ghcr.io/plausible/community-edition:v3.0.1 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/plausible/community-edition
ghcr.io/plausible/community-edition:v3.0.1 resolved to 14c1afde21d6, scanned 14 Sept 2026: 94 findings, 1 critical; deployed by 1 chart, among them plausible-analytics.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
94 distinct on this digest
Findings for digest 14c1afde21d6 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2025-6965 | sqlite | 3.48.0-r3 |
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| Medium | ALPINE-CVE-2026-21441 | py3-urllib3 | 1.26.20-r1 |
| Medium | GHSA-38jv-5279-wg99 | urllib3 | 2.6.3 |
| Medium | ALPINE-CVE-2025-4517 | python3 | 3.12.11-r0 |
| Medium | PYSEC-2025-49 | setuptools | 78.1.1 |
| Medium | ALPINE-CVE-2025-3277 | sqlite | 3.48.0-r1 |
| Medium | PYSEC-2026-2269 | pyopenssl | 26.0.0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2025-4138 | python3 | 3.12.11-r0 |
| Medium | ALPINE-CVE-2025-59375 | expat | 2.7.2-r0 |
| Medium | GHSA-2xpw-w6gg-jr37 | urllib3 | 2.6.0 |
| Medium | GHSA-gm62-xv2j-4w53 | urllib3 | 2.6.0 |
| Medium | ALPINE-CVE-2026-6100 | python3 | 3.12.14-r0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2025-4330 | python3 | 3.12.11-r0 |
| Medium | ALPINE-CVE-2026-66046 | expat | 2.8.4-r0 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-11940 | python3 | 3.12.14-r0 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.3.7-r0 |
| Low | ALPINE-CVE-2025-69420 | openssl | 3.3.6-r0 |
| Low | ALPINE-CVE-2026-7210 | python3 | 3.12.14-r0 |
| Low | ALPINE-CVE-2026-15308 | python3 | 3.12.14-r0 |
| Low | ALPINE-CVE-2026-11972 | python3 | 3.12.14-r0 |
| Low | ALPINE-CVE-2026-76641 | expat | 2.8.4-r0 |
| Low | ALPINE-CVE-2026-31789 | openssl | 3.3.7-r0 |
| Low | ALPINE-CVE-2025-69419 | openssl | 3.3.6-r0 |
| Low | ALPINE-CVE-2025-29087 | sqlite | 3.48.0-r1 |
| Low | ALPINE-CVE-2026-3644 | python3 | 3.12.14-r0 |
| Low | ALPINE-CVE-2026-22184 | zlib | 1.3.2-r0 |
| Low | ALPINE-CVE-2026-45186 | expat | 2.8.1-r0 |
| Low | GHSA-r6ph-v2qm-q3c2 | cryptography | 46.0.5 |
| Low | GHSA-jwv3-5hgf-82ww | cryptography | 49.0.0 |
| Low | ALPINE-CVE-2025-15468 | openssl | 3.3.6-r0 |
| Low | ALPINE-CVE-2024-47081 | py3-requests | 2.32.4-r0 |
| Low | GHSA-9hjg-9r4m-mvj7 | requests | 2.32.4 |
| Low | ALPINE-CVE-2026-76956 | expat | 2.8.4-r0 |
| Low | ALPINE-CVE-2024-12718 | python3 | 3.12.11-r0 |
| Low | PYSEC-2026-3554 | cryptography | 49.0.0 |
| Low | ALPINE-CVE-2026-1502 | python3 | 3.12.14-r0 |
| Low | ALPINE-CVE-2026-4786 | python3 | 3.12.14-r0 |
| Low | GHSA-g6cj-pr64-35w5 | cryptography | 50.0.0 |
| Low | ALPINE-CVE-2026-25210 | expat | 2.7.4-r0 |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.5-r11 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| plausible-analyticsimioVerified publisher | 0.4.2 | v3.0.1 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.