ghcr.io/wbstack/queryservice:0.3.6_0.6 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/wbstack/queryservice
ghcr.io/wbstack/queryservice:0.3.6_0.6 resolved to b83b5b81d4b6, scanned 14 Sept 2026: 164 findings, 5 critical, 1 on KEV; deployed by 1 chart, among them queryservice.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
164 distinct on this digest
Findings for digest b83b5b81d4b6 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-5949-rw7g-wx7w | jackson-databind | 2.9.10.7 |
| Medium | GHSA-qjw2-hr98-qgfh | jackson-databind | 2.9.10.6 |
| Medium | GHSA-wm47-8v5p-wjpj | netty | no fix listed |
| Medium | GHSA-rj7p-rfgp-852x | libthrift | 0.13.0 |
| Medium | GHSA-w3f4-3q6j-rh82 | jackson-databind | 2.7.9.5 |
| Medium | ALPINE-CVE-2019-5018 | sqlite | 3.28.0-r0 |
| Medium | GHSA-p979-4mfw-53vg | netty | no fix listed |
| Medium | GHSA-wjxj-f8rg-99wx | libthrift | 0.12.0 |
| Medium | GHSA-cjjf-94ff-43w7 | jackson-databind | 2.7.9.4 |
| Medium | GHSA-h4rc-386g-6m85 | jackson-databind | 2.9.10.4 |
| Medium | GHSA-g2fg-mr77-6vrm | libthrift | 0.14.0 |
| Medium | GHSA-9vjp-v76f-g363 | netty | no fix listed |
| Medium | GHSA-8w26-6f25-cm9x | jackson-databind | 2.9.10.8 |
| Medium | GHSA-v585-23hc-c647 | jackson-databind | 2.9.10.8 |
| Medium | GHSA-r695-7vr9-jgc2 | jackson-databind | 2.9.10.8 |
| Medium | GHSA-8c4j-34r4-xr8g | jackson-databind | 2.9.10.8 |
| Medium | GHSA-89qr-369f-5m5x | jackson-databind | 2.9.10.8 |
| Medium | GHSA-cvm9-fjm9-3572 | jackson-databind | 2.9.10.8 |
| Medium | GHSA-vfqx-33qm-g869 | jackson-databind | 2.9.10.8 |
| Medium | GHSA-9m6f-7xcq-8vf8 | jackson-databind | 2.9.10.8 |
| Medium | ALPINE-CVE-2019-14697 | musl | 1.1.20-r5 |
| Medium | GHSA-58pp-9c76-5625 | jackson-databind | 2.9.10.4 |
| Medium | GHSA-grg4-wf29-r9vv | netty | no fix listed |
| Medium | GHSA-rf6r-2c4q-2vwg | jackson-databind | 2.9.10.4 |
| Medium | GHSA-v3xw-c963-f5hc | jackson-databind | 2.9.10.4 |
| Medium | GHSA-758m-v56v-grj4 | jackson-databind | 2.9.10.4 |
| Medium | GHSA-mc6h-4qgp-37qh | jackson-databind | 2.9.10.5 |
| Medium | GHSA-cf6r-3wgc-h863 | jackson-databind | 2.9.10 |
| Medium | GHSA-c2q3-4qrh-fm48 | jackson-databind | 2.9.10.5 |
| Medium | GHSA-p2v9-g2qv-p635 | netty | no fix listed |
| Medium | GHSA-cmfg-87vq-g5g4 | jackson-databind | 2.9.9.1 |
| Medium | GHSA-7vx9-xjhr-rw6h | jetty-server | 9.4.16.v20190411 |
| Medium | ALPINE-CVE-2019-1551 | openssl | 1.1.1d-r2 |
| Medium | GHSA-95cm-88f5-f2c7 | jackson-databind | 2.9.10.4 |
| Medium | GHSA-57j2-w4cx-62h2 | jackson-databind | 2.12.6.1 |
| Medium | GHSA-27xj-rqx5-2255 | jackson-databind | 2.9.10.4 |
| Medium | ALPINE-CVE-2020-28196 | krb5 | 1.15.5-r1 |
| Medium | GHSA-7rp6-w7mg-h8rw | jena-core | 4.2.0 |
| Medium | ALPINE-CVE-2020-11655 | sqlite | 3.28.0-r3 |
| Medium | GHSA-rpr3-cw39-3pxh | jackson-databind | 2.9.10.4 |
| Medium | GHSA-qmqc-x3r4-6v39 | jackson-databind | 2.9.10 |
| Medium | ALPINE-CVE-2020-8231 | curl | 7.66.0-r5 |
| Medium | ALPINE-CVE-2021-23841 | openssl | 1.1.1j-r0 |
| Medium | GHSA-g3wg-6mcf-8jj6 | jetty-webapp | 9.4.33.v20201020 |
| Medium | ALPINE-CVE-2020-1971 | openssl | 1.1.1i-r0 |
| Medium | ALPINE-CVE-2019-19244 | sqlite | 3.28.0-r2 |
| Medium | GHSA-7r82-7xv7-xcpj | httpclient | 4.5.13 |
| Medium | GHSA-vx85-mj8c-4qm6 | libthrift | 0.12.0 |
| Medium | GHSA-h4x4-5qp2-wp46 | jackson-datatype-jsr310 | 2.9.8 |
| Medium | GHSA-668q-qrv7-99fm | logback-core | 1.2.9 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| queryservicewbstack | 0.2.1 | 0.3.6_0.6 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.