StackRadar

ghcr.io/immich-app/immich-machine-learning:v2.3.1 container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/immich-app/immich-machine-learning

ghcr.io/immich-app/immich-machine-learning:v2.3.1 resolved to 379e31b8c751, scanned 14 Sept 2026: 341 findings, 0 critical, 1 on KEV; deployed by 1 chart, among them immich.

Radar Score

3,7010258281

341 findings on digest 379e31b8c751 · scanned 14 Sept 2026

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v2.3.1resolves to379e31b8c7511 chart8 days ago02582813,701

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

341 distinct on this digest

Findings for digest 379e31b8c751 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGHSA-hx9q-6w63-j58vorjson@3.11.33.11.6
MediumGHSA-3r9x-f23j-gc73onnx@1.16.01.21.0
MediumDEBIAN-CVE-2026-66046expat@2.5.0-1+deb12u2no fix listed
MediumGHSA-7gcm-g887-7qv7protobuf@4.25.25.29.6
MediumDEBIAN-CVE-2026-28388openssl@3.0.17-1~deb12u23.0.19-1~deb12u2
MediumDEBIAN-CVE-2025-69421openssl@3.0.17-1~deb12u23.0.18-1~deb12u2
MediumDEBIAN-CVE-2026-28387openssl@3.0.17-1~deb12u23.0.19-1~deb12u2
MediumDEBIAN-CVE-2026-28389openssl@3.0.17-1~deb12u23.0.19-1~deb12u2
MediumDEBIAN-CVE-2026-28390openssl@3.0.17-1~deb12u23.0.19-1~deb12u2
MediumDEBIAN-CVE-2019-1010025glibc@2.36-9+deb12u13no fix listed
LowDEBIAN-CVE-2025-69420openssl@3.0.17-1~deb12u23.0.18-1~deb12u2
LowDEBIAN-CVE-2026-57433perl@5.36.0-7+deb12u3no fix listed
LowPYSEC-2026-2132click@8.1.78.3.3
LowDEBIAN-CVE-2026-6653libxml2@2.9.14+dfsg-1.3~deb12u4no fix listed
LowDEBIAN-CVE-2026-13221perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2026-42496perl@5.36.0-7+deb12u3no fix listed
LowGHSA-pp6c-gr5w-3c5gpython-multipart@0.0.200.0.27
LowDEBIAN-CVE-2026-9076openssl@3.0.17-1~deb12u23.0.20-1~deb12u2
LowGHSA-62p4-gmf7-7g93pillow@10.4.012.3.0
LowGHSA-whj4-6x5x-4v2jpillow@10.4.012.2.0
LowDEBIAN-CVE-2026-12087perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2025-1352elfutils@0.188-2.1no fix listed
LowDEBIAN-CVE-2026-58015glib2.0@2.74.6-2+deb12u7no fix listed
LowDEBIAN-CVE-2026-58013glib2.0@2.74.6-2+deb12u7no fix listed
LowDEBIAN-CVE-2026-58010glib2.0@2.74.6-2+deb12u7no fix listed
LowDEBIAN-CVE-2026-58012glib2.0@2.74.6-2+deb12u7no fix listed
LowGHSA-7f5h-v6xp-fcq8starlette@0.41.20.49.1
LowDEBIAN-CVE-2026-0915glibc@2.36-9+deb12u132.36-9+deb12u14
LowDEBIAN-CVE-2023-50495ncurses@6.4-4no fix listed
LowDEBIAN-CVE-2026-58014glib2.0@2.74.6-2+deb12u7no fix listed
LowGHSA-vjc4-5qp5-m44jpillow@10.4.012.3.0
LowDEBIAN-CVE-2026-63072openssl@3.0.17-1~deb12u2no fix listed
LowDEBIAN-CVE-2026-40355krb5@1.20.1-2+deb12u41.20.1-2+deb12u5
LowDEBIAN-CVE-2026-40356krb5@1.20.1-2+deb12u41.20.1-2+deb12u5
LowDEBIAN-CVE-2026-45445openssl@3.0.17-1~deb12u23.0.20-1~deb12u2
LowDEBIAN-CVE-2026-85091zlib@1:1.2.13.dfsg-1no fix listed
LowGHSA-xj96-63gp-2gmrpillow@10.4.012.3.0
LowPYSEC-2026-103onnx@1.16.01.21.0rc1
LowGHSA-cfh3-3jmp-rvhcpillow@10.4.012.1.1
LowDEBIAN-CVE-2026-42013gnutls28@3.7.9-2+deb12u53.7.9-2+deb12u7
LowDEBIAN-CVE-2026-0861glibc@2.36-9+deb12u132.36-9+deb12u14
LowDEBIAN-CVE-2026-3833gnutls28@3.7.9-2+deb12u53.7.9-2+deb12u7
LowDEBIAN-CVE-2024-2236libgcrypt20@1.10.1-3no fix listed
LowDEBIAN-CVE-2026-31789openssl@3.0.17-1~deb12u23.0.19-1~deb12u2
LowDEBIAN-CVE-2025-69419openssl@3.0.17-1~deb12u23.0.18-1~deb12u2
LowDEBIAN-CVE-2026-54874openssl@3.0.17-1~deb12u2no fix listed
LowDEBIAN-CVE-2026-42766openssl@3.0.17-1~deb12u23.0.20-1~deb12u2
LowDEBIAN-CVE-2026-74860libxml2@2.9.14+dfsg-1.3~deb12u4no fix listed
LowDEBIAN-CVE-2025-69720ncurses@6.4-4no fix listed
LowDEBIAN-CVE-2025-6020pam@1.5.2-6+deb12u11.5.2-6+deb12u2

Used by

1 chart
ChartVersionTagContainers
immichimmich-helm0.3.0v2.3.11

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.