ghcr.io/project-zot/zot:v2.1.14 container image
GitHub Container RegistryScanned 28 Sept 2026
Deployed by 1 of 17,926 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/project-zot/zot
ghcr.io/project-zot/zot:v2.1.14 resolved to 4183bd731bcc, scanned 28 Sept 2026: 224 findings, 1 critical; deployed by 1 chart, among them litefunctions.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
224 distinct on this digest
Findings for digest 4183bd731bcc as scanned on 28 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 28 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-qw64-3x98-g7q2 | github.com/ | 5.9.0 |
| Low | DEBIAN-CVE-2026-6791 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-0861 | glibc | 2.36-9+deb12u14 |
| Low | GHSA-92mm-2pjq-r785 | github.com/ | 1.8.6 |
| Low | DEBIAN-CVE-2026-42766 | openssl | 3.0.20-1~deb12u2 |
| Low | GHSA-4vrq-3vrq-g6gg | github.com/ | 0.28.1 |
| Low | GHSA-pjcq-xvwq-hhpj | github.com/ | 0.1.1 |
| Low | DEBIAN-CVE-2025-15281 | glibc | 2.36-9+deb12u14 |
| Low | GHSA-33vj-92qq-66hc | github.com/ | 2.2.5 |
| Low | DEBIAN-CVE-2026-4437 | glibc | 2.36-9+deb12u14 |
| Low | DEBIAN-CVE-2026-5928 | glibc | no fix listed |
| Low | GHSA-jxpm-75mh-9fp7 | oras.land/ | 2.6.1 |
| Low | GHSA-47q9-m4ww-924m | github.com/ | 1.5.2 |
| Low | GHSA-4qg8-fj49-pxjh | github.com/ | 2.0.3 |
| Low | GHSA-mcj4-mphf-j9ff | github.com/ | 0.71.1 |
| Low | GHSA-8xwf-rjm4-xvhv | oras.land/ | 2.6.1 |
| Low | DEBIAN-CVE-2026-75803 | openssl | 3.0.22-1~deb12u1 |
| Low | GHSA-3p65-76g6-3w7r | github.com/ | 3.1.0 |
| Low | GHSA-p436-gjf2-799p | github.com/ | 29.2.0 |
| Low | GHSA-pxq6-2prw-chj9 | github.com/ | no fix listed |
| Low | GHSA-fxhp-mv3v-67qp | oras.land/ | 2.6.2 |
| Low | DEBIAN-CVE-2026-5435 | glibc | no fix listed |
| Low | GHSA-9c54-x2g4-v92j | github.com/ | no fix listed |
| Low | GHSA-m3xc-h892-ggx6 | github.com/ | 5.9.0 |
| Low | GHSA-85jx-fm8m-x8c6 | zotregistry.dev/ | 2.1.15 |
| Low | DEBIAN-CVE-2026-19499 | glibc | no fix listed |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | GHSA-hc8v-wwc9-vgxm | github.com/ | 5.19.2 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | DEBIAN-CVE-2026-6238 | glibc | no fix listed |
| Low | GHSA-pg57-6jwg-q645 | github.com/ | 2.2.9 |
| Low | GHSA-pg57-6jwg-q645 | github.com/ | 1.7.36 |
| Low | DEBIAN-CVE-2026-63074 | openssl | 3.0.22-1~deb12u1 |
| Low | GHSA-xhf5-7wjv-pqxp | github.com/ | 2.2.5 |
| Low | GHSA-xhf5-7wjv-pqxp | github.com/ | 1.7.33 |
| Low | GHSA-qgq7-7hm3-q39j | github.com/ | 5.19.2 |
| Low | GHSA-78mq-xcr3-xm33 | golang.org/ | 0.52.0 |
| Low | GHSA-q9hv-hpm4-hj6x | github.com/ | 1.6.3 |
| Low | GHSA-qvqc-4c52-x6qp | github.com/ | 0.11.5 |
| Low | GHSA-6pjf-3r9x-m592 | github.com/ | 3.1.1 |
| Low | DEBIAN-CVE-2026-42767 | openssl | 3.0.22-1~deb12u1 |
| Low | DEBIAN-CVE-2026-22796 | openssl | 3.0.18-1~deb12u2 |
| Low | DEBIAN-CVE-2026-77117 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-80489 | glibc | no fix listed |
| Low | GHSA-jpcc-p29g-p8mq | github.com/ | 2.2.5 |
| Low | GHSA-jpcc-p29g-p8mq | github.com/ | 1.7.33 |
| Low | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/ | 0.21.0 |
| Low | GHSA-hfvc-g4fc-pqhx | go.opentelemetry.io/ | 1.43.0 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GHSA-fqw6-gf59-qr4w | github.com/ | 2.2.4 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| litefunctionslitefunctions | 0.1.1 | v2.1.14 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.