public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local container image
Amazon ECR PublicScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.all tags of public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local resolved to 8cdcb7e83f9f, scanned 14 Sept 2026: 309 findings, 4 critical, 1 on KEV; deployed by 1 chart, among them akto-testing-db-layer.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest 8cdcb7e83f9f as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-mmmh-wcxm-2wr4 | spring-security-core | 5.6.9 |
| Medium | GHSA-729q-fcgp-r5xh | struts2-core | 2.5.32 |
| Medium | UBUNTU-CVE-2026-45447 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | GHSA-g5mm-vmx4-3rg7 | spring-context | 5.3.19 |
| Medium | GHSA-4g42-gqrg-4633 | struts2-core | 2.5.31 |
| Medium | GHSA-ccgv-vj62-xf9h | spring-web | 5.3.32 |
| Medium | GHSA-8f6x-v685-g2xc | struts2-core | 2.5.31 |
| Medium | GHSA-98qh-xjc8-98pq | postgresql | 42.7.11 |
| Medium | GHSA-hgjh-9rj2-g67j | spring-web | 5.3.33 |
| Medium | GHSA-7r82-7xv7-xcpj | httpclient | 4.5.13 |
| Medium | GHSA-c4q5-6c82-3qpw | spring-security-web | 5.7.13 |
| Medium | GHSA-gwrp-pvrq-jmwv | commons-io | 2.7 |
| Medium | UBUNTU-CVE-2026-19931 | curl | no fix listed |
| Medium | GHSA-mvr2-9pj6-7w5j | guava-jdk5 | no fix listed |
| Medium | UBUNTU-CVE-2016-20013 | glibc | no fix listed |
| Medium | UBUNTU-CVE-2026-10536 | curl | 8.5.0-2ubuntu10.11 |
| Medium | GHSA-hh26-6xwr-ggv7 | spring-beans | 5.3.20 |
| Medium | UBUNTU-CVE-2026-18924 | curl | no fix listed |
| Medium | UBUNTU-CVE-2026-11856 | curl | 8.5.0-2ubuntu10.12 |
| Medium | GHSA-f263-c949-w85g | google-oauth-client | 1.31.0 |
| Medium | GHSA-xx7v-hqxh-cjr9 | struts2-core | no fix listed |
| Medium | UBUNTU-CVE-2026-8925 | curl | 8.5.0-2ubuntu10.10 |
| Medium | GHSA-2wrp-6fg6-hmc5 | spring-web | 5.3.34 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | UBUNTU-CVE-2026-42009 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Medium | UBUNTU-CVE-2026-63076 | openssl | 3.0.13-0ubuntu3.15 |
| Medium | GHSA-78wr-2p64-hpwj | commons-io | 2.14.0 |
| Medium | UBUNTU-CVE-2025-59375 | expat | no fix listed |
| Medium | UBUNTU-CVE-2026-33846 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Medium | GHSA-355h-qmc2-wpwf | jetty-http | 9.4.60 |
| Medium | GHSA-f3jh-qvm4-mg39 | spring-security-core | 5.7.12 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.18.8 |
| Medium | GHSA-wxqc-pxw9-g2p8 | spring-expression | 5.3.27 |
| Medium | UBUNTU-CVE-2026-5450 | glibc | 2.39-0ubuntu8.8 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.18.8 |
| Medium | UBUNTU-CVE-2026-34182 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | UBUNTU-CVE-2026-33416 | libpng1.6 | 1.6.43-5ubuntu0.6 |
| Medium | GHSA-p4qx-6w5p-4rj2 | graphql-java | 20.1 |
| Medium | UBUNTU-CVE-2026-31790 | openssl | 3.0.13-0ubuntu3.9 |
| Medium | UBUNTU-CVE-2026-34180 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | UBUNTU-CVE-2026-7383 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | UBUNTU-CVE-2026-8924 | curl | 8.5.0-2ubuntu10.10 |
| Medium | UBUNTU-CVE-2025-69720 | ncurses | 6.4+20240113-1ubuntu2.1 |
| Medium | UBUNTU-CVE-2026-8376 | perl | 5.38.2-3.2ubuntu0.3 |
| Medium | UBUNTU-CVE-2026-5260 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Medium | GHSA-h9mq-f6q5-6c8m | graphql-java | 20.9 |
| Medium | UBUNTU-CVE-2026-8927 | curl | 8.5.0-2ubuntu10.10 |
| Medium | UBUNTU-CVE-2026-42010 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Medium | UBUNTU-CVE-2026-28388 | openssl | 3.0.13-0ubuntu3.9 |
| Medium | UBUNTU-CVE-2025-69421 | openssl | 3.0.13-0ubuntu3.7 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| akto-testing-db-layerakto | 1.42.16 | 1.59.3_local | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.