StackRadar

registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5 container image

GitLab Container Registry

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.all tags of registry.gitlab.com/xrow-public/helm-iframely/iframely

registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5 resolved to fcf07d5ff7e2, scanned 14 Sept 2026: 199 findings, 5 critical, 2 on KEV; deployed by 1 chart, among them iframely.

Radar Score

3,1545652136

199 findings on digest fcf07d5ff7e2 · scanned 14 Sept 2026

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.3.5resolves tofcf07d5ff7e21 chartyesterday56521363,154

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

199 distinct on this digest

Findings for digest fcf07d5ff7e2 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowRHSA-2026:61383nodejs-nodemon@3.0.1-1.module+el9.7.0+23895+0637d4230:3.1.14-2.module+el9.8.0+24709+804d6b5b
LowRHSA-2026:61383nodejs@1:20.20.0-1.module+el9.7.0+23895+0637d4231:22.23.2-1.module+el9.8.0+24709+804d6b5b
LowRHSA-2026:61386nodejs@1:20.20.0-1.module+el9.7.0+23895+0637d4231:24.19.0-1.module+el9.8.0+24708+e71d2e1d
LowRHSA-2026:61386nodejs-nodemon@3.0.1-1.module+el9.7.0+23895+0637d4230:3.1.14-3.module+el9.8.0+24708+e71d2e1d
LowGHSA-8qq5-rm4j-mr97tar@6.2.17.5.3
LowRHSA-2026:52674libarchive@3.5.3-7.el9_70:3.5.3-11.el9_8
LowGHSA-qxch-whhj-8956multiparty@4.2.34.3.0
LowGHSA-23c5-xmqv-rm74minimatch@3.1.23.1.4
LowRHSA-2026:53329kernel@5.14.0-611.47.1.el9_70:5.14.0-687.38.1.el9_8
LowGHSA-qpx9-hpmf-5gmwunderscore@1.13.71.13.8
LowGHSA-mh99-v99m-4gvgbrace-expansion@2.0.12.1.3
LowRHSA-2026:28209vim@2:8.2.2637-23.el9_7.12:8.2.2637-26.el9_8.6
LowRHSA-2026:23230expat@2.5.0-5.el9_7.10:2.5.0-6.el9_8.1
LowRHSA-2026:47756openssh@8.7p1-48.el9_70:9.9p1-9.el9_8
LowGHSA-73rr-hh4g-fpgxdiff@5.2.05.2.2
LowGHSA-8x88-c5mf-7j5wtar@6.2.17.5.18
LowRHSA-2026:24381kernel@5.14.0-611.47.1.el9_70:5.14.0-687.13.1.el9_8
LowRHSA-2026:18599p11-kit@0.25.3-3.el9_50:0.26.2-1.el9
LowGHSA-c2c7-rcm5-vvqjpicomatch@2.3.12.3.2
LowGHSA-mwp4-54f8-5fhrip-address@9.0.510.3.1
LowRHSA-2026:8921kernel@5.14.0-611.47.1.el9_70:5.14.0-611.49.1.el9_7
LowGHSA-r6q2-hw4h-h46wtar@6.2.17.5.4
LowGHSA-2883-xcg3-v3hhjs-yaml@4.1.04.3.2
LowGHSA-r292-9mhp-454mtar@6.2.17.5.21
LowRHSA-2026:18587kernel@5.14.0-611.47.1.el9_70:5.14.0-687.5.1.el9_8
LowGHSA-w4pp-8pjf-rmxwpacote@18.0.621.5.1
LowGHSA-9hjg-9r4m-mvj7requests@2.25.12.32.4
LowGHSA-65x3-rw7q-gx94multiparty@4.2.34.3.0
LowGHSA-9ppj-qmqm-q256tar@6.2.17.5.11
LowRHSA-2026:45192kernel@5.14.0-611.47.1.el9_70:5.14.0-687.30.1.el9_8
LowRHSA-2026:19357krb5@1.21.1-8.el9_60:1.21.1-10.el9_8
LowRHSA-2026:43307kernel@5.14.0-611.47.1.el9_70:5.14.0-687.29.1.el9_8
LowGHSA-f886-m6hf-6m8vbrace-expansion@2.0.12.0.3
LowGHSA-xh3c-6gcq-g4rvmultiparty@4.2.34.3.0
LowGHSA-wpg9-53fq-2r8hmongoose@8.8.08.22.1
LowRHSA-2026:39315libsolv@0.7.24-3.el90:0.7.24-6.el9_8
LowRHSA-2026:33285kernel@5.14.0-611.47.1.el9_70:5.14.0-687.20.1.el9_8
LowRHSA-2026:20597glibc@2.34-231.el9_7.100:2.34-270.el9_8
LowGHSA-83g3-92jg-28cxtar@6.2.17.5.8
LowRHSA-2026:47982vim@2:8.2.2637-23.el9_7.12:8.2.2637-26.el9_8.13
LowGHSA-664h-wqgq-64gwmongoose@8.8.08.24.1
LowRHSA-2026:42952glibc@2.34-231.el9_7.100:2.34-274.el9_8
LowGHSA-34jh-p97f-mpxfurllib3@1.26.51.26.19
LowGHSA-qj8w-gfj5-8c6vserialize-javascript@6.0.27.0.5
LowGHSA-w8wr-v893-vjvptar@6.2.17.5.18
LowRHSA-2026:54443kernel@5.14.0-611.47.1.el9_70:5.14.0-687.39.1.el9_8
LowGHSA-h35f-9h28-mq5csetuptools@53.0.083.0.0
LowRHSA-2026:61623gzip@1.12-1.el90:1.12-2.el9_8
LowRHSA-2026:64800glib2@2.68.4-18.el9_7.10:2.68.4-19.el9_8.10
LowRHSA-2026:58936sqlite@3.34.1-9.el9_70:3.34.1-11.el9_8

Used by

1 chart
ChartVersionTagContainers
iframelyiframelyVerified publisher2.3.52.3.51

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.