StackRadar

ghcr.io/project-zot/zot:v2.1.14 container image

GitHub Container Registry

Scanned 28 Sept 2026

Deployed by 1 of 17,926 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/project-zot/zot

ghcr.io/project-zot/zot:v2.1.14 resolved to 4183bd731bcc, scanned 28 Sept 2026: 224 findings, 1 critical; deployed by 1 chart, among them litefunctions.

Radar Score

2,2731037186

224 findings on digest 4183bd731bcc · scanned 28 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v2.1.14resolves to4183bd731bcc1 charttoday10371862,273

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

224 distinct on this digest

Findings for digest 4183bd731bcc as scanned on 28 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 28 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGHSA-fqw6-gf59-qr4wgithub.com/containerd/containerd@v1.7.291.7.32
LowGHSA-fcv2-xgw5-pqxfgithub.com/sigstore/sigstore@v1.9.6-0.20250729224751-181c5d3339b31.10.4
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.47.00.52.0
LowGHSA-9m57-25v3-79x9golang.org/x/crypto@v0.47.00.52.0
LowGHSA-7236-3392-c5c6github.com/moby/buildkit@v0.26.20.31.1
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.78.01.82.1
LowDEBIAN-CVE-2025-27587openssl@3.0.18-1~deb12u1no fix listed
LowGHSA-cp6g-7hqx-qxhpgo.mongodb.org/mongo-driver@v1.17.61.17.7
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/service/s3@v1.92.11.97.3
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.7.31.7.8
LowGHSA-rgh6-rfwx-v388github.com/containerd/containerd/v2@v2.2.02.2.5
LowGHSA-x86f-5xw2-fm2rgithub.com/docker/docker@v28.5.2+incompatibleno fix listed
LowGHSA-8rc5-4fr6-64pwgithub.com/aquasecurity/trivy@v0.68.20.72.0
LowGHSA-9h8m-3fm2-qjrqgo.opentelemetry.io/otel/sdk@v1.38.01.40.0
LowGO-2026-4981stdlib@go1.25.61.25.10
LowGO-2026-4986stdlib@go1.25.61.25.10
LowGO-2026-4337stdlib@go1.25.61.24.13
LowGHSA-389r-gv7p-r3rpgithub.com/go-git/go-git/v5@v5.16.35.19.0
LowGHSA-crhj-59gh-8x96github.com/go-git/go-git/v5@v5.16.35.19.1
LowGO-2026-4601stdlib@go1.25.61.25.8
LowGO-2026-4977stdlib@go1.25.61.25.10
LowGHSA-7jxh-36q5-gcqvgithub.com/containerd/containerd@v1.7.291.7.35
LowGHSA-7jxh-36q5-gcqvgithub.com/containerd/containerd/v2@v2.2.02.2.8
LowDEBIAN-CVE-2026-8674glibc@2.36-9+deb12u13no fix listed
LowGO-2026-4918golang.org/x/net@v0.49.00.53.0
LowGO-2026-4918stdlib@go1.25.61.25.10
LowGO-2026-4947stdlib@go1.25.61.25.9
LowGO-2026-5026stdlib@go1.25.61.25.13
LowGO-2026-5026golang.org/x/net@v0.49.00.55.0
LowGO-2026-4870stdlib@go1.25.61.25.9
LowGO-2026-5942golang.org/x/net@v0.49.00.56.0
LowDEBIAN-CVE-2026-19542glibc@2.36-9+deb12u13no fix listed
LowDEBIAN-CVE-2026-4438glibc@2.36-9+deb12u132.36-9+deb12u14
LowGO-2026-4971stdlib@go1.25.61.25.10
LowGO-2026-5037stdlib@go1.25.61.25.11
LowGHSA-rg2x-37c3-w2rhgithub.com/docker/docker@v28.5.2+incompatibleno fix listed
LowGHSA-9vcr-p3rj-q5q6github.com/sigstore/sigstore-go@v1.1.31.2.0
LowGO-2026-5972stdlib@go1.25.61.25.13
LowGO-2026-6088stdlib@go1.25.61.25.13
LowGO-2026-6089stdlib@go1.25.61.25.13
LowGO-2026-6090stdlib@go1.25.61.25.13
LowGHSA-h7vf-4x9w-h99voras.land/oras-go/v2@v2.6.02.6.2
LowGO-2026-5038stdlib@go1.25.61.25.11
LowGO-2026-6218stdlib@go1.25.61.25.13
LowGHSA-vh4v-2xq2-g5cgoras.land/oras-go/v2@v2.6.02.6.1
LowGO-2026-6355golang.org/x/crypto@v0.47.00.56.0
LowGO-2026-5774github.com/go-chi/chi/v5@v5.2.45.3.0
LowDEBIAN-CVE-2026-86805glibc@2.36-9+deb12u13no fix listed
LowGO-2026-5970golang.org/x/text@v0.33.00.39.0
LowGHSA-w8rr-5gcm-pp58go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.38.01.43.0

Used by

1 chart
ChartVersionTagContainers
litefunctionslitefunctions0.1.1v2.1.141

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 28 Sept 2026 · advisories as of 28 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.