StackRadar

ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 2 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/celestiaorg/celestia-node

ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha resolved to 4768ea1c5fd2, scanned 14 Sept 2026: 150 findings, 0 critical; deployed by 2 charts, among them celestia-local and celestia-node.

Radar Score

1,5020218130

150 findings on digest 4768ea1c5fd2 · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v0.27.5-mocharesolves to4768ea1c5fd22 charts7 days ago02181301,502

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

150 distinct on this digest

Findings for digest 4768ea1c5fd2 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2025-4947curl@8.12.1-r08.14.0-r0
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.75.11.83.1
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.41.00.52.0
LowALPINE-CVE-2026-22796openssl@3.3.1-r33.3.6-r0
LowGHSA-f6x5-jh6r-wrfvgolang.org/x/crypto@v0.41.00.45.0
LowGHSA-78mq-xcr3-xm33golang.org/x/crypto@v0.41.00.52.0
LowALPINE-CVE-2025-10148curl@8.12.1-r08.14.1-r2
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.75.11.82.1
LowGHSA-g6x7-jq8p-6q9qgithub.com/quic-go/webtransport-go@v0.9.00.10.0
LowGHSA-px4r-g4p3-hhqvgithub.com/quic-go/webtransport-go@v0.9.00.10.0
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.7.11.7.8
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/service/s3@v1.88.11.97.3
LowGHSA-9m57-25v3-79x9golang.org/x/crypto@v0.41.00.52.0
LowGHSA-jc7w-c686-c4v9github.com/ulikunitz/xz@v0.5.140.5.15
LowGHSA-vvgj-x9jq-8cj9github.com/quic-go/quic-go@v0.54.00.59.1
LowGHSA-2f2x-8mwp-p2gcgithub.com/quic-go/webtransport-go@v0.9.00.10.0
LowGHSA-9h8m-3fm2-qjrqgo.opentelemetry.io/otel/sdk@v1.37.01.40.0
LowGHSA-34rh-wp3j-6cxcgithub.com/pion/stun@v0.6.1no fix listed
LowGHSA-34rh-wp3j-6cxcgithub.com/pion/stun/v3@v3.0.03.1.5
LowGHSA-g754-hx8w-x2g6github.com/quic-go/quic-go@v0.54.00.57.0
LowGO-2026-4981stdlib@go1.24.71.25.10
LowGO-2026-4977stdlib@go1.24.71.25.10
LowGO-2026-4986stdlib@go1.24.71.25.10
LowGO-2026-4918stdlib@go1.24.71.25.10
LowGO-2026-4918golang.org/x/net@v0.43.00.53.0
LowGO-2026-4337stdlib@go1.24.71.24.13
LowGO-2026-4601stdlib@go1.24.71.25.8
LowGO-2026-5026stdlib@go1.24.71.25.13
LowGO-2026-5026golang.org/x/net@v0.43.00.55.0
LowGO-2026-4342stdlib@go1.24.71.24.12
LowALPINE-CVE-2024-13176openssl@3.3.1-r33.3.2-r2
LowGHSA-2v4p-qf9q-27wjgoogle.golang.org/grpc@v1.75.11.82.2
LowGO-2025-4116golang.org/x/crypto@v0.41.00.43.0
LowGO-2026-4870stdlib@go1.24.71.25.9
LowGO-2025-4009stdlib@go1.24.71.24.8
LowGO-2026-4947stdlib@go1.24.71.25.9
LowGO-2025-4006stdlib@go1.24.71.24.8
LowGO-2026-5037stdlib@go1.24.71.25.11
LowGO-2026-4971stdlib@go1.24.71.25.10
LowGHSA-378j-3jfj-8r9fgithub.com/ipld/go-ipld-prime@v0.21.00.22.0
LowGO-2026-5972stdlib@go1.24.71.25.13
LowGO-2026-6088stdlib@go1.24.71.25.13
LowGO-2026-6089stdlib@go1.24.71.25.13
LowGO-2026-6090stdlib@go1.24.71.25.13
LowALPINE-CVE-2026-27171zlib@1.3.1-r11.3.2-r0
LowGO-2026-5038stdlib@go1.24.71.25.11
LowGO-2026-5942golang.org/x/net@v0.43.00.56.0
LowGO-2025-4012stdlib@go1.24.71.24.8
LowGO-2026-4440golang.org/x/net@v0.43.00.45.0
LowGO-2025-4011stdlib@go1.24.71.24.8

Used by

2 charts

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.