StackRadar

ghcr.io/jenkins-x/nexus:0.1.37 container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/jenkins-x/nexus

ghcr.io/jenkins-x/nexus:0.1.37 resolved to 8caf5289fe73, scanned 14 Sept 2026: 564 findings, 17 critical, 7 on KEV; deployed by 1 chart, among them nexus.

Radar Score

12,8561750264233

564 findings on digest 8caf5289fe73 · scanned 14 Sept 2026

KEV ×7 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
0.1.37resolves to8caf5289fe731 chart5 days ago175026423312,856

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

564 distinct on this digest

Findings for digest 8caf5289fe73 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
CriticalGHSA-f58c-gq56-vjjftika-core@1.24.13.2.2
CriticalGHSA-v98j-7crc-wvrjshiro-web@1.6.01.7.1
CriticalGHSA-f6jp-j6w3-w9hmshiro-core@1.6.01.8.0
CriticalRHSA-2021:1586KEVglib2@2.56.4-8.el80:2.56.4-9.el8
CriticalRHSA-2020:4951KEVfreetype@2.9.1-4.el80:2.9.1-4.el8_2.1
CriticalGHSA-j9h8-phrw-h4fhKEVxstream@1.4.121.4.18
CriticalGHSA-45hx-wfhj-473xh2@1.4.2002.1.210
CriticalRHSA-2024:2722glibc@2.28-101.el80:2.28-236.el8_9.13
CriticalRHSA-2024:3464glibc@2.28-101.el80:2.28-101.el8_2.2
CriticalGHSA-h376-j262-vhq6h2@1.4.2002.0.206
CriticalGHSA-mjmj-j48q-9wg2snakeyaml@1.262.0
CriticalRHSA-2025:3393KEVfreetype@2.9.1-4.el80:2.9.1-5.el8_2.1
CriticalRHSA-2023:5455KEVglibc@2.28-101.el80:2.28-225.el8_8.6
CriticalGHSA-mw36-7c6c-q4q2xstream@1.4.121.4.14-java7
CriticalRHSA-2023:5767KEVnghttp2@1.33.0-3.el8_2.10:1.33.0-3.el8_2.2
CriticalGHSA-vv7r-c36w-3prjcommons-fileupload@1.41.6.0
CriticalRHSA-2025:12010sqlite@3.26.0-6.el80:3.26.0-20.el8_10
HighRHSA-2022:5696java-1.8.0-openjdk@1:1.8.0.262.b10-0.el8_21:1.8.0.342.b07-2.el8_6
HighRHSA-2022:5700java-1.8.0-openjdk@1:1.8.0.262.b10-0.el8_21:1.8.0.342.b07-1.el8_2
HighRHSA-2022:0951expat@2.2.5-3.el80:2.2.5-4.el8_5.3
HighRHSA-2022:1070expat@2.2.5-3.el80:2.2.5-3.el8_2.2
HighGHSA-2p3x-qw9c-25hhxstream@1.4.121.4.16
HighGHSA-7chv-rrw6-w6fcxstream@1.4.121.4.17
HighRHSA-2022:1065openssl@1:1.1.1c-15.el81:1.1.1k-6.el8_5
HighRHSA-2025:0083cups@1:2.2.6-33.el81:2.2.6-62.el8_10
HighRHSA-2022:5818openssl@1:1.1.1c-15.el81:1.1.1k-7.el8_6
HighRHSA-2022:1642zlib@1.2.11-13.el80:1.2.11-18.el8_5
HighGHSA-jfvx-7wrx-43fhxstream@1.4.121.4.15
HighGHSA-4cf5-xmhp-3xj7shiro-core@1.6.01.9.1
HighRHSA-2021:1024openssl@1:1.1.1c-15.el81:1.1.1g-15.el8_3
HighRHSA-2023:1405openssl@1:1.1.1c-15.el81:1.1.1k-9.el8_7
HighRHSA-2023:1439openssl@1:1.1.1c-15.el81:1.1.1c-21.el8_2
HighGHSA-26vr-8j45-3r4wjetty-server@9.4.30.v202006119.4.39
HighRHSA-2025:1301KEVgcc@8.3.1-5.el80:8.5.0-23.el8_10
HighRHSA-2021:4424openssl@1:1.1.1c-15.el81:1.1.1k-4.el8
HighGHSA-hfrx-6qgj-fp6ccommons-fileupload@1.41.5
HighGHSA-4cch-wxpw-8p28xstream@1.4.121.4.15
HighRHSA-2021:5226openssl@1:1.1.1c-15.el81:1.1.1k-5.el8_5
HighRHSA-2025:9318javapackages-tools@5.3.0-1.module+el8+2447+6f56d9a60:5.3.0-2.module+el8.10.0+23274+27840b45
HighRHSA-2024:0628libssh@0.9.0-4.el80:0.9.6-13.el8_9
HighRHSA-2025:22871expat@2.2.5-3.el80:2.2.10-1.el8_2
HighGHSA-4hrm-m67v-5cxrxstream@1.4.121.4.16
HighGHSA-59j4-wjwp-mw9mvelocity@1.7no fix listed
HighRHSA-2024:5654curl@7.61.1-12.el80:7.61.1-34.el8_10.2
HighRHSA-2021:1633python3@3.6.8-23.el80:3.6.8-37.el8
HighGHSA-hwpc-8xqv-jvj4xstream@1.4.121.4.16
HighGHSA-hrcp-8f3q-4w2cxstream@1.4.121.4.16
HighRHSA-2021:1063openssl@1:1.1.1c-15.el81:1.1.1c-18.el8_2
HighRHSA-2024:4252nghttp2@1.33.0-3.el8_2.10:1.33.0-6.el8_10.1
HighRHSA-2020:4641python-six@1.11.0-8.el80:1.12.0-9.module+el8.2.0+5234+f98739b6

Used by

1 chart
ChartVersionTagContainers
nexusjenkins-x0.1.370.1.371

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.