ghcr.io/linuxserver/calibre-web:latest container image
GitHub Container RegistryScanned 19 Sept 2026
Deployed by 1 of 17,805 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/linuxserver/calibre-web
ghcr.io/linuxserver/calibre-web:latest resolved to 0767226fcf20, scanned 19 Sept 2026: 469 findings, 0 critical; deployed by 1 chart, among them opds-shelf.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest 0767226fcf20 as scanned on 19 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 19 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-25645 | python-pip | no fix listed |
| Low | GO-2026-4403 | stdlib | 1.23.9 |
| Low | GHSA-23w6-3w8w-8484 | pypdf | 6.16.1 |
| Low | GHSA-763m-79hh-57f2 | pypdf | 6.16.1 |
| Low | UBUNTU-CVE-2026-90781 | alsa-lib | no fix listed |
| Low | UBUNTU-CVE-2026-56369 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-53463 | imagemagick | no fix listed |
| Low | GO-2026-4970 | stdlib | 1.25.12 |
| Low | UBUNTU-CVE-2026-56365 | imagemagick | no fix listed |
| Low | GHSA-cj93-chg6-vgv8 | pypdf | 6.12.0 |
| Low | GHSA-fp3f-mc75-235c | pypdf | 6.15.0 |
| Low | GHSA-fwg2-594c-jp42 | pypdf | 6.15.0 |
| Low | UBUNTU-CVE-2026-3219 | python-pip | no fix listed |
| Low | UBUNTU-CVE-2026-32777 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-39113 | sqlite3 | 3.45.1-1ubuntu2.8 |
| Low | UBUNTU-CVE-2025-43965 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm5 |
| Low | UBUNTU-CVE-2026-61857 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13 |
| Low | UBUNTU-CVE-2026-43895 | jq | no fix listed |
| Low | UBUNTU-CVE-2026-56368 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13 |
| Low | GO-2026-4602 | stdlib | 1.25.8 |
| Low | UBUNTU-CVE-2026-55595 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-76957 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-28688 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 |
| Low | UBUNTU-CVE-2026-18508 | tar | no fix listed |
| Low | UBUNTU-CVE-2026-62946 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13 |
| Low | UBUNTU-CVE-2025-68950 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11 |
| Low | UBUNTU-CVE-2026-56373 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13 |
| Low | UBUNTU-CVE-2026-62363 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-56378 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13 |
| Low | UBUNTU-CVE-2026-41990 | libgcrypt20 | 1.12.0-2ubuntu0.1~Fips1~rc11 |
| Low | UBUNTU-CVE-2026-61860 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-61868 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-45186 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-89160 | pcre2 | no fix listed |
| Low | UBUNTU-CVE-2022-3219 | gnupg2 | no fix listed |
| Low | UBUNTU-CVE-2026-87876 | cups | no fix listed |
| Low | UBUNTU-CVE-2026-32776 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-41080 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-48733 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-62343 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-33535 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-61858 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-27798 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 |
| Low | UBUNTU-CVE-2025-11731 | libxslt | no fix listed |
| Low | UBUNTU-CVE-2026-27799 | imagemagick | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 |
| Low | UBUNTU-CVE-2025-9403 | jq | no fix listed |
| Low | UBUNTU-CVE-2026-47165 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2025-68469 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-46559 | imagemagick | no fix listed |
| Low | UBUNTU-CVE-2026-53464 | imagemagick | no fix listed |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| opds-shelfopds-shelfVerified publisher | 0.4.0 | latest | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.