StackRadar

ghcr.io/karakeep-app/karakeep:0.26.0 container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/karakeep-app/karakeep

ghcr.io/karakeep-app/karakeep:0.26.0 resolved to f575a34ed3f8, scanned 14 Sept 2026: 463 findings, 1 critical; deployed by 1 chart, among them karakeep.

Radar Score

4,9681372387

463 findings on digest f575a34ed3f8 · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
0.26.0resolves tof575a34ed3f81 chart8 days ago13723874,968

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

387 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest f575a34ed3f8 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-m8rv-5g2x-5cg5undici@6.21.36.28.0
LowGHSA-c7w3-x93f-qmm8nodemailer@7.0.48.0.4
LowALPINE-CVE-2025-9820gnutls@3.8.8-r03.8.12-r0
LowGO-2026-4602stdlib@go1.23.101.25.8
LowALPINE-CVE-2026-27456util-linux@2.41-r92.41.6-r0
LowGHSA-g8m3-5g58-fq7mundici@6.21.36.27.0
LowGHSA-35p6-xmwp-9g52undici@6.21.36.27.0
LowALPINE-CVE-2026-4519python3@3.12.11-r03.12.14-r0
LowGHSA-vfv6-92ff-j949next@14.2.2515.5.16
LowGHSA-38r7-794h-5758webpack@5.99.95.104.0
LowGHSA-8fgc-7cc6-rx7xwebpack@5.99.95.104.1
LowALPINE-CVE-2026-41080expat@2.7.1-r02.8.1-r0
LowALPINE-CVE-2025-69418openssl@3.5.1-r03.5.5-r0
LowGO-2026-5024golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f80.44.0
LowRUSTSEC-2021-0145atty@0.2.14no fix listed
LowRUSTSEC-2024-0375atty@0.2.14no fix listed
LowRUSTSEC-2024-0404anstream@0.6.50.6.8
LowRUSTSEC-2024-0436paste@1.0.14no fix listed
LowRUSTSEC-2025-0022openssl@0.10.710.10.72
LowRUSTSEC-2025-0023tokio@1.44.11.38.2
LowRUSTSEC-2025-0134rustls-pemfile@2.2.0no fix listed
LowRUSTSEC-2026-0097rand@0.8.50.8.6
LowRUSTSEC-2026-0190anyhow@1.0.981.0.103
LowRUSTSEC-2026-0204crossbeam-epoch@0.9.180.9.20
LowALPINE-CVE-2025-46394busybox@1.37.0-r181.37.0-r20
LowGHSA-pxg6-pf52-xh8xcookie@0.6.00.7.0
LowGHSA-6475-r3vj-m8vf@smithy/config-resolver@4.1.44.4.0
LowALPINE-CVE-2025-6170libxml2@2.13.8-r02.13.9-r0
LowALPINE-CVE-2026-24515expat@2.7.1-r02.7.4-r0
LowALPINE-CVE-2024-58251busybox@1.37.0-r181.37.0-r20
LowGHSA-vxr8-fq34-vvx9dompurify@3.2.63.4.9
LowGHSA-3h52-269p-cp9rnext@14.2.2514.2.30
LowGHSA-c2j3-45gr-mqc4dompurify@3.2.63.4.12
LowALPINE-CVE-2025-9165tiff@4.7.0-r04.7.1-r0
LowGHSA-x4vx-rjvf-j5p4dompurify@3.2.6no fix listed
LowGHSA-cq8v-f236-94qcrand@0.8.50.8.6
LowGHSA-g98v-hv3f-hcfratty@0.2.14no fix listed

Used by

1 chart
ChartVersionTagContainers
karakeeprtomik-helm-chartsVerified publisher0.0.10.26.01

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.