ghcr.io/gla-rad/enav-aton-service:latest container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/gla-rad/enav-aton-service
ghcr.io/gla-rad/enav-aton-service:latest resolved to 3be878690629, scanned 14 Sept 2026: 157 findings, 1 critical; deployed by 1 chart, among them enav.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
157 distinct on this digest
Findings for digest 3be878690629 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-8c42-7qj2-3j46 | netty-codec-http | 4.2.17.Final |
| Low | GHSA-9fxm-vc8v-hj55 | jackson-databind | 2.21.4 |
| Low | GHSA-r7wm-3cxj-wff9 | jackson-core | 3.1.4 |
| Low | GHSA-4mp9-239f-g9hg | netty-codec-http | 4.2.16.Final |
| Low | GHSA-5vpf-xvv7-c8vh | spring-data-commons | 4.0.6 |
| Low | GHSA-cmm3-54f8-px4j | netty-codec-classes-quic | 4.2.15.Final |
| Low | ALPINE-CVE-2026-42769 | openssl | 3.5.7-r0 |
| Low | GHSA-3chg-m5w7-qfv5 | spring-webmvc | 7.0.8 |
| Low | GHSA-5hh8-q8hv-fr38 | jackson-databind | 2.21.4 |
| Low | GHSA-83f7-v6px-pp3h | spring-webflux | 7.0.8 |
| Low | GHSA-hgj6-7826-r7m5 | jackson-databind | 2.21.4 |
| Low | GHSA-wxpp-56q6-5pcg | spring-expression | 7.0.8 |
| Low | GHSA-5jmj-h7xm-6q6v | jackson-databind | 2.21.5 |
| Low | ALPINE-CVE-2026-76957 | expat | 2.8.4-r0 |
| Low | GHSA-mfg7-5gfp-c4w3 | netty-codec-dns | 4.2.16.Final |
| Low | GHSA-x2r2-rvhq-2mqv | spring-security-web | 7.0.6 |
| Low | ALPINE-CVE-2026-56403 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-56404 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-56405 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-56408 | expat | 2.8.2-r0 |
| Low | GHSA-gcjf-9mgh-3p7g | netty-codec-http | 4.2.16.Final |
| Low | GHSA-v8h7-rr48-vmmv | netty-codec-http | 4.2.13.Final |
| Low | ALPINE-CVE-2026-56406 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-56407 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-56410 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-56411 | expat | 2.8.2-r0 |
| Low | GHSA-563q-j3cm-6jxm | netty-codec-http2 | 4.2.15.Final |
| Low | GHSA-5x3r-wrvg-rp6q | netty-codec-http2 | 4.2.15.Final |
| Low | ALPINE-CVE-2026-45446 | openssl | 3.5.7-r0 |
| Low | GHSA-7g45-4rm6-3mm3 | guava | 32.0.0-android |
| Low | ALPINE-CVE-2026-56412 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-50219 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-56409 | expat | 2.8.2-r0 |
| Low | GHSA-5mg8-w23w-74h3 | guava | 32.0.0-android |
| Low | GHSA-hvcg-qmg6-jm4c | netty-codec-http | 4.2.15.Final |
| Low | ALPINE-CVE-2026-56132 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-40930 | libpng | 1.6.58-r1 |
| Low | GHSA-957g-f97v-vppc | spring-webmvc | 7.0.8 |
| Low | ALPINE-CVE-2026-42768 | openssl | 3.5.7-r0 |
| Low | GHSA-cjpg-rgq5-fr37 | spring-webmvc | 7.0.8 |
| Low | GHSA-cjpg-rgq5-fr37 | spring-webflux | 7.0.8 |
| Low | GHSA-mhm7-754m-9p8w | jackson-databind | 2.21.5 |
| Low | ALPINE-CVE-2026-42770 | openssl | 3.5.7-r0 |
| Low | GHSA-cq4q-cv5g-r8q5 | netty-codec-classes-quic | 4.2.15.Final |
| Low | ALPINE-CVE-2026-56131 | expat | 2.8.2-r0 |
| Low | GHSA-q723-847q-5g8g | spring-websocket | 7.0.8 |
| Low | GHSA-9m89-8frq-c98c | tomcat-embed-core | 11.0.22 |
| Low | GHSA-659m-px2c-25wj | spring-core | 7.0.8 |
| Low | GHSA-4hfh-6x8g-gwpp | spring-webflux | 7.0.8 |
| Low | GHSA-ggg2-9786-hwc8 | spring-boot-autoconfigure | 4.0.7 |