ghcr.io/kubeflow/spark-operator/controller:2.2.1 container image
GitHub Container RegistryScanned 15 Sept 2026
Deployed by 1 of 17,787 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/kubeflow/spark-operator/controller
ghcr.io/kubeflow/spark-operator/controller:2.2.1 resolved to 865ff4da5686, scanned 15 Sept 2026: 641 findings, 5 critical; deployed by 1 chart, among them spark-operator.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest 865ff4da5686 as scanned on 15 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 15 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-41080 | expat | no fix listed |
| Low | UBUNTU-CVE-2025-11839 | binutils | 2.34-6ubuntu1.11+esm1 |
| Low | UBUNTU-CVE-2025-11840 | binutils | 2.34-6ubuntu1.11+esm1 |
| Low | GHSA-w573-9ffj-6ff9 | netty-transport-native-epoll | 4.1.135.Final |
| Low | GHSA-w573-9ffj-6ff9 | netty-transport-native-kqueue | 4.1.135.Final |
| Low | UBUNTU-CVE-2025-4878 | libssh | 0.9.3-2ubuntu2.5+esm1 |
| Low | UBUNTU-CVE-2025-11495 | binutils | 2.34-6ubuntu1.11+esm2 |
| Low | UBUNTU-CVE-2025-8225 | binutils | 2.34-6ubuntu1.11+esm1 |
| Low | GHSA-wjpw-4j6x-6rwh | jetty-http | no fix listed |
| Low | UBUNTU-CVE-2025-11413 | binutils | 2.34-6ubuntu1.11+esm2 |
| Low | UBUNTU-CVE-2025-11494 | binutils | 2.34-6ubuntu1.11+esm2 |
| Low | UBUNTU-CVE-2025-69418 | openssl | 1.1.1f-1ubuntu2.24+esm2 |
| Low | UBUNTU-CVE-2025-1795 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm1 |
| Low | UBUNTU-CVE-2025-8732 | libxml2 | 2.9.10+dfsg-5ubuntu0.20.04.10+esm4 |
| Low | UBUNTU-CVE-2025-11412 | binutils | 2.34-6ubuntu1.11+esm2 |
| Low | UBUNTU-CVE-2025-11414 | binutils | 2.34-6ubuntu1.11+esm2 |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | UBUNTU-CVE-2026-59846 | libssh | no fix listed |
| Low | GO-2026-6179 | golang.org/ | 0.40.0 |
| Low | UBUNTU-CVE-2026-18477 | tar | no fix listed |
| Low | UBUNTU-CVE-2025-6141 | ncurses | 6.2-0ubuntu2.1+esm2 |
| Low | GO-2025-3787 | github.com/ | 2.3.0 |
| Low | USN-8010-1 | python-pip | 20.0.2-5ubuntu1.11+esm4 |
| Low | USN-8091-1 | util-linux | 2.34-0.1ubuntu9.6+esm1 |
| Low | USN-8543-2 | wget | 1.20.3-1ubuntu2.1+esm4 |
| Low | USN-8688-1 | pam | 1.3.1-5ubuntu4.7+esm1 |
| Low | GHSA-58qw-p7qm-5rvh | jetty-xml | 9.4.52.v20230823 |
| Low | UBUNTU-CVE-2025-13462 | python3.8 | no fix listed |
| Low | UBUNTU-CVE-2026-0965 | libssh | 0.9.3-2ubuntu2.5+esm3 |
| Low | GHSA-fghv-69vj-qj49 | netty-codec-http | 4.1.125.Final |
| Low | UBUNTU-CVE-2025-66382 | expat | no fix listed |
| Low | UBUNTU-CVE-2025-6170 | libxml2 | 2.9.10+dfsg-5ubuntu0.20.04.10+esm1 |
| Low | UBUNTU-CVE-2026-24515 | expat | 2.2.9-1ubuntu0.8+esm1 |
| Low | UBUNTU-CVE-2026-40228 | systemd | no fix listed |
| Low | UBUNTU-CVE-2026-32778 | expat | no fix listed |
| Low | GHSA-6vgw-5pg2-w6jp | pip | 26.0 |
| Low | UBUNTU-CVE-2026-1703 | python-pip | no fix listed |
| Low | UBUNTU-CVE-2026-15310 | python3.8 | no fix listed |
| Low | UBUNTU-CVE-2026-53910 | diffutils | 1:3.7-3ubuntu0.1~esm1 |
| Low | UBUNTU-CVE-2026-6879 | python3.8 | no fix listed |
| Low | UBUNTU-CVE-2026-86137 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-86141 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-89162 | pcre2 | no fix listed |
| Low | UBUNTU-CVE-2026-89156 | pcre2 | no fix listed |
| Low | UBUNTU-CVE-2026-0967 | libssh | 0.9.3-2ubuntu2.5+esm3 |
| Low | UBUNTU-CVE-2025-66861 | binutils | no fix listed |
| Low | UBUNTU-CVE-2026-18503 | python3.8 | no fix listed |
| Low | UBUNTU-CVE-2026-5958 | sed | 4.7-1ubuntu0.1~esm1 |
| Low | UBUNTU-CVE-2026-6368 | glibc | no fix listed |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| spark-operatorwikimedia | 2.2.7 | 2.2.1 | 2 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.