StackRadar

ghcr.io/papra-hq/papra:26.6.2-rootless container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/papra-hq/papra

ghcr.io/papra-hq/papra:26.6.2-rootless resolved to a281cb44176d, scanned 14 Sept 2026: 273 findings, 0 critical; deployed by 1 chart, among them papra.

Radar Score

2,5380018255

273 findings on digest a281cb44176d · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
26.6.2-rootlessresolves toa281cb44176d1 chart2 days ago00182552,538

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Low findings

255 distinct on this digest

Low: findings whose contribution to the Radar Score is 1–14. Show every band

Findings for digest a281cb44176d as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGO-2024-2600stdlib@go1.20.71.21.8
LowGHSA-28wg-ghj8-5hjvnanoid@3.3.113.3.16
LowGO-2024-2609stdlib@go1.20.71.21.8
LowDEBIAN-CVE-2026-34743xz-utils@5.8.1-15.8.1-1+deb13u1
LowGO-2024-3107stdlib@go1.20.71.22.7
LowDEBIAN-CVE-2026-5704tar@1.35+dfsg-3.1no fix listed
LowGHSA-2v37-7h3g-55p8nanoid@3.3.113.3.18
LowDEBIAN-CVE-2026-3184util-linux@2.41-5no fix listed
LowGHSA-jr45-8vmc-qm54undici@8.5.08.9.0
LowDEBIAN-CVE-2026-7010perl@5.40.1-65.40.1-6+deb13u1
LowDEBIAN-CVE-2026-19487perl@5.40.1-6no fix listed
LowGHSA-mh29-5h37-fv8mjs-yaml@3.14.13.14.2
LowDEBIAN-CVE-2026-89158pcre2@10.46-1~deb13u110.46-1~deb13u2
LowGO-2023-2041stdlib@go1.20.71.20.8
LowGO-2023-2043stdlib@go1.20.71.20.8
LowDEBIAN-CVE-2013-4392systemd@257.13-1~deb13u1no fix listed
LowGO-2023-2186stdlib@go1.20.71.20.11
LowGHSA-g6gw-c38x-mqfchono@4.12.274.13.5
LowGHSA-h67p-54hq-rp68js-yaml@3.14.13.15.0
LowDEBIAN-CVE-2026-78408util-linux@2.41-5no fix listed
LowGHSA-3jxr-9vmj-r5cpbrace-expansion@2.1.12.1.2
LowGO-2024-3105stdlib@go1.20.71.22.7
LowGHSA-q8mj-m7cp-5q26qs@6.14.06.15.2
LowGHSA-p88m-4jfj-68fvundici@6.26.06.27.0
LowGO-2026-4981stdlib@go1.20.71.25.10
LowDEBIAN-CVE-2023-31439systemd@257.13-1~deb13u1no fix listed
LowGO-2025-3563stdlib@go1.20.71.23.8
LowGHSA-vmf3-w455-68vhtar@7.5.27.5.16
LowGO-2026-4977stdlib@go1.20.71.25.10
LowGO-2024-2610stdlib@go1.20.71.21.8
LowDEBIAN-CVE-2023-31437systemd@257.13-1~deb13u1no fix listed
LowGO-2026-4986stdlib@go1.20.71.25.10
LowGO-2026-4918stdlib@go1.20.71.25.10
LowGO-2026-4337stdlib@go1.20.71.24.13
LowDEBIAN-CVE-2023-31438systemd@257.13-1~deb13u1no fix listed
LowGO-2026-4601stdlib@go1.20.71.25.8
LowGHSA-qx2v-qp2m-jg93postcss@8.4.498.5.10
LowDEBIAN-CVE-2026-78410util-linux@2.41-5no fix listed
LowDEBIAN-CVE-2026-89161pcre2@10.46-1~deb13u110.46-1~deb13u2
LowGO-2026-5026stdlib@go1.20.71.25.13
LowDEBIAN-CVE-2025-14104util-linux@2.41-52.41.3-1
LowGHSA-54fx-42gc-7vw4hono@4.12.274.12.34
LowGO-2025-3420stdlib@go1.20.71.22.11
LowGO-2026-4342stdlib@go1.20.71.24.12
LowGO-2024-2598stdlib@go1.20.71.21.8
LowGO-2025-3751stdlib@go1.20.71.23.10
LowDEBIAN-CVE-2026-78409util-linux@2.41-5no fix listed
LowGHSA-2x7j-588g-ccc2nodemailer@9.0.19.1.0
LowGHSA-5p4m-2wfm-xmqjjs-yaml@3.14.13.15.1
LowGO-2026-4870stdlib@go1.20.71.25.9

Used by

1 chart
ChartVersionTagContainers
paprahelmforgeVerified publisher1.0.026.6.2-rootless2

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.