ffc-79xg-29w8cassandra-all@2.0.93.0.26
CriticalGHSA-qxxx-2pp7-5hmxjackson-databind@2.3.02.6.7.1
HighGHSA-9339-86wc-4qgfxalan@2.7.12.7.3
HighGHSA-ghgj-3xqr-6jfmjetty-server@8.1.7.v201209109.2.9.v20150224
HighGHSA-4wrc-f8pq-fpqpspring-web@4.2.1.RELEASE6.0.0
HighGHSA-8489-44mv-ggj8log4j-core@2.8.22.12.4
HighGHSA-4w82-r329-3q67jackson-databind@2.3.02.6.7.4
HighGHSA-26vr-8j45-3r4wjetty-server@8.1.7.v201209109.4.39
HighALPINE-CVE-2021-23840openssl@1.1.1b-r11.1.1j-r0
HighGHSA-cggj-fvv3-cqwvjackson-databind@2.3.02.6.7.5
HighGHSA-6x9x-8qw9-9pp6jetty-server@8.1.7.v201209109.2.25.v20180606
HighGHSA-q93h-jc49-78ggjackson-databind@2.3.02.7.9.7
HighGHSA-p43x-xfjf-5jhrjackson-databind@2.3.02.7.9.7
HighGHSA-59j4-wjwp-mw9mvelocity@1.7no fix listed
HighGHSA-9qcf-c26r-x5rfquartz@2.2.12.3.2
HighGHSA-vgg8-72f2-qm23jetty-server@8.1.7.v201209109.2.25.v20180606
HighGHSA-w77p-8cfg-2x43slf4j-ext@1.7.251.7.26
HighALPINE-CVE-2021-3449openssl@1.1.1b-r11.1.1k-r0
HighGHSA-645p-88qh-w398jackson-databind@2.3.02.6.7.3
HighGHSA-6phf-73q6-gh87commons-beanutils@1.8.31.9.4
HighGHSA-rvwf-54qp-4r6vsnakeyaml@1.111.26
HighGHSA-9gph-22xh-8x98jackson-databind@2.3.02.6.7.5
HighGHSA-h822-r4r5-v8jgjackson-databind@2.3.02.6.7.3
HighGHSA-c8hm-7hpq-7jhgjackson-databind@2.3.02.6.7.3
HighGHSA-558x-2xjg-6232spring-expression@4.2.1.RELEASE5.2.20.RELEASE
HighGHSA-mph4-vhrx-mv67jackson-databind@2.3.02.6.7.3
HighGHSA-5ww9-j83m-q7qxjackson-databind@2.3.02.6.7.3
HighGHSA-4gq5-ch57-c2mgjackson-databind@2.3.02.7.9.5
HighGHSA-2363-cqg2-863cjdom@1.0no fix listed
HighGHSA-gww7-p5w4-wrfvjackson-databind@2.3.02.6.7.4
HighGHSA-h592-38cm-4ggpjackson-databind@2.3.02.6.7.3
HighGHSA-6fpp-rgj9-8rwcjackson-databind@2.3.02.7.9.6
HighGHSA-6hgm-866r-3cjvcommons-collections@3.2.13.2.2
HighGHSA-j8g6-2wh7-6439tika-core@1.31.14
HighALPINE-CVE-2019-12900bzip2@1.0.6-r61.0.6-r7
HighGHSA-g8hw-794c-4j9gspring-core@4.2.1.RELEASE4.3.15
HighGHSA-hwj3-m3p6-hj38dom4j@1.6.12.0.3
HighGHSA-cqqj-4p63-rrmmnetty@3.6.6.Finalno fix listed
HighGHSA-5r5r-6hpj-8gg9jackson-databind@2.3.02.9.10.8
MediumGHSA-8vhq-qq4p-grq3plexus-utils@3.0.153.0.16

Used by

1 chart
ChartVersionTagContainers
archivaslamdev0.0.7v2.2.51

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.