registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1 container image
GitLab Container RegistryScanned 14 Sept 2026
Deployed by 3 of 17,781 indexed charts (latest versions) at this tag.all tags of registry.gitlab.com/gitlab-org/gitlab-runner
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1 resolved to af0325804248, scanned 14 Sept 2026: 88 findings, 0 critical; deployed by 3 charts, among them gitlab-runner, gitlab-runner and gitlab-runner.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
88 distinct on this digest
Findings for digest af0325804248 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-19931 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-18924 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | GO-2026-4887 | github.com/ | no fix listed |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-80231 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-66046 | expat | 2.8.4-r0 |
| Medium | ALPINE-CVE-2026-80229 | curl | 8.22.0-r0 |
| Low | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Low | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-82209 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-80255 | curl | 8.22.0-r0 |
| Low | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Low | ALPINE-CVE-2026-13608 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-60002 | openssh | 10.3_p1-r1 |
| Low | ALPINE-CVE-2026-80230 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-76641 | expat | 2.8.4-r0 |
| Low | ALPINE-CVE-2026-54874 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | GHSA-q4h4-gmj2-qvw2 | golang.org/ | 0.52.0 |
| Low | GHSA-w879-237q-wc7r | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2026-60000 | openssh | 10.3_p1-r1 |
| Low | ALPINE-CVE-2026-82208 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | GHSA-pxq6-2prw-chj9 | github.com/ | no fix listed |
| Low | ALPINE-CVE-2026-76956 | expat | 2.8.4-r0 |
| Low | ALPINE-CVE-2026-63074 | openssl | 3.5.8-r0 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | ALPINE-CVE-2026-60001 | openssh | 10.3_p1-r1 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | GHSA-78mq-xcr3-xm33 | golang.org/ | 0.52.0 |
| Low | GHSA-hrxh-6v49-42gf | google.golang.org/ | 1.82.1 |
| Low | ALPINE-CVE-2026-59999 | openssh | 10.3_p1-r1 |
| Low | GHSA-9m57-25v3-79x9 | golang.org/ | 0.52.0 |
| Low | GHSA-x86f-5xw2-fm2r | github.com/ | no fix listed |
| Low | ALPINE-CVE-2026-76957 | expat | 2.8.4-r0 |
| Low | ALPINE-CVE-2026-59998 | openssh | 10.3_p1-r1 |
| Low | GO-2026-5026 | golang.org/ | 0.55.0 |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
Used by
3 charts
| Chart | Version | Tag | Containers |
|---|---|---|---|
| gitlab-runnergitlabVerified publisher | 0.92.1 | alpine-v19.3.1 | 1 |
| gitlab-runnergitlab-jh | 0.92.1 | alpine-v19.3.1 | 1 |
| gitlab-runnerwenerme | 0.92.1 | alpine-v19.3.1 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.