ghcr.io/kubeflow/spark-operator/controller:2.2.1 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/kubeflow/spark-operator/controller
ghcr.io/kubeflow/spark-operator/controller:2.2.1 resolved to 865ff4da5686, scanned 14 Sept 2026: 633 findings, 6 critical; deployed by 1 chart, among them spark-operator.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
633 distinct on this digest
Findings for digest 865ff4da5686 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2025-13837 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm5 |
| Low | UBUNTU-CVE-2025-9714 | libxml2 | 2.9.10+dfsg-5ubuntu0.20.04.10+esm2 |
| Low | UBUNTU-CVE-2026-56409 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-58470 | wget | 1.20.3-1ubuntu2.1+esm2 |
| Low | GHSA-r978-9m6m-6gm6 | zookeeper | no fix listed |
| Low | GO-2026-5972 | stdlib | 1.25.13 |
| Low | GO-2026-6088 | stdlib | 1.25.13 |
| Low | GO-2026-6089 | stdlib | 1.25.13 |
| Low | GO-2026-6090 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2026-50813 | sqlite3 | no fix listed |
| Low | GO-2026-5038 | stdlib | 1.25.11 |
| Low | UBUNTU-CVE-2026-86139 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-13757 | p11-kit | 0.23.20-1ubuntu0.1+esm1 |
| Low | GO-2026-5942 | golang.org/ | 0.56.0 |
| Low | GHSA-5mg8-w23w-74h3 | guava | 32.0.0-android |
| Low | GHSA-hvcg-qmg6-jm4c | netty-codec-http | 4.1.135.Final |
| Low | UBUNTU-CVE-2026-11850 | krb5 | no fix listed |
| Low | UBUNTU-CVE-2026-56132 | expat | no fix listed |
| Low | GO-2025-4012 | stdlib | 1.24.8 |
| Low | UBUNTU-CVE-2026-15146 | wget | 1.20.3-1ubuntu2.1+esm3 |
| Low | GO-2025-3956 | stdlib | 1.23.12 |
| Low | UBUNTU-CVE-2025-8058 | glibc | 2.31-0ubuntu9.18+esm1 |
| Low | GO-2026-4440 | golang.org/ | 0.45.0 |
| Low | GO-2025-4011 | stdlib | 1.24.8 |
| Low | GO-2025-4015 | stdlib | 1.24.8 |
| Low | GO-2026-6218 | stdlib | 1.25.13 |
| Low | GO-2026-4441 | golang.org/ | 0.45.0 |
| Low | UBUNTU-CVE-2026-40930 | libpng1.6 | 1.6.37-2ubuntu0.1~esm3 |
| Low | UBUNTU-CVE-2025-64506 | libpng1.6 | 1.6.37-2ubuntu0.1~esm1 |
| Low | UBUNTU-CVE-2013-4235 | shadow | no fix listed |
| Low | UBUNTU-CVE-2025-45582 | tar | no fix listed |
| Low | UBUNTU-CVE-2026-15534 | perl | 5.30.0-9ubuntu0.5+esm4 |
| Low | GO-2026-5970 | golang.org/ | 0.39.0 |
| Low | UBUNTU-CVE-2025-8291 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm3 |
| Low | GO-2025-4155 | stdlib | 1.24.11 |
| Low | UBUNTU-CVE-2025-14017 | curl | 7.68.0-1ubuntu2.25+esm2 |
| Low | UBUNTU-CVE-2026-86144 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-56288 | patch | no fix listed |
| Low | UBUNTU-CVE-2026-56289 | patch | no fix listed |
| Low | GO-2025-4008 | stdlib | 1.24.8 |
| Low | GO-2025-4010 | stdlib | 1.24.8 |
| Low | UBUNTU-CVE-2025-69645 | binutils | no fix listed |
| Low | UBUNTU-CVE-2024-10041 | pam | no fix listed |
| Low | UBUNTU-CVE-2026-59850 | libssh | no fix listed |
| Low | UBUNTU-CVE-2026-50812 | sqlite3 | no fix listed |
| Low | GO-2025-4014 | stdlib | 1.24.8 |
| Low | UBUNTU-CVE-2026-34757 | libpng1.6 | 1.6.37-2ubuntu0.1~esm3 |
| Low | UBUNTU-CVE-2026-18938 | p11-kit | 0.23.20-1ubuntu0.1+esm1 |
| Low | UBUNTU-CVE-2026-0989 | libxml2 | 2.9.10+dfsg-5ubuntu0.20.04.10+esm4 |
| Low | GHSA-wf8f-6423-gfxg | jackson-core | 2.13.0 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| spark-operatorwikimedia | 2.2.7 | 2.2.1 | 2 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.