ghcr.io/advplyr/audiobookshelf:2.0.3 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/advplyr/audiobookshelf
ghcr.io/advplyr/audiobookshelf:2.0.3 resolved to 140aed2752c3, scanned 14 Sept 2026: 119 findings, 1 critical, 1 on KEV; deployed by 1 chart, among them audiobookshelf.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
119 distinct on this digest
Findings for digest 140aed2752c3 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2023-4863KEV | libwebp | 1.2.2-r2 |
| High | ALPINE-CVE-2023-0286 | openssl | 1.1.1t-r0 |
| High | ALPINE-CVE-2023-2650 | openssl | 1.1.1u-r0 |
| High | ALPINE-CVE-2022-37434 | zlib | 1.2.12-r2 |
| High | ALPINE-CVE-2022-4450 | openssl | 1.1.1t-r0 |
| Medium | GHSA-2p57-rm9w-gvfp | ip | no fix listed |
| Medium | ALPINE-CVE-2022-4304 | openssl | 1.1.1t-r0 |
| Medium | ALPINE-CVE-2022-27404 | freetype | 2.11.1-r1 |
| Medium | GHSA-wc69-rhjr-hc9g | moment | 2.29.4 |
| Medium | ALPINE-CVE-2023-0215 | openssl | 1.1.1t-r0 |
| Medium | ALPINE-CVE-2021-46848 | libtasn1 | 4.18.0-r1 |
| Medium | GHSA-hj9c-8jmm-8c52 | npm | 8.11.0 |
| Medium | ALPINE-CVE-2023-0464 | openssl | 1.1.1t-r2 |
| Medium | GHSA-93q8-gq69-wqmw | ansi-regex | 3.0.1 |
| Medium | GHSA-wm7h-9275-46v2 | dicer | no fix listed |
| Medium | ALPINE-CVE-2022-27406 | freetype | 2.11.1-r2 |
| Medium | ALPINE-CVE-2021-27219 | glib | 2.66.6-r0 |
| Medium | ALPINE-CVE-2022-27405 | freetype | 2.11.1-r2 |
| Medium | ALPINE-CVE-2022-40674 | expat | 2.4.9-r0 |
| Medium | GHSA-c2qf-rxjj-qqgw | semver | 7.5.2 |
| Medium | GHSA-43fc-jf86-j433 | axios | 0.30.3 |
| Medium | GHSA-qm95-pgcg-qqfq | socket.io-parser | 4.0.5 |
| Medium | GHSA-29mw-wpgm-hmr9 | lodash.trim | no fix listed |
| Medium | ALPINE-CVE-2022-43680 | expat | 2.5.0-r0 |
| Medium | ALPINE-CVE-2023-3446 | openssl | 1.1.1u-r2 |
| Medium | ALPINE-CVE-2022-2509 | gnutls | 3.7.1-r1 |
| Medium | GHSA-f8q6-p94x-37v3 | minimatch | 3.0.5 |
| Medium | ALPINE-CVE-2023-3138 | libx11 | 1.7.3.1-r1 |
| Medium | ALPINE-CVE-2022-2097 | openssl | 1.1.1q-r0 |
| Medium | GHSA-rc47-6667-2j5j | http-cache-semantics | 4.1.1 |
| Medium | ALPINE-CVE-2023-5678 | openssl | 1.1.1w-r1 |
| Medium | GHSA-w4m6-x6c2-j5c9 | express-fileupload | no fix listed |
| Medium | ALPINE-CVE-2023-0361 | gnutls | 3.7.1-r2 |
| Medium | GHSA-3h5v-q93c-6h6q | ws | 8.17.1 |
| Medium | GHSA-pjwm-pj3p-43mv | axios | 0.32.0 |
| Medium | GHSA-r7qp-cfhv-p84w | engine.io | 6.2.1 |
| Medium | GHSA-jr5f-v2jv-69x6 | axios | 0.30.0 |
| Medium | ALPINE-CVE-2022-29458 | ncurses | 6.3_p20211120-r1 |
| Medium | ALPINE-CVE-2023-29491 | ncurses | 6.3_p20211120-r2 |
| Medium | GHSA-cqmj-92xf-r6r9 | socket.io-parser | 4.2.3 |
| Medium | ALPINE-CVE-2023-1999 | libwebp | 1.2.2-r1 |
| Medium | GHSA-37ch-88jc-xwx2 | path-to-regexp | 0.1.13 |
| Medium | GHSA-9wv6-86v2-598j | path-to-regexp | 0.1.10 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 0.32.0 |
| Medium | GHSA-q9mw-68c2-j6m5 | engine.io | 6.4.2 |
| Medium | GHSA-pfrx-2q88-qq97 | got | 11.8.5 |
| Medium | GHSA-qwcr-r2fm-qrc7 | body-parser | 1.20.3 |
| Medium | GHSA-96hv-2xvq-fx4p | ws | 8.21.0 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 3.1.3 |
| Medium | GHSA-pf86-5x62-jrwf | axios | 0.31.1 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| audiobookshelfgeek-cookbookVerified publisher | 1.2.2 | 2.0.3 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.