ghcr.io/wundergraph/cosmo/controlplane:0.133.1 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/wundergraph/cosmo/controlplane
ghcr.io/wundergraph/cosmo/controlplane:0.133.1 resolved to 49800ff775f3, scanned 14 Sept 2026: 288 findings, 0 critical; deployed by 1 chart, among them cosmo.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
288 distinct on this digest
Findings for digest 49800ff775f3 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-2mjp-6q6p-2qxm | undici | 6.24.0 |
| Low | GHSA-968p-4wvh-cqc8 | @babel/ | 7.26.10 |
| Low | GHSA-3p68-rc4w-qgx5 | axios | 1.15.0 |
| Low | GHSA-jqh4-m9w3-8hp9 | axios | 1.18.0 |
| Low | GO-2024-2887 | stdlib | 1.21.11 |
| Low | GHSA-pxq6-2prw-chj9 | github.com/ | no fix listed |
| Low | GHSA-f886-m6hf-6m8v | brace-expansion | 2.0.3 |
| Low | GHSA-c96f-x56v-gq3h | find-my-way | 9.7.0 |
| Low | GHSA-42h9-826w-cgv3 | axios | 1.18.0 |
| Low | GHSA-pmv8-rq9r-6j72 | axios | 1.18.0 |
| Low | GHSA-83g3-92jg-28cx | tar | 7.5.8 |
| Low | GHSA-38c4-r59v-3vqw | markdown-it | 14.1.1 |
| Low | GHSA-hfvc-g4fc-pqhx | go.opentelemetry.io/ | 1.43.0 |
| Low | GHSA-g9mf-h72j-4rw9 | undici | 6.23.0 |
| Low | GHSA-w8wr-v893-vjvp | tar | 7.5.18 |
| Low | GHSA-m7pr-hjqh-92cm | axios | 1.15.1 |
| Low | GHSA-7p8r-x3mc-p8w7 | fast-uri | 2.4.4 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | GHSA-jp2q-39xq-3w4g | fast-xml-parser | 4.5.5 |
| Low | GHSA-p6gq-j5cr-w38f | nodemailer | 9.0.1 |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | GHSA-mmx7-hfxf-jppx | axios | 1.18.0 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.5-r11 |
| Low | GHSA-vvjj-xcjg-gr5g | nodemailer | 8.0.5 |
| Low | ALPINE-CVE-2025-66199 | openssl | 3.3.6-r0 |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | GHSA-52v5-jr5w-gjxr | sigstore | 4.1.1 |
| Low | GHSA-vvgc-356p-c3xw | golang.org/ | 0.38.0 |
| Low | GHSA-m454-3xv7-qj85 | github.com/ | 0.65.0 |
| Low | GO-2023-2382 | stdlib | 1.20.12 |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2026-22796 | openssl | 3.3.6-r0 |
| Low | GHSA-f6x5-jh6r-wrfv | golang.org/ | 0.45.0 |
| Low | GHSA-gvwx-54wh-qm9j | tar | 7.5.17 |
| Low | GHSA-78mq-xcr3-xm33 | golang.org/ | 0.52.0 |
| Low | GO-2024-2599 | stdlib | 1.21.8 |
| Low | GO-2024-3106 | stdlib | 1.22.7 |
| Low | GHSA-v2v4-37r5-5v8g | ip-address | 10.1.1 |
| Low | GO-2024-2600 | stdlib | 1.21.8 |
| Low | GHSA-w9j2-pvgh-6h63 | axios | 1.15.1 |
| Low | GO-2024-2609 | stdlib | 1.21.8 |
| Low | GO-2024-3107 | stdlib | 1.22.7 |
| Low | GHSA-58qx-3vcg-4xpx | ws | 8.20.1 |
| Low | GHSA-9m57-25v3-79x9 | golang.org/ | 0.52.0 |
| Low | GHSA-3v7f-55p6-f55p | picomatch | 2.3.2 |
| Low | GHSA-mh29-5h37-fv8m | js-yaml | 4.1.1 |
| Low | GHSA-x86f-5xw2-fm2r | github.com/ | no fix listed |
| Low | GO-2023-2041 | stdlib | 1.20.8 |
| Low | GHSA-7q8q-rj6j-mhjq | axios | 1.18.0 |