quay.io/kiwigrid/k8s-sidecar:1.25.2 container image
Quay.ioScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Quay.io all tags of quay.io/kiwigrid/k8s-sidecar
quay.io/kiwigrid/k8s-sidecar:1.25.2 resolved to cb4c638ffb1f, scanned 14 Sept 2026: 59 findings, 1 critical; deployed by 1 chart, among them upgrade-responder.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
59 distinct on this digest
Findings for digest cb4c638ffb1f as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2025-6965 | sqlite | 3.41.2-r4 |
| High | ALPINE-CVE-2024-6119 | openssl | 3.1.7-r0 |
| High | ALPINE-CVE-2024-2511 | openssl | 3.1.4-r6 |
| Medium | ALPINE-CVE-2024-5535 | openssl | 3.1.6-r0 |
| Medium | ALPINE-CVE-2023-5363 | openssl | 3.1.4-r0 |
| Medium | ALPINE-CVE-2024-37371 | krb5 | 1.20.2-r1 |
| Medium | GHSA-cx63-2mw6-8hw5 | setuptools | 70.0.0 |
| Medium | ALPINE-CVE-2024-45492 | expat | 2.6.3-r0 |
| Medium | GHSA-38jv-5279-wg99 | urllib3 | 2.6.3 |
| Medium | ALPINE-CVE-2024-4741 | openssl | 3.1.6-r0 |
| Medium | ALPINE-CVE-2024-45491 | expat | 2.6.3-r0 |
| Medium | PYSEC-2025-49 | setuptools | 78.1.1 |
| Medium | ALPINE-CVE-2024-28757 | expat | 2.6.2-r0 |
| Medium | ALPINE-CVE-2023-36054 | krb5 | 1.20.2-r0 |
| Medium | ALPINE-CVE-2023-52425 | expat | 2.6.0-r0 |
| Medium | ALPINE-CVE-2024-45490 | expat | 2.6.3-r0 |
| Medium | ALPINE-CVE-2023-5678 | openssl | 3.1.4-r1 |
| Medium | ALPINE-CVE-2023-6129 | openssl | 3.1.4-r3 |
| Medium | PYSEC-2024-60 | idna | 3.7 |
| Medium | ALPINE-CVE-2024-8176 | expat | 2.7.0-r0 |
| Medium | ALPINE-CVE-2024-0727 | openssl | 3.1.4-r5 |
| Medium | ALPINE-CVE-2023-7104 | sqlite | 3.41.2-r3 |
| Medium | GHSA-2xpw-w6gg-jr37 | urllib3 | 2.6.0 |
| Medium | GHSA-gm62-xv2j-4w53 | urllib3 | 2.6.0 |
| Medium | ALPINE-CVE-2023-6237 | openssl | 3.1.4-r4 |
| Medium | ALPINE-CVE-2024-9143 | openssl | 3.1.7-r1 |
| Medium | PYSEC-2024-230 | certifi | 2024.7.4 |
| Medium | ALPINE-CVE-2025-31115 | xz | 5.4.3-r1 |
| Medium | GHSA-jr27-m4p2-rc6r | pyasn1 | 0.6.3 |
| Low | ALPINE-CVE-2024-37370 | krb5 | 1.20.2-r1 |
| Low | ALPINE-CVE-2024-50602 | expat | 2.6.4-r0 |
| Low | ALPINE-CVE-2024-4603 | openssl | 3.1.5-r0 |
| Low | GHSA-wf93-45jw-7689 | pip | 26.1.2 |
| Low | GHSA-m4p7-r5rc-7g4j | pyasn1 | 0.6.4 |
| Low | GHSA-9hjg-9r4m-mvj7 | requests | 2.32.4 |
| Low | GHSA-8ppf-4f7h-5ppj | pyasn1 | 0.6.4 |
| Low | GHSA-hm4w-wwcw-mr6r | pyasn1 | 0.6.4 |
| Low | ALPINE-CVE-2025-26519 | musl | 1.2.4-r3 |
| Low | GHSA-8rrh-rw8j-w5fx | wheel | 0.46.2 |
| Low | GHSA-34jh-p97f-mpxf | urllib3 | 2.2.2 |
| Low | GHSA-4xh5-x5gv-qwph | pip | 25.3 |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | GHSA-mq26-g339-26xf | pip | 23.3 |
| Low | ALPINE-CVE-2023-42364 | busybox | 1.36.1-r7 |
| Low | ALPINE-CVE-2023-42363 | busybox | 1.36.1-r7 |
| Low | ALPINE-CVE-2023-42366 | busybox | 1.36.1-r6 |
| Low | ALPINE-CVE-2023-42365 | busybox | 1.36.1-r7 |
| Low | GHSA-pq67-6m6q-mj2v | urllib3 | 2.5.0 |
| Low | ALPINE-CVE-2023-52426 | expat | 2.6.0-r0 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| upgrade-responderepinioVerified publisher | 0.2.0 | 1.25.2 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.