ghcr.io/akash-network/console-api:2.64.0 container image
GitHub Container RegistryScanned 23 Sept 2026
Deployed by 1 of 17,832 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/akash-network/console-api
ghcr.io/akash-network/console-api:2.64.0 resolved to ba359097329d, scanned 23 Sept 2026: 330 findings, 1 critical; deployed by 1 chart, among them console-api.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
330 distinct on this digest
Findings for digest ba359097329d as scanned on 23 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 23 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2026-42945 | nginx | 1.26.3-r1 |
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| High | ALPINE-CVE-2026-49975 | nginx | 1.26.3-r1 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| High | ALPINE-CVE-2026-9256 | nginx | 1.26.3-r1 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-42055 | nginx | 1.26.3-r2 |
| Medium | ALPINE-CVE-2026-42533 | nginx | 1.26.3-r2 |
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.3.7-r1 |
| Medium | GHSA-v778-237x-gjrc | golang.org/ | 0.31.0 |
| Medium | GHSA-2w6w-674q-4c4q | handlebars | 4.7.9 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 4.0.4 |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | GHSA-43fc-jf86-j433 | axios | 0.30.3 |
| Medium | GHSA-pq67-2wwv-3xjx | tar-fs | 2.1.2 |
| Medium | GHSA-mxhp-79qh-mcx6 | taffydb | no fix listed |
| Medium | GHSA-xq3m-2v4x-88gg | protobufjs | 7.5.5 |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.3.5-r0 |
| Medium | GHSA-rf6f-7fwh-wjgh | flatted | 3.4.2 |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.3.5-r0 |
| Medium | GHSA-x9vf-53q3-cvx6 | @casl/ | 6.7.5 |
| Medium | GHSA-pjwm-pj3p-43mv | axios | 0.32.0 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.3.7-r1 |
| Medium | GHSA-5rq4-664w-9x2c | basic-ftp | 5.2.0 |
| Medium | GHSA-jr5f-v2jv-69x6 | axios | 0.30.0 |
| Medium | GHSA-95m3-7q98-8xr5 | sha.js | 2.4.12 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-4hjh-wcwx-xvwj | axios | 1.12.0 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.3.7-r1 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2025-23419 | nginx | 1.26.3-r0 |
| Medium | GHSA-4f99-4q7p-p3gh | github.com/ | 1.9.1 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.3.5-r0 |
| Medium | GHSA-hcg3-q754-cr77 | golang.org/ | 0.35.0 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-60005 | nginx | 1.26.3-r2 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 0.32.0 |
| Medium | GHSA-8cj5-5rvv-wf4v | tar-fs | 2.1.3 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | ALPINE-CVE-2026-42946 | nginx | 1.26.3-r1 |
| Medium | GHSA-3mfm-83xf-c92r | handlebars | 4.7.9 |
| Medium | GHSA-xhpv-hc6g-r9c6 | handlebars | 4.7.9 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.3.7-r0 |
| Medium | GHSA-99f4-grh7-6pcq | @grpc/ | 1.10.12 |
| Medium | GHSA-v8fg-2rw7-q452 | sequelize | 6.37.4 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| console-apiovrclk-2 | 0.1.1 | 2.64.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.