yandex/clickhouse-server:21.3.20 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of yandex/clickhouse-server
yandex/clickhouse-server:21.3.20 resolved to 4eccfffb01d7, scanned 14 Sept 2026: 277 findings, 6 critical; deployed by 1 chart, among them clickhouse.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
277 distinct on this digest
Findings for digest 4eccfffb01d7 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | UBUNTU-CVE-2022-3116 | heimdal | 7.7.0+dfsg-1ubuntu1.1 |
| Medium | UBUNTU-CVE-2026-42010 | gnutls28 | 3.6.13-2ubuntu1.12+esm2 |
| Medium | UBUNTU-CVE-2026-28388 | openssl | 1.1.1f-1ubuntu2.24+esm3 |
| Medium | UBUNTU-CVE-2025-69421 | openssl | 1.1.1f-1ubuntu2.24+esm2 |
| Medium | UBUNTU-CVE-2026-28387 | openssl | 1.1.1f-1ubuntu2.24+esm3 |
| Medium | UBUNTU-CVE-2025-32988 | gnutls28 | 3.6.13-2ubuntu1.12+esm1 |
| Medium | UBUNTU-CVE-2021-3999 | glibc | 2.31-0ubuntu9.7 |
| Medium | UBUNTU-CVE-2026-28389 | openssl | 1.1.1f-1ubuntu2.24+esm3 |
| Medium | UBUNTU-CVE-2026-28390 | openssl | 1.1.1f-1ubuntu2.24+esm3 |
| Medium | UBUNTU-CVE-2026-33845 | gnutls28 | 3.6.13-2ubuntu1.12+esm2 |
| Low | UBUNTU-CVE-2025-69420 | openssl | 1.1.1f-1ubuntu2.24+esm2 |
| Low | UBUNTU-CVE-2026-57433 | perl | 5.30.0-9ubuntu0.5+esm3 |
| Low | UBUNTU-CVE-2023-4806 | glibc | 2.31-0ubuntu9.14 |
| Low | UBUNTU-CVE-2026-13221 | perl | 5.30.0-9ubuntu0.5+esm3 |
| Low | UBUNTU-CVE-2026-42496 | perl | 5.30.0-9ubuntu0.5+esm2 |
| Low | UBUNTU-CVE-2026-9076 | openssl | 1.1.1f-1ubuntu2.24+esm4 |
| Low | UBUNTU-CVE-2024-10524 | wget | no fix listed |
| Low | UBUNTU-CVE-2022-3437 | heimdal | 7.7.0+dfsg-1ubuntu1.3 |
| Low | UBUNTU-CVE-2021-40528 | libgcrypt20 | 1.8.5-5ubuntu1.fips.1.1 |
| Low | UBUNTU-CVE-2026-12087 | perl | 5.30.0-9ubuntu0.5+esm3 |
| Low | UBUNTU-CVE-2023-47038 | perl | 5.30.0-9ubuntu0.5 |
| Low | UBUNTU-CVE-2026-0915 | glibc | 2.31-0ubuntu9.18+esm1 |
| Low | UBUNTU-CVE-2025-4802 | glibc | 2.31-0ubuntu9.18 |
| Low | UBUNTU-CVE-2023-50495 | ncurses | no fix listed |
| Low | UBUNTU-CVE-2023-5981 | gnutls28 | 3.6.13-2ubuntu1.9 |
| Low | UBUNTU-CVE-2026-63072 | openssl | 1.1.1f-1ubuntu2.24+esm5 |
| Low | UBUNTU-CVE-2021-31879 | wget | no fix listed |
| Low | UBUNTU-CVE-2024-33600 | glibc | 2.31-0ubuntu9.16 |
| Low | UBUNTU-CVE-2022-48303 | tar | 1.30+dfsg-7ubuntu0.20.04.3 |
| Low | UBUNTU-CVE-2023-0466 | openssl | 1.1.1f-1ubuntu2.18 |
| Low | UBUNTU-CVE-2024-41436 | clickhouse | no fix listed |
| Low | UBUNTU-CVE-2023-0465 | openssl | 1.1.1f-1ubuntu2.18 |
| Low | UBUNTU-CVE-2026-42013 | gnutls28 | 3.6.13-2ubuntu1.12+esm3 |
| Low | UBUNTU-CVE-2026-0861 | glibc | 2.31-0ubuntu9.18+esm1 |
| Low | UBUNTU-CVE-2024-2236 | libgcrypt20 | no fix listed |
| Low | UBUNTU-CVE-2025-69419 | openssl | 1.1.1f-1ubuntu2.24+esm2 |
| Low | UBUNTU-CVE-2022-23491 | ca-certificates | 20211016ubuntu0.20.04.1 |
| Low | UBUNTU-CVE-2026-54874 | openssl | 1.1.1f-1ubuntu2.24+esm5 |
| Low | UBUNTU-CVE-2026-42766 | openssl | 1.1.1f-1ubuntu2.24+esm4 |
| Low | UBUNTU-CVE-2025-32990 | gnutls28 | 3.6.13-2ubuntu1.12+esm1 |
| Low | UBUNTU-CVE-2025-6020 | pam | no fix listed |
| Low | UBUNTU-CVE-2023-7104 | sqlite3 | 3.31.1-4ubuntu0.6 |
| Low | UBUNTU-CVE-2022-45142 | heimdal | 7.7.0+dfsg-1ubuntu1.4 |
| Low | UBUNTU-CVE-2026-86145 | pcre2 | no fix listed |
| Low | UBUNTU-CVE-2023-47039 | perl | no fix listed |
| Low | UBUNTU-CVE-2025-15281 | glibc | 2.31-0ubuntu9.18+esm1 |
| Low | UBUNTU-CVE-2025-6297 | dpkg | no fix listed |
| Low | UBUNTU-CVE-2025-1385 | clickhouse | no fix listed |
| Low | UBUNTU-CVE-2022-44011 | clickhouse | no fix listed |
| Low | UBUNTU-CVE-2026-42011 | gnutls28 | 3.6.13-2ubuntu1.12+esm3 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| clickhousezloi-space | 1.2.0 | 21.3.20 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.