StackRadar

ghcr.io/linuxserver/mstream:version-v5.2.5 container image

GitHub Container Registry

Scanned 20 Sept 2026

Deployed by 1 of 17,813 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/linuxserver/mstream

ghcr.io/linuxserver/mstream:version-v5.2.5 resolved to 22c012bcc43c, scanned 20 Sept 2026: 344 findings, 0 critical, 2 on KEV; deployed by 1 chart, among them mstream.

Radar Score

4,3790864272

344 findings on digest 22c012bcc43c · scanned 20 Sept 2026

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
version-v5.2.5resolves to22c012bcc43c1 chartyesterday08642724,379

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

272 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest 22c012bcc43c as scanned on 20 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 20 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-vcc3-ghjq-m6frdecode-uri-component@0.2.00.5.0
LowGHSA-rhx6-c78j-4q9wpath-to-regexp@0.1.70.1.12
LowGHSA-hj48-42vr-x3v9path-parse@1.0.61.0.7
LowGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
LowGHSA-62hf-57xw-28j9axios@0.21.10.31.1
LowGHSA-9phm-fm57-rhg8golang.org/x/image@v0.0.0-20201208152932-35266b937fa60.18.0
LowGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
LowGHSA-34x7-hfp2-rc4vtar@4.4.157.5.7
LowGO-2021-0142stdlib@go1.13.11.13.15
LowGO-2021-0263stdlib@go1.15.51.16.10
LowGO-2022-0213stdlib@go1.13.11.12.11
LowGHSA-hfxv-24rg-xrqfaxios@0.21.10.32.0
LowGO-2023-1571stdlib@go1.15.51.19.6
LowGHSA-j5f8-grm9-p9fcaxios@0.21.10.32.0
LowGHSA-3g43-6gmg-66jwaxios@0.21.10.31.1
LowGHSA-cxjh-pqwp-8mfpfollow-redirects@1.14.11.15.6
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.111.1.17
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowGO-2022-0435stdlib@go1.15.51.17.9
LowGHSA-pw2r-vq6v-hr8cfollow-redirects@1.14.11.14.8
LowGHSA-x92r-3vfx-4cv3golang.org/x/image@v0.0.0-20201208152932-35266b937fa60.10.0
LowGHSA-f5x3-32g6-xq36tar@4.4.156.2.1
LowGHSA-8cf7-32gw-wr33jsonwebtoken@8.5.19.0.0
LowGO-2022-0288stdlib@go1.15.51.16.12
LowGO-2022-0288golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b2970.0.0-20211209124913-491a49abca63
LowGHSA-pmwg-cvhr-8vh7axios@0.21.10.31.1
LowGO-2023-2102stdlib@go1.15.51.20.10
LowGHSA-qffp-2rhf-9h96tar@4.4.157.5.10
LowGHSA-j3p8-6mrq-6g7hgolang.org/x/image@v0.0.0-20201208152932-35266b937fa60.10.0
LowGO-2022-0236stdlib@go1.15.51.15.12
LowGHSA-23hp-3jrh-7fpwtar@4.4.157.5.19
LowGO-2021-0226stdlib@go1.13.11.14.8
LowGHSA-52cp-r559-cp3mjs-yaml@3.14.13.15.0
LowGHSA-hmw2-7cc7-3qxxform-data@2.3.22.5.6
LowGO-2021-0240stdlib@go1.15.51.15.13
LowGHSA-7r86-cg39-jmmjminimatch@3.0.43.1.3
LowGO-2021-0242stdlib@go1.15.51.15.13
LowGHSA-8qq5-rm4j-mr97tar@4.4.157.5.3
LowGO-2021-0264stdlib@go1.15.51.16.10
LowGO-2022-0969stdlib@go1.15.51.18.6
LowGHSA-fvcv-3m26-pcqxaxios@0.21.10.31.0
LowGHSA-jmr9-qjv8-65gvextract-zip@1.7.0no fix listed
LowGO-2021-0239stdlib@go1.15.51.15.13
LowGO-2021-0347stdlib@go1.15.51.16.15
LowGO-2021-0245stdlib@go1.15.51.15.15
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
LowGHSA-23c5-xmqv-rm74minimatch@3.0.43.1.4
LowGO-2021-0319stdlib@go1.15.51.16.14
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
LowGHSA-2wrh-6pvc-2jm9golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b2970.13.0

Used by

1 chart
ChartVersionTagContainers
mstreamnicholaswildeVerified publisher2.1.2version-v5.2.51

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 20 Sept 2026 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.