ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/voxpupuli/container-puppetserver
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0 resolved to 916746209ac5, scanned 14 Sept 2026: 565 findings, 8 critical, 3 on KEV; deployed by 1 chart, among them puppetserver.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest 916746209ac5 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-70907 | openjdk-17 | no fix listed |
| Low | UBUNTU-CVE-2026-45446 | openssl | 3.0.2-0ubuntu1.25 |
| Low | UBUNTU-CVE-2026-22801 | libpng1.6 | 1.6.37-3ubuntu0.3 |
| Low | UBUNTU-CVE-2024-21210 | openjdk-17 | 17.0.13+11-2ubuntu1~22.04 |
| Low | UBUNTU-CVE-2024-21210 | openjdk-8 | 8u432-ga~us1-0ubuntu2~22.04 |
| Low | GHSA-25qh-j22f-pwp8 | logback-core | 1.3.16 |
| Low | UBUNTU-CVE-2026-58055 | nghttp2 | 1.43.0-1ubuntu0.4 |
| Low | UBUNTU-CVE-2025-29088 | sqlite3 | 3.37.2-2ubuntu0.4 |
| Low | UBUNTU-CVE-2024-21094 | openjdk-17 | 17.0.11+9-1~22.04.1 |
| Low | UBUNTU-CVE-2024-21094 | openjdk-8 | 8u412-ga-1~22.04.1 |
| Low | UBUNTU-CVE-2026-40225 | systemd | 249.11-0ubuntu3.19 |
| Low | UBUNTU-CVE-2026-3832 | gnutls28 | 3.7.3-4ubuntu1.9 |
| Low | UBUNTU-CVE-2025-58767 | ruby3.0 | no fix listed |
| Low | UBUNTU-CVE-2026-56409 | expat | no fix listed |
| Low | UBUNTU-CVE-2025-1390 | libcap2 | 1:2.44-1ubuntu0.22.04.2 |
| Low | UBUNTU-CVE-2026-50813 | sqlite3 | 3.37.2-2ubuntu0.7 |
| Low | UBUNTU-CVE-2026-13757 | p11-kit | 0.24.0-6ubuntu0.1 |
| Low | UBUNTU-CVE-2026-27447 | cups | 2.4.1op1-1ubuntu4.20 |
| Low | UBUNTU-CVE-2026-11850 | krb5 | 1.19.2-2ubuntu0.8 |
| Low | UBUNTU-CVE-2026-56132 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-34933 | avahi | 0.8-5ubuntu5.5 |
| Low | UBUNTU-CVE-2026-15588 | glib2.0 | no fix listed |
| Low | UBUNTU-CVE-2025-8058 | glibc | 2.35-0ubuntu3.11 |
| Low | UBUNTU-CVE-2026-41079 | cups | 2.4.1op1-1ubuntu4.20 |
| Low | UBUNTU-CVE-2026-40930 | libpng1.6 | 1.6.37-3ubuntu0.6 |
| Low | UBUNTU-CVE-2025-64506 | libpng1.6 | 1.6.37-3ubuntu0.1 |
| Low | UBUNTU-CVE-2025-45582 | tar | 1.34+dfsg-1ubuntu0.1.22.04.4 |
| Low | UBUNTU-CVE-2026-15534 | perl | 5.34.0-3ubuntu1.9 |
| Low | UBUNTU-CVE-2024-32020 | git | 1:2.34.1-1ubuntu1.11 |
| Low | UBUNTU-CVE-2025-58436 | cups | 2.4.1op1-1ubuntu4.16 |
| Low | UBUNTU-CVE-2025-59529 | avahi | no fix listed |
| Low | UBUNTU-CVE-2025-14017 | curl | 7.81.0-1ubuntu1.22 |
| Low | UBUNTU-CVE-2024-10041 | pam | no fix listed |
| Low | UBUNTU-CVE-2026-59850 | libssh | 0.9.6-2ubuntu0.22.04.8 |
| Low | UBUNTU-CVE-2025-0167 | curl | 7.81.0-1ubuntu1.23 |
| Low | UBUNTU-CVE-2026-50812 | sqlite3 | 3.37.2-2ubuntu0.7 |
| Low | UBUNTU-CVE-2025-68276 | avahi | 0.8-5ubuntu5.4 |
| Low | UBUNTU-CVE-2026-34757 | libpng1.6 | 1.6.37-3ubuntu0.5 |
| Low | UBUNTU-CVE-2026-87875 | cups | no fix listed |
| Low | GHSA-46q3-7gv7-qmgg | net-imap | 0.5.15 |
| Low | UBUNTU-CVE-2026-47242 | ruby3.0 | no fix listed |
| Low | UBUNTU-CVE-2026-18938 | p11-kit | 0.24.0-6ubuntu0.1 |
| Low | GHSA-wv3x-4vxv-whpp | concurrent-ruby | 1.3.7 |
| Low | UBUNTU-CVE-2026-21925 | openjdk-17 | 17.0.18+8-1~22.04.1 |
| Low | UBUNTU-CVE-2026-21925 | openjdk-8 | 8u482-ga~us1-0ubuntu1~22.04 |
| Low | UBUNTU-CVE-2025-27613 | git | 1:2.34.1-1ubuntu1.15 |
| Low | UBUNTU-CVE-2025-5278 | coreutils | 8.32-4.1ubuntu1.4 |
| Low | UBUNTU-CVE-2026-22795 | openssl | 3.0.2-0ubuntu1.21 |
| Low | UBUNTU-CVE-2026-42770 | openssl | 3.0.2-0ubuntu1.25 |
| Low | UBUNTU-CVE-2025-3360 | glib2.0 | 2.72.4-0ubuntu2.7 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| puppetserverpuppetserver | 9.5.2 | 7.17.0-v1.5.0 | 2 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.