ghcr.io/kafbat/kafka-ui:v1.2.0 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/kafbat/kafka-ui
ghcr.io/kafbat/kafka-ui:v1.2.0 resolved to 185da4ad3e88, scanned 14 Sept 2026: 117 findings, 0 critical; deployed by 1 chart, among them kafka-ui.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
117 distinct on this digest
Findings for digest 185da4ad3e88 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| Medium | GHSA-w9fj-cfpg-grvv | netty-codec-http2 | 4.1.132.Final |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.3.5-r0 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.3.5-r0 |
| Medium | GHSA-3qp7-7mw8-wx86 | netty-handler | 4.1.135.Final |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.18.8 |
| Medium | GHSA-9pp5-9c7g-4r83 | spring-security-core | 6.4.6 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.18.8 |
| Medium | GHSA-prj3-ccx8-p6x4 | netty-codec-http2 | 4.1.124.Final |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.3.7-r0 |
| Medium | GHSA-cm33-6792-r9fm | netty-codec-dns | 4.1.133.Final |
| Medium | GHSA-f6hv-jmp6-3vwv | netty-codec-http2 | 4.1.133.Final |
| Medium | GHSA-f6hv-jmp6-3vwv | netty-codec-http | 4.1.133.Final |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.3.5-r0 |
| Medium | GHSA-jppx-w49h-x2qq | netty-codec-http | 4.1.136.Final |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | GHSA-mf92-479x-3373 | spring-security-web | no fix listed |
| Medium | GHSA-x4gw-5cx5-pgmh | netty-handler | 4.1.135.Final |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.3.7-r0 |
| Low | ALPINE-CVE-2025-69420 | openssl | 3.3.6-r0 |
| Low | GHSA-g3pr-3p32-fp23 | micrometer-core | no fix listed |
| Low | GHSA-57rv-r2g8-2cj3 | netty-codec-http | 4.1.133.Final |
| Low | GHSA-pwqr-wmgm-9rr8 | netty-codec-http | 4.1.132.Final |
| Low | GHSA-45q3-82m4-75jr | netty-handler-proxy | 4.1.133.Final |
| Low | GHSA-c4c3-7fpv-j4q5 | netty-handler | 4.1.137.Final |
| Low | GHSA-mg83-c7gq-rv5c | spring-security-crypto | 6.4.4 |
| Low | ALPINE-CVE-2026-31789 | openssl | 3.3.7-r0 |
| Low | ALPINE-CVE-2025-69419 | openssl | 3.3.6-r0 |
| Low | GHSA-5pvg-856g-cp85 | netty-resolver-dns | 4.1.135.Final |
| Low | GHSA-qv9r-c865-cp47 | log4j-api | 2.25.5 |
| Low | ALPINE-CVE-2026-22184 | zlib | 1.3.2-r0 |
| Low | GHSA-3p8m-j85q-pgmj | netty-codec | 4.1.125.Final |
| Low | GHSA-jmp9-x22r-554x | spring-core | 6.2.11 |
| Low | GHSA-mj4r-2hfc-f8p6 | netty-codec | 4.1.133.Final |
| Low | GHSA-c653-97m9-rcg9 | netty-handler | 4.1.135.Final |
| Low | GHSA-93wv-jw9v-4972 | netty-codec-http2 | 4.1.136.Final |
| Low | GHSA-6jqx-86gh-f27w | netty-codec-http | 4.1.136.Final |
| Low | GHSA-8v5q-rhf3-jphm | spring-security-core | 6.4.10 |
| Low | GHSA-mvh2-crg5-v77c | netty-codec-http | 4.1.136.Final |
| Low | GHSA-558v-64gr-wgg4 | netty-codec | 4.1.136.Final |
| Low | GHSA-x23c-287f-qqv5 | spring-webflux | 6.2.19 |
| Low | GHSA-xwmg-2g98-w7v9 | nimbus-jose-jwt | 10.0.2 |
| Low | GHSA-6r3c-xf4w-jxjm | spring-web | 6.2.8 |
| Low | GHSA-676x-f7gg-47vc | netty-resolver-dns | 4.1.135.Final |
| Low | GHSA-rc42-6c7j-7h5r | spring-boot | 3.4.5 |
| Low | ALPINE-CVE-2025-15468 | openssl | 3.3.6-r0 |