StackRadar

yuzutech/kroki-mermaid:0.29.1 container image

Docker Hub

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of yuzutech/kroki-mermaid

yuzutech/kroki-mermaid:0.29.1 resolved to 963b4acfde6e, scanned 14 Sept 2026: 138 findings, 0 critical; deployed by 1 chart, among them kroki.

Radar Score

1,6250227109

138 findings on digest 963b4acfde6e · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
0.29.1resolves to963b4acfde6e1 chart9 days ago02271091,625

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

138 distinct on this digest

Findings for digest 963b4acfde6e as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2026-56404expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56405expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56408expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56406expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56407expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56410expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56411expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-42014gnutls@3.8.8-r03.8.13-r0
LowALPINE-CVE-2026-39316cups@2.4.11-r02.4.18-r0
LowGHSA-5p4m-2wfm-xmqjjs-yaml@4.1.14.3.1
LowGHSA-jfc7-64v2-mr8c@sigstore/core@2.0.03.2.1
LowALPINE-CVE-2026-56412expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2025-58436cups@2.4.11-r02.4.16-r0
LowALPINE-CVE-2026-3832gnutls@3.8.8-r03.8.13-r0
LowALPINE-CVE-2026-50219expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-25834mbedtls@3.6.5-r03.6.6-r0
LowALPINE-CVE-2026-56409expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-39314cups@2.4.11-r02.4.18-r0
LowALPINE-CVE-2026-27171zlib@1.3.1-r21.3.2-r0
LowALPINE-CVE-2026-34990cups@2.4.11-r02.4.18-r0
LowALPINE-CVE-2026-32777expat@2.7.3-r02.7.5-r0
LowALPINE-CVE-2026-56132expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-32778expat@2.7.3-r02.7.5-r0
LowALPINE-CVE-2026-32776expat@2.7.3-r02.7.5-r0
LowALPINE-CVE-2026-6042musl@1.2.5-r91.2.5-r10
LowGHSA-w9m9-85wc-3x92postcss-selector-parser@7.1.07.1.3
LowALPINE-CVE-2026-22795openssl@3.3.5-r03.3.6-r0
LowALPINE-CVE-2026-56131expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-5419gnutls@3.8.8-r03.8.13-r0
LowALPINE-CVE-2025-69277libsodium@1.0.20-r01.0.20-r1
LowALPINE-CVE-2026-34757libpng@1.6.53-r01.6.57-r0
LowALPINE-CVE-2025-68160openssl@3.3.5-r03.3.6-r0
LowALPINE-CVE-2025-9820gnutls@3.8.8-r03.8.12-r0
LowALPINE-CVE-2026-41080expat@2.7.3-r02.8.1-r0
LowALPINE-CVE-2025-69418openssl@3.3.5-r03.3.6-r0
LowALPINE-CVE-2025-46394busybox@1.37.0-r131.37.0-r14
LowALPINE-CVE-2026-24515expat@2.7.3-r02.7.4-r0
LowALPINE-CVE-2024-58251busybox@1.37.0-r131.37.0-r14

Used by

1 chart
ChartVersionTagContainers
krokicowboysysopVerified publisher6.1.00.29.11

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.