ghcr.io/immich-app/immich-server:v2.3.1 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/immich-app/immich-server
ghcr.io/immich-app/immich-server:v2.3.1 resolved to f8d06a32b1b2, scanned 14 Sept 2026: 620 findings, 0 critical; deployed by 1 chart, among them immich.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
506 distinct on this digest
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest f8d06a32b1b2 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-gr94-w7qr-f4j3 | engine.io | 6.6.7 |
| Low | DEBIAN-CVE-2026-40356 | krb5 | 1.21.3-5+deb13u1 |
| Low | DEBIAN-CVE-2026-45445 | openssl | 3.5.6-1~deb13u2 |
| Low | DEBIAN-CVE-2026-85091 | zlib | no fix listed |
| Low | DEBIAN-CVE-2026-6637 | postgresql-17 | 17.10-0+deb13u1 |
| Low | GHSA-6g55-p6wh-862q | postcss | 8.5.12 |
| Low | DEBIAN-CVE-2026-18408 | postgresql-17 | 17.11-0+deb13u1 |
| Low | GHSA-qffp-2rhf-9h96 | tar | 7.5.10 |
| Low | DEBIAN-CVE-2026-80230 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-15741 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-34545 | openexr | no fix listed |
| Low | GHSA-23hp-3jrh-7fpw | tar | 7.5.19 |
| Low | DEBIAN-CVE-2026-42013 | gnutls28 | 3.8.9-3+deb13u4 |
| Low | DEBIAN-CVE-2026-0861 | glibc | 2.41-12+deb13u2 |
| Low | GHSA-wmrf-hv6w-mr66 | kysely | 0.28.12 |
| Low | GHSA-52cp-r559-cp3m | js-yaml | 4.3.0 |
| Low | DEBIAN-CVE-2026-3833 | gnutls28 | 3.8.9-3+deb13u4 |
| Low | DEBIAN-CVE-2024-2236 | libgcrypt20 | no fix listed |
| Low | DEBIAN-CVE-2026-34588 | openexr | no fix listed |
| Low | DEBIAN-CVE-2026-31789 | openssl | 3.5.5-1~deb13u2 |
| Low | DEBIAN-CVE-2025-69419 | openssl | 3.5.4-1~deb13u2 |
| Low | GHSA-8cpq-38p9-67gx | kysely | 0.28.14 |
| Low | DEBIAN-CVE-2026-54874 | openssl | 3.5.7-1~deb13u2 |
| Low | DEBIAN-CVE-2026-6475 | postgresql-17 | 17.10-0+deb13u1 |
| Low | GHSA-7r86-cg39-jmmj | minimatch | 10.2.3 |
| Low | GHSA-vghf-hv5q-vc2g | validator | 13.15.22 |
| Low | DEBIAN-CVE-2026-42766 | openssl | 3.5.6-1~deb13u2 |
| Low | DEBIAN-CVE-2026-74860 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-66035 | libssh2 | 1.11.1-1+deb13u2 |
| Low | GHSA-2m8v-j782-fhvr | socket.io-parser | 4.2.7 |
| Low | DEBIAN-CVE-2025-69720 | ncurses | no fix listed |
| Low | GHSA-8qq5-rm4j-mr97 | tar | 7.5.3 |
| Low | DEBIAN-CVE-2026-86145 | pcre2 | 10.46-1~deb13u2 |
| Low | DEBIAN-CVE-2026-34543 | openexr | no fix listed |
| Low | DEBIAN-CVE-2026-63075 | openssl | 3.5.7-1~deb13u2 |
| Low | GHSA-rcmh-qjqh-p98v | nodemailer | 7.0.11 |
| Low | GHSA-v39h-62p7-jpjc | fast-uri | 3.1.2 |
| Low | DEBIAN-CVE-2026-58011 | glib2.0 | 2.84.4-3~deb13u4 |
| Low | GHSA-23c5-xmqv-rm74 | minimatch | 10.2.3 |
| Low | GHSA-q7rr-3cgh-j5r3 | @opentelemetry/ | 0.217.0 |
| Low | GHSA-q7rr-3cgh-j5r3 | @opentelemetry/ | 0.217.0 |
| Low | DEBIAN-CVE-2026-6479 | postgresql-17 | 17.10-0+deb13u1 |
| Low | DEBIAN-CVE-2025-15281 | glibc | 2.41-12+deb13u2 |
| Low | GHSA-mh99-v99m-4gvg | brace-expansion | 2.1.3 |
| Low | DEBIAN-CVE-2026-45186 | expat | 2.8.2-1~deb13u1 |
| Low | GHSA-wcpc-wj8m-hjx6 | protobufjs | 7.6.1 |
| Low | DEBIAN-CVE-2026-42011 | gnutls28 | 3.8.9-3+deb13u4 |
| Low | GHSA-73rr-hh4g-fpgx | diff | 5.2.2 |
| Low | DEBIAN-CVE-2026-6464 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-9538 | perl | no fix listed |