gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5 container image
Google Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.all tags of gcr.io/ml-pipeline/metadata-envoy
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5 resolved to e8bc6cf08613, scanned 14 Sept 2026: 344 findings, 3 critical; deployed by 1 chart, among them kubeflow.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest e8bc6cf08613 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-22796 | openssl | 1.0.2g-1ubuntu4.20+esm14 |
| Low | UBUNTU-CVE-2016-10739 | glibc | no fix listed |
| Low | UBUNTU-CVE-2020-27350 | apt | 1.2.32ubuntu0.2 |
| Low | UBUNTU-CVE-2025-68973 | gnupg | 1.4.20-1ubuntu3.3+esm3 |
| Low | UBUNTU-CVE-2026-11979 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2022-3821 | systemd | 229-4ubuntu21.31+esm3 |
| Low | UBUNTU-CVE-2026-86140 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2023-39804 | tar | 1.28-2.1ubuntu0.2+esm3 |
| Low | UBUNTU-CVE-2026-34743 | xz-utils | 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2 |
| Low | UBUNTU-CVE-2026-54411 | pam | no fix listed |
| Low | UBUNTU-CVE-2025-32414 | libxml2 | 2.9.3+dfsg1-1ubuntu0.7+esm8 |
| Low | UBUNTU-CVE-2023-32665 | glib2.0 | 2.48.2-0ubuntu4.8+esm3 |
| Low | UBUNTU-CVE-2023-32611 | glib2.0 | 2.48.2-0ubuntu4.8+esm3 |
| Low | UBUNTU-CVE-2026-19487 | perl | 5.22.1-9ubuntu0.9+esm4 |
| Low | UBUNTU-CVE-2026-4878 | libcap2 | 1:2.24-12ubuntu0.1~esm2 |
| Low | UBUNTU-CVE-2016-1585 | apparmor | no fix listed |
| Low | UBUNTU-CVE-2025-4373 | glib2.0 | no fix listed |
| Low | UBUNTU-CVE-2026-78408 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-54369 | acl | no fix listed |
| Low | UBUNTU-CVE-2026-41989 | libgcrypt20 | no fix listed |
| Low | UBUNTU-CVE-2018-20482 | tar | 1.28-2.1ubuntu0.2 |
| Low | UBUNTU-CVE-2026-13595 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-54371 | attr | 1:2.4.47-2ubuntu0.16.04.1~esm1 |
| Low | UBUNTU-CVE-2026-1489 | glib2.0 | no fix listed |
| Low | UBUNTU-CVE-2026-5704 | tar | 1.28-2.1ubuntu0.2+esm6 |
| Low | UBUNTU-CVE-2026-78410 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2016-5011 | util-linux | 2.27.1-6ubuntu3.10+esm2 |
| Low | UBUNTU-CVE-2025-14104 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-86142 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-78409 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2024-13176 | openssl | no fix listed |
| Low | UBUNTU-CVE-2026-86138 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2021-20193 | tar | 1.28-2.1ubuntu0.2+esm1 |
| Low | UBUNTU-CVE-2026-86143 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2025-9714 | libxml2 | 2.9.3+dfsg1-1ubuntu0.7+esm10 |
| Low | UBUNTU-CVE-2025-1390 | libcap2 | no fix listed |
| Low | UBUNTU-CVE-2017-18018 | coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-86139 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-15588 | glib2.0 | no fix listed |
| Low | UBUNTU-CVE-2025-8058 | glibc | 2.23-0ubuntu11.3+esm9 |
| Low | UBUNTU-CVE-2013-4235 | shadow | 1:4.2-3.1ubuntu5.5+esm3 |
| Low | UBUNTU-CVE-2025-45582 | tar | no fix listed |
| Low | UBUNTU-CVE-2026-15534 | perl | 5.22.1-9ubuntu0.9+esm4 |
| Low | UBUNTU-CVE-2018-16888 | systemd | 229-4ubuntu21.27 |
| Low | USN-8467-1 | perl | 5.22.1-9ubuntu0.9+esm2 |
| Low | UBUNTU-CVE-2017-11671 | gccgo-6 | 6.0.1-0ubuntu1+esm1 |
| Low | UBUNTU-CVE-2017-11671 | gcc-5 | 5.4.0-6ubuntu1~16.04.12+esm2 |
| Low | UBUNTU-CVE-2026-86144 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2024-10041 | pam | no fix listed |
| Low | UBUNTU-CVE-2023-4641 | shadow | 1:4.2-3.1ubuntu5.5+esm4 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| kubeflowkubeflow | 1.6.2 | 2.0.0-alpha.5 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.