ghcr.io/wundergraph/cosmo/controlplane:0.133.1 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/wundergraph/cosmo/controlplane
ghcr.io/wundergraph/cosmo/controlplane:0.133.1 resolved to 49800ff775f3, scanned 14 Sept 2026: 288 findings, 0 critical; deployed by 1 chart, among them cosmo.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
247 distinct on this digest
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest 49800ff775f3 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2025-3849 | stdlib | 1.23.12 |
| Low | GO-2026-4946 | stdlib | 1.25.9 |
| Low | GHSA-v3r7-h72x-cjcm | undici | 6.28.0 |
| Low | GO-2026-4603 | stdlib | 1.25.8 |
| Low | GO-2026-6303 | golang.org/ | 0.55.0 |
| Low | GHSA-8m3c-c648-2xjj | nodemailer | 9.1.1 |
| Low | GO-2026-6354 | golang.org/ | 0.56.0 |
| Low | GO-2026-4982 | stdlib | 1.25.10 |
| Low | GO-2026-6091 | stdlib | 1.25.13 |
| Low | GHSA-8xcm-r25x-g524 | undici | 6.28.0 |
| Low | GO-2026-6180 | golang.org/ | 0.40.0 |
| Low | GO-2025-3750 | stdlib | 1.23.10 |
| Low | GO-2026-4864 | stdlib | 1.25.9 |
| Low | GO-2025-3447 | stdlib | 1.22.12 |
| Low | GO-2026-4865 | stdlib | 1.25.9 |
| Low | GO-2026-4869 | stdlib | 1.25.9 |
| Low | GO-2026-4340 | stdlib | 1.24.12 |
| Low | GO-2025-4175 | stdlib | 1.24.11 |
| Low | GHSA-v6h2-p8h4-qcjw | brace-expansion | 2.0.2 |
| Low | ALPINE-CVE-2025-68160 | openssl | 3.3.6-r0 |
| Low | GO-2026-4403 | stdlib | 1.23.9 |
| Low | GO-2026-5025 | golang.org/ | 0.55.0 |
| Low | GO-2026-4970 | stdlib | 1.25.12 |
| Low | GHSA-m8rv-5g2x-5cg5 | undici | 6.28.0 |
| Low | GO-2026-5027 | golang.org/ | 0.55.0 |
| Low | GO-2026-5029 | golang.org/ | 0.55.0 |
| Low | GO-2026-5030 | golang.org/ | 0.55.0 |
| Low | GO-2026-5777 | github.com/ | 5.3.0 |
| Low | GHSA-c7w3-x93f-qmm8 | nodemailer | 8.0.4 |
| Low | GO-2026-4602 | stdlib | 1.25.8 |
| Low | GHSA-g8m3-5g58-fq7m | undici | 6.27.0 |
| Low | GHSA-35p6-xmwp-9g52 | undici | 6.27.0 |
| Low | GHSA-xhjh-pmcv-23jw | axios | 1.15.1 |
| Low | GO-2026-5775 | github.com/ | 5.3.0 |
| Low | GHSA-cxrh-j4jr-qwg3 | undici | 5.29.0 |
| Low | GHSA-r8jr-wg88-fq5c | @keycloak/ | no fix listed |
| Low | ALPINE-CVE-2025-69418 | openssl | 3.3.6-r0 |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | GO-2026-6179 | golang.org/ | 0.40.0 |
| Low | GO-2026-5841 | github.com/ | 1.18.7 |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | ALPINE-CVE-2025-46394 | busybox | 1.37.0-r14 |
| Low | GHSA-pxg6-pf52-xh8x | cookie | 0.7.0 |
| Low | GHSA-4vq8-7jfc-9cvp | github.com/ | 28.0.0 |
| Low | GHSA-6475-r3vj-m8vf | @smithy/ | 4.4.0 |
| Low | GHSA-4x5r-pxfx-6jf8 | @babel/ | 7.29.6 |
| Low | ALPINE-CVE-2024-58251 | busybox | 1.37.0-r14 |