StackRadar

ghcr.io/immich-app/immich-server:v3.1.0 container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/immich-app/immich-server

ghcr.io/immich-app/immich-server:v3.1.0 resolved to b434cb9287ee, scanned 14 Sept 2026: 408 findings, 0 critical; deployed by 1 chart, among them immich.

Radar Score

4,2390059348

408 findings on digest b434cb9287ee · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v3.1.0resolves tob434cb9287ee1 chart8 days ago00593484,239

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

408 distinct on this digest

Findings for digest b434cb9287ee as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-8458curl@8.14.1-2+deb13u3no fix listed
LowDEBIAN-CVE-2026-6253curl@8.14.1-2+deb13u38.14.1-2+deb13u4
LowGHSA-qfvm-cv95-jqjfmulter@2.2.02.3.0
LowGHSA-w4pp-8pjf-rmxwpacote@21.4.021.5.1
LowGHSA-9ppj-qmqm-q256tar@7.5.97.5.11
LowDEBIAN-CVE-2026-4437glibc@2.41-12+deb13u22.41-12+deb13u3
LowDEBIAN-CVE-2026-9547curl@8.14.1-2+deb13u3no fix listed
LowDEBIAN-CVE-2025-8177tiff@4.7.0-3+deb13u2no fix listed
LowDEBIAN-CVE-2021-45346sqlite3@3.46.1-7+deb13u1no fix listed
LowDEBIAN-CVE-2025-8941pam@1.7.0-5no fix listed
LowDEBIAN-CVE-2025-70873sqlite3@3.46.1-7+deb13u1no fix listed
LowDEBIAN-CVE-2026-56209aom@3.12.1-13.12.1-1+deb13u1
LowDEBIAN-CVE-2026-57432perl@5.40.1-65.40.1-6+deb13u1
LowDEBIAN-CVE-2026-6276curl@8.14.1-2+deb13u38.14.1-2+deb13u4
LowGHSA-wc9g-mqfw-jrwmmulter@2.2.02.3.0
LowDEBIAN-CVE-2024-26458krb5@1.21.3-5+deb13u1no fix listed
LowDEBIAN-CVE-2026-76956expat@2.7.1-2no fix listed
LowGHSA-f886-m6hf-6m8vbrace-expansion@5.0.35.0.5
LowGHSA-535w-7cp7-47q4multer@2.2.02.3.0
LowDEBIAN-CVE-2025-8176tiff@4.7.0-3+deb13u2no fix listed
LowDEBIAN-CVE-2026-9080curl@8.14.1-2+deb13u3no fix listed
LowDEBIAN-CVE-2026-5545curl@8.14.1-2+deb13u38.14.1-2+deb13u4
LowDEBIAN-CVE-2026-48962perl@5.40.1-65.40.1-6+deb13u1
LowDEBIAN-CVE-2026-3784curl@8.14.1-2+deb13u38.14.1-2+deb13u4
LowDEBIAN-CVE-2026-9545curl@8.14.1-2+deb13u3no fix listed
LowGHSA-fxqj-rqcc-2cmppostcss@8.5.198.5.23
LowDEBIAN-CVE-2026-59982openexr@3.1.13-2no fix listed
LowDEBIAN-CVE-2026-56210aom@3.12.1-13.12.1-1+deb13u1
LowDEBIAN-CVE-2025-14819curl@8.14.1-2+deb13u38.14.1-2+deb13u4
LowDEBIAN-CVE-2026-76642util-linux@2.41-5no fix listed
LowDEBIAN-CVE-2026-11822sqlite3@3.46.1-7+deb13u13.46.1-7+deb13u2
LowDEBIAN-CVE-2026-11824sqlite3@3.46.1-7+deb13u13.46.1-7+deb13u2
LowDEBIAN-CVE-2026-6471postgresql-17@17.10-1.pgdg13+117.11-0+deb13u1
LowDEBIAN-CVE-2026-48961perl@5.40.1-65.40.1-6+deb13u1
LowDEBIAN-CVE-2026-34379openexr@3.1.13-2no fix listed
LowDEBIAN-CVE-2026-63074openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
LowDEBIAN-CVE-2025-14524curl@8.14.1-2+deb13u38.14.1-2+deb13u4
LowDEBIAN-CVE-2025-61144tiff@4.7.0-3+deb13u2no fix listed
LowDEBIAN-CVE-2026-6238glibc@2.41-12+deb13u2no fix listed
LowGHSA-5jgf-p345-68v8fast-uri@3.1.33.1.6
LowGHSA-jqff-g426-hqxpfast-uri@3.1.33.1.6
LowGHSA-w8wr-v893-vjvptar@7.5.167.5.18
LowDEBIAN-CVE-2026-27622openexr@3.1.13-2no fix listed
LowDEBIAN-CVE-2026-34544openexr@3.1.13-2no fix listed
LowDEBIAN-CVE-2026-53532openexr@3.1.13-2no fix listed
LowGHSA-7p8r-x3mc-p8w7fast-uri@3.1.33.1.5
LowDEBIAN-CVE-2026-25210expat@2.7.1-22.8.2-1~deb13u1
LowGHSA-f65p-4m7j-42xcfast-uri@3.1.33.1.6
LowGHSA-fph4-wmhf-6fwffast-uri@3.1.33.1.6
LowDEBIAN-CVE-2026-5435glibc@2.41-12+deb13u2no fix listed

Used by

1 chart
ChartVersionTagContainers
immichhelmforgeVerified publisher1.2.8v3.1.01

Also in older indexed versions (1)

Not counted above: the chart’s latest version no longer references it, or the chart is no longer in the index.

ChartVersionTagContainers
immichsecustorVerified publisher2.0.3v3.1.01

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.