ghcr.io/nicholaswilde/etherpad:version-1.8.14 container image
GitHub Container RegistryScanned 20 Sept 2026
Deployed by 1 of 17,813 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/nicholaswilde/etherpad
ghcr.io/nicholaswilde/etherpad:version-1.8.14 resolved to 26bbd45110d5, scanned 20 Sept 2026: 211 findings, 2 critical; deployed by 1 chart, among them etherpad.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
211 distinct on this digest
Findings for digest 26bbd45110d5 as scanned on 20 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 20 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2021-3711 | openssl | 1.1.1l-r0 |
| Critical | ALPINE-CVE-2021-22930 | nodejs | 14.17.4-r0 |
| High | GHSA-phwq-j96m-2c2q | ejs | 3.1.7 |
| High | ALPINE-CVE-2022-0778 | libretls | 3.3.3p1-r3 |
| High | ALPINE-CVE-2022-0778 | openssl | 1.1.1n-r0 |
| High | ALPINE-CVE-2023-0286 | openssl | 1.1.1t-r0 |
| High | ALPINE-CVE-2022-32214 | nodejs | 14.20.1-r0 |
| High | ALPINE-CVE-2018-25032 | zlib | 1.2.12-r0 |
| High | ALPINE-CVE-2021-22931 | nodejs | 14.17.5-r0 |
| High | ALPINE-CVE-2021-3712 | openssl | 1.1.1l-r0 |
| High | ALPINE-CVE-2022-32215 | nodejs | 14.20.1-r0 |
| High | ALPINE-CVE-2022-37434 | zlib | 1.2.12-r2 |
| High | ALPINE-CVE-2022-32213 | nodejs | 14.20.1-r0 |
| High | ALPINE-CVE-2022-21824 | nodejs | 14.19.0-r0 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| High | GHSA-w573-4hg7-7wgq | decode-uri-component | 0.2.1 |
| High | ALPINE-CVE-2022-4450 | openssl | 1.1.1t-r0 |
| High | GHSA-3jfq-g458-7qm9 | tar | 6.1.1 |
| Medium | GHSA-hrpp-h998-j3pp | qs | 6.10.3 |
| Medium | GHSA-2p57-rm9w-gvfp | ip | no fix listed |
| Medium | GHSA-xvch-5gv4-984h | minimist | 1.2.6 |
| Medium | GHSA-r628-mhmh-qjhw | tar | 6.1.2 |
| Medium | GHSA-896r-f27r-55mw | json-schema | 0.4.0 |
| Medium | GHSA-cph5-m8f7-6c5x | axios | 0.21.2 |
| Medium | ALPINE-CVE-2021-22918 | nodejs | 14.17.3-r0 |
| Medium | ALPINE-CVE-2021-44531 | nodejs | 14.19.0-r0 |
| Medium | ALPINE-CVE-2022-4304 | openssl | 1.1.1t-r0 |
| Medium | GHSA-9w5j-4mwv-2wj8 | simple-git | 3.16.0 |
| Medium | ALPINE-CVE-2022-28391 | busybox | 1.33.1-r7 |
| Medium | ALPINE-CVE-2021-22939 | nodejs | 14.17.5-r0 |
| Medium | GHSA-p6mc-m468-83gw | lodash.pick | no fix listed |
| Medium | ALPINE-CVE-2021-37701 | nodejs | 14.17.6-r0 |
| Medium | GHSA-28xr-mwxg-3qc8 | simple-git | 3.5.0 |
| Medium | ALPINE-CVE-2021-36159 | apk-tools | 2.12.6-r0 |
| Medium | ALPINE-CVE-2023-0215 | openssl | 1.1.1t-r0 |
| Medium | GHSA-3f95-r44v-8mrg | simple-git | 3.3.0 |
| Medium | GHSA-9r2w-394v-53qc | tar | 6.1.7 |
| Medium | GHSA-hj9c-8jmm-8c52 | npm | 8.11.0 |
| Medium | GHSA-fwr7-v2mv-hh25 | async | 2.6.4 |
| Medium | ALPINE-CVE-2023-0464 | openssl | 1.1.1t-r1 |
| Medium | ALPINE-CVE-2021-44532 | nodejs | 14.19.0-r0 |
| Medium | GHSA-93q8-gq69-wqmw | ansi-regex | 3.0.1 |
| Medium | GHSA-9p95-fxvg-qgq2 | simple-git | 3.15.0 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 3.0.4 |
| Medium | ALPINE-CVE-2021-44533 | nodejs | 14.19.0-r0 |
| Medium | GHSA-j4f2-536g-r55m | engine.io | 3.6.0 |
| Medium | GHSA-4wf5-vphf-c2xc | terser | 4.8.1 |
| Medium | GHSA-74fj-2j2h-c42q | follow-redirects | 1.14.7 |
| Medium | GHSA-crh6-fp67-6883 | xmldom | no fix listed |
| Medium | GHSA-43fc-jf86-j433 | axios | 0.30.3 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| etherpadnicholaswildeVerified publisher | 1.0.2 | version-1.8.14 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.