ghcr.io/wbstack/queryservice:0.3.6_0.6 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/wbstack/queryservice
ghcr.io/wbstack/queryservice:0.3.6_0.6 resolved to b83b5b81d4b6, scanned 14 Sept 2026: 164 findings, 5 critical, 1 on KEV; deployed by 1 chart, among them queryservice.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest b83b5b81d4b6 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-p2v9-g2qv-p635 | netty | no fix listed |
| Medium | GHSA-cmfg-87vq-g5g4 | jackson-databind | 2.9.9.1 |
| Medium | GHSA-7vx9-xjhr-rw6h | jetty-server | 9.4.16.v20190411 |
| Medium | ALPINE-CVE-2019-1551 | openssl | 1.1.1d-r2 |
| Medium | GHSA-95cm-88f5-f2c7 | jackson-databind | 2.9.10.4 |
| Medium | GHSA-57j2-w4cx-62h2 | jackson-databind | 2.12.6.1 |
| Medium | GHSA-27xj-rqx5-2255 | jackson-databind | 2.9.10.4 |
| Medium | ALPINE-CVE-2020-28196 | krb5 | 1.15.5-r1 |
| Medium | GHSA-7rp6-w7mg-h8rw | jena-core | 4.2.0 |
| Medium | ALPINE-CVE-2020-11655 | sqlite | 3.28.0-r3 |
| Medium | GHSA-rpr3-cw39-3pxh | jackson-databind | 2.9.10.4 |
| Medium | GHSA-qmqc-x3r4-6v39 | jackson-databind | 2.9.10 |
| Medium | ALPINE-CVE-2020-8231 | curl | 7.66.0-r5 |
| Medium | ALPINE-CVE-2021-23841 | openssl | 1.1.1j-r0 |
| Medium | GHSA-g3wg-6mcf-8jj6 | jetty-webapp | 9.4.33.v20201020 |
| Medium | ALPINE-CVE-2020-1971 | openssl | 1.1.1i-r0 |
| Medium | ALPINE-CVE-2019-19244 | sqlite | 3.28.0-r2 |
| Medium | GHSA-7r82-7xv7-xcpj | httpclient | 4.5.13 |
| Medium | GHSA-vx85-mj8c-4qm6 | libthrift | 0.12.0 |
| Medium | GHSA-h4x4-5qp2-wp46 | jackson-datatype-jsr310 | 2.9.8 |
| Medium | GHSA-668q-qrv7-99fm | logback-core | 1.2.9 |
| Medium | GHSA-jjjh-jjxp-wpff | jackson-databind | 2.12.7.1 |
| Medium | GHSA-rgv9-q543-rqg4 | jackson-databind | 2.12.7.1 |
| Medium | ALPINE-CVE-2019-16168 | sqlite | 3.28.0-r1 |
| Medium | ALPINE-CVE-2019-2201 | libjpeg-turbo | 1.5.3-r6 |
| Medium | GHSA-gwrp-pvrq-jmwv | commons-io | 2.7 |
| Medium | GHSA-mvr2-9pj6-7w5j | guava | 24.1.1-android |
| Medium | GHSA-f256-j965-7f32 | netty | no fix listed |
| Medium | ALPINE-CVE-2019-1549 | openssl | 1.1.1d-r0 |
| Medium | GHSA-86wm-rrjm-8wh8 | jetty-server | 9.4.35.v20201120 |
| Medium | GHSA-xc67-hjx6-cgg6 | jetty-server | 9.4.17.v20190418 |
| Medium | ALPINE-CVE-2018-14498 | libjpeg-turbo | 1.5.3-r5 |
| Medium | GHSA-wx5j-54mm-rqqq | netty | no fix listed |
| Medium | GHSA-x27m-9w8j-5vcw | jettison | 1.5.2 |
| Medium | GHSA-pvp8-3xj6-8c6x | commons-configuration | no fix listed |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang | no fix listed |
| Medium | GHSA-r28m-g6j9-r2h5 | jetty-server | 9.4.17.v20190418 |
| Medium | GHSA-7rf3-mqpx-h7xg | jettison | 1.5.2 |
| Medium | GHSA-grr4-wv38-f68w | jettison | 1.5.2 |
| Medium | GHSA-78wr-2p64-hpwj | commons-io | 2.14.0 |
| Medium | GHSA-355h-qmc2-wpwf | jetty-http | 9.4.60 |
| Medium | ALPINE-CVE-2019-19242 | sqlite | 3.28.0-r2 |
| Medium | GHSA-qw69-rqj8-6qw8 | jetty-server | 9.4.51.v20230217 |
| Medium | ALPINE-CVE-2019-5094 | e2fsprogs | 1.44.5-r1 |
| Medium | GHSA-56h3-78gp-v83r | jettison | 1.5.1 |
| Medium | GHSA-h46c-h94j-95f3 | jackson-core | 2.15.0 |
| Medium | GHSA-q6g2-g7f3-rr83 | jettison | 1.5.4 |
| Medium | GHSA-5mcr-gq6c-3hq2 | netty | no fix listed |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| queryservicewbstack | 0.2.1 | 0.3.6_0.6 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.