StackRadar

public.ecr.aws/docker/library/caddy:2.6.3 container image

Amazon ECR Public

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.all tags of public.ecr.aws/docker/library/caddy

public.ecr.aws/docker/library/caddy:2.6.3 resolved to 87cbd356af2e, scanned 14 Sept 2026: 182 findings, 0 critical, 1 on KEV; deployed by 1 chart, among them tfy-cloudflared.

Radar Score

2,0150522155

182 findings on digest 87cbd356af2e · scanned 14 Sept 2026

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.6.3resolves to87cbd356af2e1 chart6 days ago05221552,015

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

182 distinct on this digest

Findings for digest 87cbd356af2e as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGO-2026-4946stdlib@go1.201.25.9
LowGO-2026-4603stdlib@go1.201.25.8
LowGO-2026-6303golang.org/x/crypto@v0.5.00.55.0
LowGO-2026-6354golang.org/x/crypto@v0.5.00.56.0
LowGO-2026-4982stdlib@go1.201.25.10
LowGO-2026-6091stdlib@go1.201.25.13
LowGHSA-j7c9-79x7-8hprgithub.com/smallstep/certificates@v0.23.20.29.0
LowGO-2025-3750stdlib@go1.201.23.10
LowGO-2026-4864stdlib@go1.201.25.9
LowGO-2025-3447stdlib@go1.201.22.12
LowGO-2026-4865stdlib@go1.201.25.9
LowGO-2026-4869stdlib@go1.201.25.9
LowGO-2026-5320github.com/yuin/goldmark@v1.5.41.7.17
LowGO-2026-4340stdlib@go1.201.24.12
LowGO-2025-4175stdlib@go1.201.24.11
LowGO-2026-4403stdlib@go1.201.23.9
LowGO-2026-5025golang.org/x/net@v0.5.00.55.0
LowGO-2026-4970stdlib@go1.201.25.12
LowGO-2026-5027golang.org/x/net@v0.5.00.55.0
LowGO-2026-5029golang.org/x/net@v0.5.00.55.0
LowGO-2026-5030golang.org/x/net@v0.5.00.55.0
LowGHSA-vcc4-2c75-vc9vgithub.com/caddyserver/caddy/v2@v2.6.32.11.4
LowGO-2026-4316github.com/go-chi/chi@v4.1.2+incompatibleno fix listed
LowGO-2026-4602stdlib@go1.201.25.8
LowALPINE-CVE-2023-2602libcap@2.64-r02.64-r1
LowGHSA-gx7w-56w6-g48xgithub.com/caddyserver/caddy/v2@v2.6.32.11.3
LowGO-2026-5024golang.org/x/sys@v0.5.00.44.0
LowGO-2023-2153google.golang.org/grpc@v1.52.31.56.3
LowGO-2026-5408github.com/caddyserver/caddy/v2@v2.6.32.11.3
LowGO-2026-5932golang.org/x/crypto@v0.5.0no fix listed
LowGO-2026-6061google.golang.org/grpc@v1.52.31.82.1
LowGHSA-j88v-2chj-qfwxgithub.com/jackc/pgx/v4@v4.17.2no fix listed

Used by

1 chart
ChartVersionTagContainers
tfy-cloudflaredtruefoundryVerified publisher0.5.02.6.31

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.