ghcr.io/wundergraph/cosmo/controlplane:0.133.1 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/wundergraph/cosmo/controlplane
ghcr.io/wundergraph/cosmo/controlplane:0.133.1 resolved to 49800ff775f3, scanned 14 Sept 2026: 288 findings, 0 critical; deployed by 1 chart, among them cosmo.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
288 distinct on this digest
Findings for digest 49800ff775f3 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| High | GHSA-v23v-6jw2-98fq | github.com/ | 26.1.5 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | GHSA-v778-237x-gjrc | golang.org/ | 0.31.0 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 4.0.4 |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | GHSA-43fc-jf86-j433 | axios | 1.13.5 |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.3.5-r0 |
| Medium | GHSA-rf6f-7fwh-wjgh | flatted | 3.4.2 |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.3.5-r0 |
| Medium | GO-2026-4887 | github.com/ | no fix listed |
| Medium | GHSA-3h5v-q93c-6h6q | ws | 8.17.1 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | GHSA-vrm6-8vpv-qv8q | undici | 6.24.0 |
| Medium | GHSA-4hjh-wcwx-xvwj | axios | 1.12.0 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.3.7-r0 |
| Medium | GHSA-f6v4-cf5j-vf3w | dset | 3.1.4 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.3.5-r0 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | GHSA-hcg3-q754-cr77 | golang.org/ | 0.35.0 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.3.7-r0 |
| Medium | GHSA-m7jm-9gc2-mpf2 | fast-xml-parser | 4.5.4 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | GHSA-v9p9-hfj2-hcw8 | undici | 6.24.0 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 1.16.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.3.7-r0 |
| Medium | GHSA-jmr7-xgp7-cmfj | fast-xml-parser | 4.5.4 |
| Medium | GHSA-96hv-2xvq-fx4p | ws | 8.21.0 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 9.0.6 |
| Medium | GHSA-25h7-pfq9-p65f | flatted | 3.4.0 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.3.7-r0 |
| Medium | GHSA-pf86-5x62-jrwf | axios | 1.15.1 |
| Medium | GHSA-jx2c-rxcm-jvmq | fastify | 5.7.2 |
| Low | ALPINE-CVE-2025-69420 | openssl | 3.3.6-r0 |
| Low | GHSA-vxpw-j846-p89q | undici | 6.27.0 |
| Low | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Low | GHSA-62hf-57xw-28j9 | axios | 1.15.1 |
| Low | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Low | GHSA-34x7-hfp2-rc4v | tar | 7.5.7 |
| Low | GHSA-q8qp-cvcw-x6jj | axios | 1.15.2 |
| Low | GHSA-3g43-6gmg-66jw | axios | 1.15.2 |
| Low | GHSA-rrr8-f88r-h8q6 | find-my-way | 8.2.2 |