StackRadar

ghcr.io/karakeep-app/karakeep:0.27.1 container image

GitHub Container Registry

Scanned 16 Sept 2026

Deployed by 1 of 17,790 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/karakeep-app/karakeep

ghcr.io/karakeep-app/karakeep:0.27.1 resolved to abd7d6b11b1b, scanned 16 Sept 2026: 504 findings, 0 critical; deployed by 1 chart, among them karakeep.

Radar Score

5,2200372429

504 findings on digest abd7d6b11b1b · scanned 16 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
0.27.1resolves toabd7d6b11b1b1 chart10 days ago03724295,220

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

504 distinct on this digest

Findings for digest abd7d6b11b1b as scanned on 16 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 16 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-phqj-4mhp-q6mqopenssl@0.10.710.10.80
LowGHSA-3hrh-pfw6-9m5xhono@4.7.114.12.21
LowGHSA-v6h2-p8h4-qcjwbrace-expansion@2.0.12.0.2
LowALPINE-CVE-2025-68160openssl@3.5.1-r03.5.5-r0
LowALPINE-CVE-2025-69277libsodium@1.0.20-r01.0.20-r1
LowGHSA-2rxc-gjrp-vjhxanstream@0.6.50.6.8
LowALPINE-CVE-2026-34757libpng@1.6.47-r01.6.57-r0
LowGHSA-qp7p-654g-cw7phono@4.7.114.12.18
LowGO-2026-4403stdlib@go1.20.71.23.9
LowGHSA-gq3j-xvxp-8hrfhono@4.7.114.11.10
LowGHSA-67mh-4wv8-2f99esbuild@0.18.200.25.0
LowGHSA-w37m-7fhw-fmv9next@15.3.315.3.7
LowGO-2026-4970stdlib@go1.23.101.25.12
LowGHSA-69xw-7hcm-h432hono@4.7.114.12.16
LowGHSA-3g8h-86w9-wvmqnext@15.3.315.5.16
LowGHSA-m8rv-5g2x-5cg5undici@6.21.36.28.0
LowGHSA-c7w3-x93f-qmm8nodemailer@7.0.48.0.4
LowALPINE-CVE-2025-9820gnutls@3.8.8-r03.8.12-r0
LowGO-2026-4602stdlib@go1.23.101.25.8
LowALPINE-CVE-2026-27456util-linux@2.41-r92.41.6-r0
LowGHSA-g8m3-5g58-fq7mundici@6.21.36.27.0
LowGHSA-79qm-7rj5-m7r9hono@4.7.114.12.34
LowGHSA-hm8q-7f3q-5f36hono@4.7.114.12.18
LowGHSA-35p6-xmwp-9g52undici@6.21.36.27.0
LowALPINE-CVE-2026-4519python3@3.12.11-r03.12.14-r0
LowALPINE-CVE-2026-25832mbedtls@3.6.4-r03.6.7-r0
LowGHSA-vfv6-92ff-j949next@15.3.315.5.16
LowGHSA-38r7-794h-5758webpack@5.99.95.104.0
LowGHSA-8fgc-7cc6-rx7xwebpack@5.99.95.104.1
LowALPINE-CVE-2026-41080expat@2.7.1-r02.8.1-r0
LowALPINE-CVE-2025-69418openssl@3.5.1-r03.5.5-r0
LowGO-2026-5024golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f80.44.0
LowRUSTSEC-2021-0145atty@0.2.14no fix listed
LowRUSTSEC-2024-0375atty@0.2.14no fix listed
LowRUSTSEC-2024-0404anstream@0.6.50.6.8
LowRUSTSEC-2024-0436paste@1.0.14no fix listed
LowRUSTSEC-2025-0022openssl@0.10.710.10.72
LowRUSTSEC-2025-0023tokio@1.44.11.38.2
LowRUSTSEC-2025-0134rustls-pemfile@2.2.0no fix listed
LowRUSTSEC-2026-0097rand@0.8.50.8.6
LowRUSTSEC-2026-0190anyhow@1.0.791.0.103
LowRUSTSEC-2026-0204crossbeam-epoch@0.9.180.9.20
LowALPINE-CVE-2025-46394busybox@1.37.0-r181.37.0-r20
LowGHSA-pxg6-pf52-xh8xcookie@0.6.00.7.0
LowGHSA-6475-r3vj-m8vf@smithy/config-resolver@4.1.44.4.0
LowALPINE-CVE-2025-6170libxml2@2.13.8-r02.13.9-r0
LowALPINE-CVE-2026-24515expat@2.7.1-r02.7.4-r0
LowALPINE-CVE-2024-58251busybox@1.37.0-r181.37.0-r20
LowGHSA-vxr8-fq34-vvx9dompurify@3.2.63.4.9
LowGHSA-c2j3-45gr-mqc4dompurify@3.2.63.4.12

Used by

1 chart
ChartVersionTagContainers
karakeepself-hosters-by-nightVerified publisher2.5.10.27.11

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 16 Sept 2026 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.