StackRadar

ghcr.io/k10app/catalog:latest container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/k10app/catalog

ghcr.io/k10app/catalog:latest resolved to 639c980be0f1, scanned 14 Sept 2026: 63 findings, 0 critical; deployed by 1 chart, among them k10app.

Radar Score

940031347

63 findings on digest 639c980be0f1 · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
latestresolves to639c980be0f11 chart7 days ago031347940

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

63 distinct on this digest

Findings for digest 639c980be0f1 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
HighALPINE-CVE-2023-0286openssl@1.1.1s-r01.1.1t-r0
HighALPINE-CVE-2023-2650openssl@1.1.1s-r01.1.1u-r0
HighALPINE-CVE-2022-4450openssl@1.1.1s-r01.1.1t-r0
MediumGHSA-2p57-rm9w-gvfpip@2.0.0no fix listed
MediumALPINE-CVE-2022-4304openssl@1.1.1s-r01.1.1t-r0
MediumGHSA-x3cc-x39p-42qxfast-xml-parser@4.0.114.1.2
MediumALPINE-CVE-2023-0215openssl@1.1.1s-r01.1.1t-r0
MediumALPINE-CVE-2023-0464openssl@1.1.1s-r01.1.1t-r1
MediumGHSA-c2qf-rxjj-qqgwsemver@5.7.15.7.2
MediumALPINE-CVE-2023-3446openssl@1.1.1s-r01.1.1u-r2
MediumGHSA-rc47-6667-2j5jhttp-cache-semantics@4.1.04.1.1
MediumALPINE-CVE-2023-5678openssl@1.1.1s-r01.1.1w-r1
MediumGHSA-37ch-88jc-xwx2path-to-regexp@0.1.70.1.13
MediumGHSA-9wv6-86v2-598jpath-to-regexp@0.1.70.1.10
MediumGHSA-qwcr-r2fm-qrc7body-parser@1.20.11.20.3
MediumGHSA-3ppc-4f35-3m26minimatch@3.1.23.1.3
LowGHSA-rhx6-c78j-4q9wpath-to-regexp@0.1.70.1.12
LowGHSA-34x7-hfp2-rc4vtar@6.1.117.5.7
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowGHSA-f5x3-32g6-xq36tar@6.1.116.2.1
LowGHSA-8cf7-32gw-wr33jsonwebtoken@8.5.19.0.0
LowGHSA-8gc5-j5rx-235rfast-xml-parser@4.0.114.5.5
LowGHSA-qffp-2rhf-9h96tar@6.1.117.5.10
LowALPINE-CVE-2023-0465openssl@1.1.1s-r01.1.1t-r2
LowGHSA-23hp-3jrh-7fpwtar@6.1.117.5.19
LowGHSA-7r86-cg39-jmmjminimatch@3.1.23.1.3
LowGHSA-8qq5-rm4j-mr97tar@6.1.117.5.3
LowGHSA-23c5-xmqv-rm74minimatch@3.1.23.1.4
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.111.1.17
LowGHSA-73rr-hh4g-fpgxdiff@5.1.05.2.2
LowGHSA-8x88-c5mf-7j5wtar@6.1.117.5.18
LowGHSA-rv95-896h-c2vcexpress@4.18.24.19.2
LowGHSA-r6q2-hw4h-h46wtar@6.1.117.5.4
LowGHSA-r292-9mhp-454mtar@6.1.117.5.21
LowGHSA-fj3w-jwp8-x2g3fast-xml-parser@4.0.114.5.4
LowGHSA-w5hq-g745-h8pquuid@8.3.211.1.1
LowGHSA-w4pp-8pjf-rmxwpacote@13.6.221.5.1
LowGHSA-9ppj-qmqm-q256tar@6.1.117.5.11
LowGHSA-qwph-4952-7xr6jsonwebtoken@8.5.19.0.0
LowALPINE-CVE-2025-26519musl@1.2.3-r11.2.3-r4
LowGHSA-f886-m6hf-6m8vbrace-expansion@1.1.111.1.13
LowGHSA-83g3-92jg-28cxtar@6.1.117.5.8
LowGHSA-w8wr-v893-vjvptar@6.1.117.5.18
LowGHSA-hjrf-2m68-5959jsonwebtoken@8.5.19.0.0
LowGHSA-jp2q-39xq-3w4gfast-xml-parser@4.0.114.5.5
LowGHSA-869p-cjfg-cm3xjws@3.2.23.2.3
LowGHSA-cm22-4g7w-348pserve-static@1.15.01.16.0
LowGHSA-gvwx-54wh-qm9jtar@6.1.117.5.17
LowALPINE-CVE-2023-42366busybox@1.35.0-r171.35.0-r18
LowGHSA-m6fv-jmcg-4jfgsend@0.18.00.19.0

Used by

1 chart
ChartVersionTagContainers
k10appk10app0.2.1latest1

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.