ghcr.io/open-telemetry/demo:1.12.0-loadgenerator container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/open-telemetry/demo
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator resolved to 85c9935ff31b, scanned 14 Sept 2026: 508 findings, 2 critical, 1 on KEV; deployed by 1 chart, among them opentelemetry-demo.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest 85c9935ff31b as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | PYSEC-2026-3554 | cryptography | 49.0.0 |
| Low | DEBIAN-CVE-2026-56000 | xorg-server | no fix listed |
| Low | DEBIAN-CVE-2025-40909 | perl | 5.36.0-7+deb12u3 |
| Low | GHSA-43qf-4rqw-9q2g | flask-cors | 6.0.0 |
| Low | DEBIAN-CVE-2025-62230 | xorg-server | 2:21.1.7-3+deb12u11 |
| Low | DEBIAN-CVE-2026-12318 | nss | 2:3.87.1-1+deb12u3 |
| Low | DEBIAN-CVE-2026-48961 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-63074 | openssl | no fix listed |
| Low | DEBIAN-CVE-2024-52616 | avahi | no fix listed |
| Low | DEBIAN-CVE-2025-14831 | gnutls28 | 3.7.9-2+deb12u6 |
| Low | DEBIAN-CVE-2026-6238 | glibc | no fix listed |
| Low | GHSA-34jh-p97f-mpxf | urllib3 | 2.2.2 |
| Low | GHSA-4xh5-x5gv-qwph | pip | 25.3 |
| Low | DEBIAN-CVE-2025-49177 | xorg-server | 2:21.1.7-3+deb12u10 |
| Low | DEBIAN-CVE-2026-25210 | expat | no fix listed |
| Low | DEBIAN-CVE-2025-65018 | libpng1.6 | 1.6.39-2+deb12u1 |
| Low | DEBIAN-CVE-2026-5435 | glibc | no fix listed |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | DEBIAN-CVE-2026-54369 | acl | no fix listed |
| Low | DEBIAN-CVE-2018-15853 | x11-xkb-utils | no fix listed |
| Low | DEBIAN-CVE-2018-15859 | x11-xkb-utils | no fix listed |
| Low | DEBIAN-CVE-2018-15861 | x11-xkb-utils | no fix listed |
| Low | DEBIAN-CVE-2018-15863 | x11-xkb-utils | no fix listed |
| Low | DEBIAN-CVE-2026-7017 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-16118 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2021-4214 | libpng1.6 | no fix listed |
| Low | DEBIAN-CVE-2026-54371 | attr | no fix listed |
| Low | GHSA-84pr-m4jr-85g5 | flask-cors | 4.0.1 |
| Low | DEBIAN-CVE-2025-0395 | glibc | 2.36-9+deb12u10 |
| Low | DEBIAN-CVE-2023-4039 | gcc-12 | 12.2.0-14+deb12u1 |
| Low | DEBIAN-CVE-2024-52615 | avahi | no fix listed |
| Low | DSA-5962-1 | gnutls28 | 3.7.9-2+deb12u5 |
| Low | DSA-5807-1 | nss | 2:3.87.1-1+deb12u1 |
| Low | DEBIAN-CVE-2025-4598 | systemd | 252.38-1~deb12u1 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | DEBIAN-CVE-2026-27447 | cups | no fix listed |
| Low | DEBIAN-CVE-2026-50259 | xorg-server | 2:21.1.7-3+deb12u13 |
| Low | GHSA-cpwx-vrp4-4pq7 | jinja2 | 3.1.6 |
| Low | DEBIAN-CVE-2026-50258 | xorg-server | 2:21.1.7-3+deb12u13 |
| Low | DEBIAN-CVE-2024-22365 | pam | 1.5.2-6+deb12u2 |
| Low | DEBIAN-CVE-2026-22796 | openssl | 3.0.18-1~deb12u2 |
| Low | DEBIAN-CVE-2026-50256 | xorg-server | 2:21.1.7-3+deb12u13 |
| Low | DEBIAN-CVE-2026-50260 | xorg-server | 2:21.1.7-3+deb12u13 |
| Low | DEBIAN-CVE-2026-50261 | xorg-server | 2:21.1.7-3+deb12u13 |
| Low | DEBIAN-CVE-2025-49175 | xorg-server | 2:21.1.7-3+deb12u10 |
| Low | DEBIAN-CVE-2024-26462 | krb5 | 1.20.1-2+deb12u3 |
| Low | DEBIAN-CVE-2026-22695 | libpng1.6 | 1.6.39-2+deb12u2 |
| Low | DEBIAN-CVE-2026-24401 | avahi | no fix listed |
| Low | GHSA-87hc-h4r5-73f7 | werkzeug | 3.1.5 |
| Low | DEBIAN-CVE-2022-0563 | util-linux | no fix listed |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| opentelemetry-demogpg-dev | 0.33.8 | 1.12.0-loadgenerator | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.