ghcr.io/nicholaswilde/etherpad:version-1.8.14 container image
GitHub Container RegistryScanned 20 Sept 2026
Deployed by 1 of 17,813 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/nicholaswilde/etherpad
ghcr.io/nicholaswilde/etherpad:version-1.8.14 resolved to 26bbd45110d5, scanned 20 Sept 2026: 211 findings, 2 critical; deployed by 1 chart, among them etherpad.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
211 distinct on this digest
Findings for digest 26bbd45110d5 as scanned on 20 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 20 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-677m-j7p3-52f9 | socket.io-parser | 3.4.4 |
| Low | GHSA-vcc3-ghjq-m6fr | decode-uri-component | 0.5.0 |
| Low | GHSA-rhx6-c78j-4q9w | path-to-regexp | 0.1.12 |
| Low | GHSA-hj48-42vr-x3v9 | path-parse | 1.0.7 |
| Low | GHSA-2h3h-q99f-3fhc | @npmcli/ | 2.8.2 |
| Low | GHSA-62hf-57xw-28j9 | axios | 0.31.1 |
| Low | GHSA-34x7-hfp2-rc4v | tar | 7.5.7 |
| Low | GHSA-x6wf-f3px-wcqx | xmldom | no fix listed |
| Low | GHSA-gmw6-94gg-2rc2 | @npmcli/ | 2.8.2 |
| Low | GHSA-hfxv-24rg-xrqf | axios | 0.32.0 |
| Low | GHSA-j5f8-grm9-p9fc | axios | 0.32.0 |
| Low | GHSA-3g43-6gmg-66jw | axios | 0.31.1 |
| Low | GHSA-cxjh-pqwp-8mfp | follow-redirects | 1.15.6 |
| Low | ALPINE-CVE-2021-39134 | nodejs | 14.17.6-r0 |
| Low | GHSA-2jp7-wwpg-3p9w | ep_etherpad-lite | 3.3.0 |
| Low | GHSA-mh99-v99m-4gvg | brace-expansion | 1.1.17 |
| Low | GHSA-25hc-qcg6-38wj | socket.io | 2.5.1 |
| Low | GHSA-rgw5-rvv9-x895 | brace-expansion | 1.1.18 |
| Low | ALPINE-CVE-2021-39135 | nodejs | 14.17.6-r0 |
| Low | GHSA-pw2r-vq6v-hr8c | follow-redirects | 1.14.8 |
| Low | GHSA-f5x3-32g6-xq36 | tar | 6.2.1 |
| Low | GHSA-8cf7-32gw-wr33 | jsonwebtoken | 9.0.0 |
| Low | GHSA-pmwg-cvhr-8vh7 | axios | 0.31.1 |
| Low | GHSA-qffp-2rhf-9h96 | tar | 7.5.10 |
| Low | GHSA-j759-j44w-7fr8 | xmldom | no fix listed |
| Low | ALPINE-CVE-2023-0465 | openssl | 1.1.1t-r2 |
| Low | GHSA-23hp-3jrh-7fpw | tar | 7.5.19 |
| Low | GHSA-93r5-fhx6-vmg9 | xmldom | no fix listed |
| Low | GHSA-965w-775f-mr7g | xmldom | no fix listed |
| Low | GHSA-52cp-r559-cp3m | js-yaml | 4.3.0 |
| Low | GHSA-27p8-2357-5qqv | xmldom | no fix listed |
| Low | GHSA-4w3w-2rp5-g8jm | xmldom | no fix listed |
| Low | GHSA-c7q8-3ch8-vqpv | xmldom | no fix listed |
| Low | GHSA-w2rr-34g9-rvrj | xmldom | no fix listed |
| Low | GHSA-8344-3jmq-59r6 | xmldom | no fix listed |
| Low | GHSA-hmw2-7cc7-3qxx | form-data | 3.0.5 |
| Low | GHSA-7r86-cg39-jmmj | minimatch | 3.1.3 |
| Low | GHSA-2m8v-j782-fhvr | socket.io-parser | 3.4.5 |
| Low | GHSA-8qq5-rm4j-mr97 | tar | 7.5.3 |
| Low | GHSA-776f-qx25-q3cc | xml2js | 0.5.0 |
| Low | GHSA-fvcv-3m26-pcqx | axios | 0.31.0 |
| Low | GHSA-73rr-hh4g-fpgx | diff | 5.2.2 |
| Low | GHSA-23c5-xmqv-rm74 | minimatch | 3.1.4 |
| Low | GHSA-wh4c-j3r5-mjhp | xmldom | no fix listed |
| Low | GHSA-qpx9-hpmf-5gmw | underscore | 1.13.8 |
| Low | GHSA-8x88-c5mf-7j5w | tar | 7.5.18 |
| Low | GHSA-jchw-25xp-jwwc | follow-redirects | 1.15.4 |
| Low | GHSA-rv95-896h-c2vc | express | 4.19.2 |
| Low | GHSA-r6q2-hw4h-h46w | tar | 7.5.4 |
| Low | GHSA-7q85-xj36-vmfc | adm-zip | 0.6.1 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| etherpadnicholaswildeVerified publisher | 1.0.2 | version-1.8.14 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.