public.ecr.aws/gravitational/tbot-distroless:18.11.0 container image
Amazon ECR PublicScanned 14 Sept 2026
Deployed by 2 of 17,781 indexed charts (latest versions) at this tag.all tags of public.ecr.aws/gravitational/tbot-distroless
public.ecr.aws/gravitational/tbot-distroless:18.11.0 resolved to 4ba5ace31fea, scanned 14 Sept 2026: 44 findings, 0 critical; deployed by 2 charts, among them tbot and tbot-spiffe-daemon-set.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
44 distinct on this digest
Findings for digest 4ba5ace31fea as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | DEBIAN-CVE-2019-1010022 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2018-20796 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2019-1010023 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2019-9192 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2026-63076 | openssl | no fix listed |
| Medium | DEBIAN-CVE-2019-1010024 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2026-5450 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2019-1010025 | glibc | no fix listed |
| Low | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Low | DEBIAN-CVE-2026-63072 | openssl | no fix listed |
| Low | DEBIAN-CVE-2026-54874 | openssl | no fix listed |
| Low | DEBIAN-CVE-2026-75803 | openssl | no fix listed |
| Low | DEBIAN-CVE-2026-5928 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-6791 | glibc | no fix listed |
| Low | DEBIAN-CVE-2022-27943 | gcc-12 | no fix listed |
| Low | DEBIAN-CVE-2026-42767 | openssl | no fix listed |
| Low | DEBIAN-CVE-2026-63074 | openssl | no fix listed |
| Low | DEBIAN-CVE-2026-6238 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-5435 | glibc | no fix listed |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | DEBIAN-CVE-2025-27587 | openssl | no fix listed |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Low | GO-2026-5972 | stdlib | 1.25.13 |
| Low | GO-2026-6088 | stdlib | 1.25.13 |
| Low | GO-2026-6089 | stdlib | 1.25.13 |
| Low | GO-2026-6090 | stdlib | 1.25.13 |
| Low | GO-2026-6218 | stdlib | 1.25.13 |
| Low | GO-2026-6355 | golang.org/ | 0.56.0 |
| Low | DEBIAN-CVE-2010-4756 | glibc | no fix listed |
| Low | GO-2026-6303 | golang.org/ | 0.55.0 |
| Low | GO-2026-6354 | golang.org/ | 0.56.0 |
| Low | GO-2026-6091 | stdlib | 1.25.13 |
| Low | GO-2026-6180 | golang.org/ | 0.40.0 |
| Low | DEBIAN-CVE-2026-89092 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-18374 | glibc | no fix listed |
| Low | GO-2026-5298 | github.com/ | no fix listed |
| Low | GO-2026-6179 | golang.org/ | 0.40.0 |
| Low | DEBIAN-CVE-2026-19499 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-19542 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-77117 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-80489 | glibc | no fix listed |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | DEBIAN-CVE-2026-6368 | glibc | no fix listed |