ghcr.io/umami-software/umami:3.1.0 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/umami-software/umami
ghcr.io/umami-software/umami:3.1.0 resolved to e3f80c0625aa, scanned 14 Sept 2026: 179 findings, 0 critical; deployed by 1 chart, among them umami.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
179 distinct on this digest
Findings for digest e3f80c0625aa as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | GHSA-c4j6-fc7j-m34r | next | 16.2.5 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | GHSA-p293-qw3h-jr36 | next | 16.3.3 |
| Medium | ALPINE-CVE-2026-19931 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-9079 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-10536 | curl | 8.22.0-r0 |
| Medium | GHSA-m99w-x7hq-7vfj | next | 16.2.11 |
| Medium | ALPINE-CVE-2026-18924 | curl | 8.22.0-r0 |
| Medium | GHSA-267c-6grr-h53f | next | 16.2.5 |
| Medium | ALPINE-CVE-2026-11856 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-8925 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | GHSA-6gpp-xcg3-4w24 | next | 16.2.11 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | GHSA-89xv-2m56-2m9x | next | 16.2.11 |
| Medium | ALPINE-CVE-2026-42764 | openssl | 3.5.7-r0 |
| Medium | GHSA-p9j2-gv94-2wf4 | next | 16.2.11 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | GHSA-w7jw-789q-3m8p | shell-quote | 1.8.4 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-8924 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-80231 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-80229 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-8927 | curl | 8.22.0-r0 |
| Medium | GHSA-hwx4-2j3j-g496 | pnpm | 10.34.0 |
| Medium | GHSA-492v-c6pp-mqqv | next | 16.2.5 |
| Low | ALPINE-CVE-2026-8926 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-27135 | nghttp2 | 1.68.1 |
| Low | GHSA-mg66-mrh9-m8jx | next | 16.2.5 |
| Low | ALPINE-CVE-2026-3805 | curl | 8.19.0-r0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-9076 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-82209 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-80255 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-11564 | curl | 8.22.0-r0 |
| Low | GHSA-rgw5-rvv9-x895 | brace-expansion | 2.1.4 |
| Low | GHSA-36qx-fr4f-26g5 | next | 16.2.5 |
| Low | ALPINE-CVE-2026-13608 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-5773 | curl | 8.20.0-r0 |
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | GHSA-ggr8-5vv4-36mx | deepmerge-ts | 8.0.0 |
| Low | ALPINE-CVE-2026-11586 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-45445 | openssl | 3.5.7-r0 |