ghcr.io/thm-mni-ii/fbs-identity-service:v2.0.1 container image
GitHub Container RegistryScanned 25 Sept 2026
Deployed by 1 of 17,844 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/thm-mni-ii/fbs-identity-service
ghcr.io/thm-mni-ii/fbs-identity-service:v2.0.1 resolved to baf79539e5df, scanned 25 Sept 2026: 159 findings, 0 critical; deployed by 1 chart, among them feedbacksystem.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
159 distinct on this digest
Findings for digest baf79539e5df as scanned on 25 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 25 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-67mf-3cr5-8w23 | bcprov-jdk18on | 1.78 |
| Low | GHSA-574f-3g2m-x479 | bcprov-jdk18on | 1.80.2 |
| Low | GHSA-m39w-hqxx-3r48 | spring-graphql | 1.4.6 |
| Low | GHSA-3pjw-73gf-8qr5 | jackson-databind | 2.21.4 |
| Low | GHSA-4cx2-fc23-5wg6 | bcpkix-jdk18on | 1.79 |
| Low | GHSA-hr8g-6v94-x4m9 | bcprov-jdk18on | 1.74 |
| Low | GHSA-3pjj-qpw6-5fcm | spring-security-saml2-service-provider | 6.5.11 |
| Low | GHSA-5gvw-p9qm-jgwh | jackson-databind | 2.21.5 |
| Low | UBUNTU-CVE-2026-89158 | pcre2 | no fix listed |
| Low | GHSA-3chg-m5w7-qfv5 | spring-webmvc | 6.2.19 |
| Low | GHSA-rcqc-6cw3-h962 | jackson-databind | 2.21.4 |
| Low | GHSA-jhq6-gfmj-v8fx | logback-core | 1.5.34 |
| Low | GHSA-5m4m-73w9-8433 | spring-data-commons | 3.5.12 |
| Low | UBUNTU-CVE-2026-76642 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-78408 | util-linux | no fix listed |
| Low | GHSA-72pg-x5f8-j25j | spring-webmvc | 6.2.19 |
| Low | GHSA-5vpf-xvv7-c8vh | spring-data-commons | 3.5.12 |
| Low | UBUNTU-CVE-2026-89161 | pcre2 | no fix listed |
| Low | UBUNTU-CVE-2026-35368 | rust-coreutils | no fix listed |
| Low | GHSA-mq64-j8f9-9gcj | spring-webmvc | 6.2.19 |
| Low | GHSA-wxpp-56q6-5pcg | spring-expression | 6.2.19 |
| Low | GHSA-x2r2-rvhq-2mqv | spring-security-web | 6.5.11 |
| Low | UBUNTU-CVE-2026-54369 | acl | no fix listed |
| Low | GHSA-9fxm-vc8v-hj55 | jackson-databind | 2.21.4 |
| Low | GHSA-5jmj-h7xm-6q6v | jackson-databind | 2.21.5 |
| Low | GHSA-r7wm-3cxj-wff9 | jackson-core | 2.21.4 |
| Low | UBUNTU-CVE-2026-89157 | pcre2 | no fix listed |
| Low | UBUNTU-CVE-2026-78410 | util-linux | no fix listed |
| Low | GHSA-293q-567p-wmwq | spring-security-web | 6.5.11 |
| Low | GHSA-5hh8-q8hv-fr38 | jackson-databind | 2.21.4 |
| Low | GHSA-4r8w-73jc-3m7q | spring-security-oauth2-authorization-server | 1.5.8 |
| Low | GHSA-hgj6-7826-r7m5 | jackson-databind | 2.21.4 |
| Low | UBUNTU-CVE-2026-78409 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-8674 | glibc | no fix listed |
| Low | UBUNTU-CVE-2026-35341 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-16599 | wget | no fix listed |
| Low | GHSA-957g-f97v-vppc | spring-webmvc | 6.2.19 |
| Low | UBUNTU-CVE-2026-93658 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-13757 | p11-kit | no fix listed |
| Low | GHSA-cjpg-rgq5-fr37 | spring-webmvc | 6.2.19 |
| Low | UBUNTU-CVE-2026-56403 | expat | 2.7.4-1ubuntu0.1 |
| Low | UBUNTU-CVE-2026-56404 | expat | 2.7.4-1ubuntu0.1 |
| Low | UBUNTU-CVE-2026-56405 | expat | 2.7.4-1ubuntu0.1 |
| Low | UBUNTU-CVE-2026-56408 | expat | 2.7.4-1ubuntu0.1 |
| Low | UBUNTU-CVE-2026-56406 | expat | 2.7.4-1ubuntu0.2 |
| Low | UBUNTU-CVE-2026-56407 | expat | 2.7.4-1ubuntu0.2 |
| Low | UBUNTU-CVE-2026-56410 | expat | 2.7.4-1ubuntu0.2 |
| Low | UBUNTU-CVE-2026-56411 | expat | 2.7.4-1ubuntu0.2 |
| Low | UBUNTU-CVE-2026-72522 | expat | 2.7.4-1ubuntu0.2 |
| Low | GHSA-7g45-4rm6-3mm3 | guava | 32.0.0-android |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| feedbacksystemthm-mni-iiVerified publisher | 0.48.0 | v2.0.1 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.