StackRadar

quay.io/keycloak/keycloak-operator:18.0.0-legacy container image

Quay.io

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Quay.io all tags of quay.io/keycloak/keycloak-operator

quay.io/keycloak/keycloak-operator:18.0.0-legacy resolved to 36ce77526145, scanned 14 Sept 2026: 316 findings, 4 critical, 4 on KEV; deployed by 1 chart, among them keycloak-operator.

Radar Score

4,71441372227

316 findings on digest 36ce77526145 · scanned 14 Sept 2026

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
18.0.0-legacyresolves to36ce775261451 chart8 days ago413722274,714

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Medium findings

72 distinct on this digest

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

Findings for digest 36ce77526145 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumRHSA-2024:0253sqlite@3.26.0-15.el80:3.26.0-19.el8_9
MediumRHSA-2023:3018libarchive@3.3.3-3.el8_50:3.3.3-5.el8
MediumGHSA-gwc9-m7rh-j2wwgolang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b00.0.0-20211202192323-5770296d904e
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b00.52.0
MediumRHSA-2023:1140curl@7.61.1-22.el80:7.61.1-25.el8_7.3
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b00.52.0
MediumRHSA-2023:0116libtasn1@4.13-3.el80:4.13-4.el8_7
MediumGO-2021-0243stdlib@go1.13.81.15.14
MediumGO-2022-0273stdlib@go1.13.81.16.8
MediumGHSA-p782-xgp4-8hr8golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd0.0.0-20220412211240-33da011f77ad
MediumRHSA-2023:5249ncurses@6.1-9.20180224.el80:6.1-9.20180224.el8_8.1
MediumRHSA-2025:11327glib2@2.56.4-156.el80:2.56.4-166.el8_10
MediumRHBA-2024:5736ca-certificates@2021.2.50-80.0.el8_40:2024.2.69_v8.0.303-80.0.el8_10
MediumGHSA-4f99-4q7p-p3ghgithub.com/sirupsen/logrus@v1.6.01.8.3
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b00.52.0
MediumGHSA-hcg3-q754-cr77golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b00.35.0
MediumRHSA-2026:26354libxml2@2.9.7-12.el8_50:2.9.7-21.el8_10.5
MediumRHSA-2023:4523curl@7.61.1-22.el80:7.61.1-30.el8_8.3
MediumGO-2022-1144stdlib@go1.13.81.18.9
MediumGHSA-6v2p-p543-phr9golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d0.27.0
MediumRHSA-2025:17415gnutls@3.6.16-4.el80:3.6.16-8.el8_10.4
MediumRHSA-2026:38503openssl@1:1.1.1k-6.el8_51:1.1.1k-17.el8_6

Used by

1 chart
ChartVersionTagContainers
keycloak-operatorwiremindVerified publisher0.0.1418.0.0-legacy1

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.