registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlab container image
GitLab Container RegistryScanned 20 Sept 2026
Deployed by 1 of 17,813 indexed charts (latest versions) at this tag.all tags of registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlab resolved to dc1a8972c640, scanned 20 Sept 2026: 225 findings, 0 critical; deployed by 1 chart, among them gitlab.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest dc1a8972c640 as scanned on 20 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 20 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-22185 | openldap | no fix listed |
| Low | GO-2026-5027 | golang.org/ | 0.55.0 |
| Low | GO-2026-5029 | golang.org/ | 0.55.0 |
| Low | GO-2026-5030 | golang.org/ | 0.55.0 |
| Low | DEBIAN-CVE-2026-42250 | bzip2 | no fix listed |
| Low | DEBIAN-CVE-2026-76014 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-27456 | util-linux | no fix listed |
| Low | DEBIAN-CVE-2026-18508 | tar | no fix listed |
| Low | DEBIAN-CVE-2025-68972 | gnupg2 | no fix listed |
| Low | GHSA-37cx-329c-33x3 | github.com/ | 5.16.5 |
| Low | DEBIAN-CVE-2022-3219 | gnupg2 | no fix listed |
| Low | DEBIAN-CVE-2023-4016 | procps | no fix listed |
| Low | DEBIAN-CVE-2026-38752 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-38755 | busybox | no fix listed |
| Low | DEBIAN-CVE-2007-5686 | shadow | no fix listed |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | DEBIAN-CVE-2026-18477 | tar | no fix listed |
| Low | DEBIAN-CVE-2025-46394 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-53613 | util-linux | no fix listed |
| Low | DEBIAN-CVE-2026-53615 | util-linux | no fix listed |
| Low | DEBIAN-CVE-2026-82560 | perl | no fix listed |
| Low | GO-2022-0379 | github.com/ | 2.8.0+incompatible |
| Low | GO-2026-5693 | github.com/ | 5.19.1 |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | GO-2026-6061 | google.golang.org/ | 1.82.1 |
| Low | DEBIAN-CVE-2026-40228 | systemd | no fix listed |
| Low | GHSA-m7cr-m3pv-hgrp | github.com/ | 5.19.1 |
| Low | GHSA-j88v-2chj-qfwx | github.com/ | 5.9.2 |
| Low | DEBIAN-CVE-2026-57062 | gnupg2 | no fix listed |
| Low | GHSA-gm2x-2g9h-ccm8 | github.com/ | 5.17.1 |
| Low | DEBIAN-CVE-2026-53910 | diffutils | no fix listed |
| Low | DEBIAN-CVE-2024-58251 | busybox | no fix listed |
| Low | GHSA-qq97-vm5h-rrhg | github.com/ | 2.8.0 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | DEBIAN-CVE-2026-6368 | glibc | no fix listed |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| gitlabgitlabVerified publisher | 10.4.0 | v4.40.2-gitlab | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.