StackRadar

ghcr.io/linuxserver/mstream:version-v5.2.5 container image

GitHub Container Registry

Scanned 20 Sept 2026

Deployed by 1 of 17,813 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/linuxserver/mstream

ghcr.io/linuxserver/mstream:version-v5.2.5 resolved to 22c012bcc43c, scanned 20 Sept 2026: 344 findings, 0 critical, 2 on KEV; deployed by 1 chart, among them mstream.

Radar Score

4,3790864272

344 findings on digest 22c012bcc43c · scanned 20 Sept 2026

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
version-v5.2.5resolves to22c012bcc43c1 chartyesterday08642724,379

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

344 distinct on this digest

Findings for digest 22c012bcc43c as scanned on 20 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 20 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGHSA-jr5f-v2jv-69x6axios@0.21.10.30.0
MediumGHSA-x527-x647-q7gggolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
MediumGHSA-f23m-r3pf-42rhlodash@4.17.214.18.0
MediumGHSA-xxjr-mmjv-4gpglodash@4.17.214.17.23
MediumGHSA-gwc9-m7rh-j2wwgolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.0.0-20211202192323-5770296d904e
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
MediumGO-2021-0243stdlib@go1.15.51.15.14
MediumGO-2022-0273stdlib@go1.15.51.16.8
MediumGHSA-p782-xgp4-8hr8golang.org/x/sys@v0.0.0-20201214095126-aec9a390925b0.0.0-20220412211240-33da011f77ad
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
MediumGHSA-37ch-88jc-xwx2path-to-regexp@0.1.70.1.13
MediumGHSA-9wv6-86v2-598jpath-to-regexp@0.1.70.1.10
MediumGHSA-hcg3-q754-cr77golang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.35.0
MediumGHSA-p92q-9vqr-4j8vaxios@0.21.10.32.0
MediumGO-2022-1144stdlib@go1.15.51.18.9
MediumGHSA-3xgq-45jj-v275cross-spawn@7.0.37.0.5
MediumGHSA-pfrx-2q88-qq97got@6.7.111.8.5
MediumGHSA-3ppc-4f35-3m26minimatch@3.0.43.1.3
MediumGHSA-qwcr-r2fm-qrc7body-parser@1.19.01.20.3
MediumGHSA-96hv-2xvq-fx4pws@7.5.37.5.11
MediumGHSA-pf86-5x62-jrwfaxios@0.21.10.31.1
LowGHSA-vcc3-ghjq-m6frdecode-uri-component@0.2.00.5.0
LowGHSA-rhx6-c78j-4q9wpath-to-regexp@0.1.70.1.12
LowGHSA-hj48-42vr-x3v9path-parse@1.0.61.0.7
LowGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
LowGHSA-62hf-57xw-28j9axios@0.21.10.31.1
LowGHSA-9phm-fm57-rhg8golang.org/x/image@v0.0.0-20201208152932-35266b937fa60.18.0
LowGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.0.0-20201016220609-9e8e0b3908970.52.0
LowGHSA-34x7-hfp2-rc4vtar@4.4.157.5.7
LowGO-2021-0142stdlib@go1.13.11.13.15
LowGO-2021-0263stdlib@go1.15.51.16.10
LowGO-2022-0213stdlib@go1.13.11.12.11
LowGHSA-hfxv-24rg-xrqfaxios@0.21.10.32.0
LowGO-2023-1571stdlib@go1.15.51.19.6
LowGHSA-j5f8-grm9-p9fcaxios@0.21.10.32.0
LowGHSA-3g43-6gmg-66jwaxios@0.21.10.31.1
LowGHSA-cxjh-pqwp-8mfpfollow-redirects@1.14.11.15.6
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.111.1.17
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowGO-2022-0435stdlib@go1.15.51.17.9
LowGHSA-pw2r-vq6v-hr8cfollow-redirects@1.14.11.14.8
LowGHSA-x92r-3vfx-4cv3golang.org/x/image@v0.0.0-20201208152932-35266b937fa60.10.0
LowGHSA-f5x3-32g6-xq36tar@4.4.156.2.1
LowGHSA-8cf7-32gw-wr33jsonwebtoken@8.5.19.0.0
LowGO-2022-0288golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b2970.0.0-20211209124913-491a49abca63
LowGO-2022-0288stdlib@go1.15.51.16.12
LowGHSA-pmwg-cvhr-8vh7axios@0.21.10.31.1
LowGO-2023-2102stdlib@go1.15.51.20.10
LowGHSA-qffp-2rhf-9h96tar@4.4.157.5.10

Used by

1 chart
ChartVersionTagContainers
mstreamnicholaswildeVerified publisher2.1.2version-v5.2.51

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 20 Sept 2026 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.