ghcr.io/kubeflow/spark-operator/controller:2.2.1 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/kubeflow/spark-operator/controller
ghcr.io/kubeflow/spark-operator/controller:2.2.1 resolved to 865ff4da5686, scanned 14 Sept 2026: 633 findings, 6 critical; deployed by 1 chart, among them spark-operator.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
633 distinct on this digest
Findings for digest 865ff4da5686 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2025-11414 | binutils | 2.34-6ubuntu1.11+esm2 |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | UBUNTU-CVE-2026-59846 | libssh | no fix listed |
| Low | GO-2026-6179 | golang.org/ | 0.40.0 |
| Low | UBUNTU-CVE-2026-18477 | tar | no fix listed |
| Low | UBUNTU-CVE-2025-6141 | ncurses | 6.2-0ubuntu2.1+esm2 |
| Low | GO-2025-3787 | github.com/ | 2.3.0 |
| Low | USN-8010-1 | python-pip | 20.0.2-5ubuntu1.11+esm4 |
| Low | USN-8091-1 | util-linux | 2.34-0.1ubuntu9.6+esm1 |
| Low | USN-8543-2 | wget | 1.20.3-1ubuntu2.1+esm4 |
| Low | USN-8688-1 | pam | 1.3.1-5ubuntu4.7+esm1 |
| Low | GHSA-58qw-p7qm-5rvh | jetty-xml | 9.4.52.v20230823 |
| Low | UBUNTU-CVE-2025-13462 | python3.8 | no fix listed |
| Low | UBUNTU-CVE-2026-0965 | libssh | 0.9.3-2ubuntu2.5+esm3 |
| Low | GHSA-fghv-69vj-qj49 | netty-codec-http | 4.1.125.Final |
| Low | UBUNTU-CVE-2025-66382 | expat | no fix listed |
| Low | UBUNTU-CVE-2025-6170 | libxml2 | 2.9.10+dfsg-5ubuntu0.20.04.10+esm1 |
| Low | UBUNTU-CVE-2026-24515 | expat | 2.2.9-1ubuntu0.8+esm1 |
| Low | UBUNTU-CVE-2026-40228 | systemd | no fix listed |
| Low | UBUNTU-CVE-2026-32778 | expat | no fix listed |
| Low | GHSA-6vgw-5pg2-w6jp | pip | 26.0 |
| Low | UBUNTU-CVE-2026-1703 | python-pip | no fix listed |
| Low | UBUNTU-CVE-2026-15310 | python3.8 | no fix listed |
| Low | UBUNTU-CVE-2026-53910 | diffutils | 1:3.7-3ubuntu0.1~esm1 |
| Low | UBUNTU-CVE-2026-6879 | python3.8 | no fix listed |
| Low | UBUNTU-CVE-2026-86137 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-86141 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-0967 | libssh | 0.9.3-2ubuntu2.5+esm3 |
| Low | UBUNTU-CVE-2025-66861 | binutils | no fix listed |
| Low | UBUNTU-CVE-2026-18503 | python3.8 | no fix listed |
| Low | UBUNTU-CVE-2026-5958 | sed | 4.7-1ubuntu0.1~esm1 |
| Low | UBUNTU-CVE-2026-6368 | glibc | no fix listed |
| None | UBUNTU-CVE-2026-19582 | binutils | no fix listed |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| spark-operatorwikimedia | 2.2.7 | 2.2.1 | 2 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.