ghcr.io/open-telemetry/demo:3.1.0-fraud-detection container image
GitHub Container RegistryScanned 19 Sept 2026
Deployed by 1 of 17,805 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/open-telemetry/demo
ghcr.io/open-telemetry/demo:3.1.0-fraud-detection resolved to a07ee694304b, scanned 19 Sept 2026: 125 findings, 0 critical; deployed by 1 chart, among them opentelemetry-demo.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
125 distinct on this digest
Findings for digest a07ee694304b as scanned on 19 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 19 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | DEBIAN-CVE-2019-1010022 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2023-45853 | zlib | no fix listed |
| Medium | DEBIAN-CVE-2018-20796 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2019-1010023 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2019-9192 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2012-0039 | glib2.0 | no fix listed |
| Medium | DEBIAN-CVE-2024-28757 | expat | no fix listed |
| Medium | DEBIAN-CVE-2023-25193 | harfbuzz | no fix listed |
| Medium | DEBIAN-CVE-2025-59375 | expat | no fix listed |
| Medium | DEBIAN-CVE-2019-1010024 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2026-5450 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2026-33416 | libpng1.6 | 1.6.39-2+deb12u4 |
| Medium | DEBIAN-CVE-2026-58016 | glib2.0 | no fix listed |
| Medium | DEBIAN-CVE-2025-29070 | lcms2 | no fix listed |
| Medium | DEBIAN-CVE-2026-66046 | expat | no fix listed |
| Medium | DEBIAN-CVE-2019-1010025 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-33636 | libpng1.6 | 1.6.39-2+deb12u4 |
| Low | DEBIAN-CVE-2026-22016 | openjdk-17 | 17.0.19+10-1~deb12u2 |
| Low | DEBIAN-CVE-2026-58015 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2026-58013 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2026-58010 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2026-58012 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2026-34282 | openjdk-17 | 17.0.19+10-1~deb12u2 |
| Low | DEBIAN-CVE-2026-0915 | glibc | 2.36-9+deb12u14 |
| Low | DEBIAN-CVE-2026-58014 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2026-85091 | zlib | no fix listed |
| Low | GHSA-c4c3-7fpv-j4q5 | netty-handler | 4.2.17.Final |
| Low | DEBIAN-CVE-2026-0861 | glibc | 2.36-9+deb12u14 |
| Low | DEBIAN-CVE-2025-15281 | glibc | 2.36-9+deb12u14 |
| Low | DEBIAN-CVE-2026-86145 | pcre2 | 10.42-1+deb12u1 |
| Low | DEBIAN-CVE-2026-58011 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2026-45186 | expat | no fix listed |
| Low | DEBIAN-CVE-2026-19499 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-4046 | glibc | 2.36-9+deb12u14 |
| Low | DEBIAN-CVE-2026-5928 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-41254 | openjdk-17 | 17.0.20+8-1~deb12u1 |
| Low | DEBIAN-CVE-2026-41254 | lcms2 | 2.14-2+deb12u1 |
| Low | DEBIAN-CVE-2026-6791 | glibc | no fix listed |
| Low | DEBIAN-CVE-2022-27943 | gcc-12 | no fix listed |
| Low | DEBIAN-CVE-2026-4437 | glibc | 2.36-9+deb12u14 |
| Low | GHSA-xx22-p4ch-683r | lz4-java | 1.11.1 |
| Low | GHSA-fccg-mwvh-qqg4 | netty-handler | 4.2.17.Final |
| Low | DEBIAN-CVE-2026-76642 | util-linux | no fix listed |
| Low | DEBIAN-CVE-2026-47063 | openjdk-17 | 17.0.20+8-1~deb12u1 |
| Low | DEBIAN-CVE-2026-6238 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-61308 | openjdk-17 | 17.0.20.1+1-1~deb12u1 |
| Low | DEBIAN-CVE-2026-25210 | expat | no fix listed |
| Low | DEBIAN-CVE-2026-5435 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-16118 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2021-4214 | libpng1.6 | no fix listed |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| opentelemetry-demoopentelemetry-helmOfficialVerified publisher | 0.42.0 | 3.1.0-fraud-detection | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.