quay.io/prometheus/alertmanager:v0.34.0

container image

Deployed by 2 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.

Radar Score

28
worst finding Low
Critical
0
High
0
Medium
0
Low
5
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

5 findings on digest 690c7b525f43 · scanned 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of quay.io/prometheus/alertmanager:v0.34.0 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.

2 Sept 2026 · Radar Score 28 · OSV as of 2 Sept 2026 · digest 690c7b525f43
history since 2 Sept 2026

Findings

5 distinct on the current digest

Findings for digest 690c7b525f43 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.

AdvisoryPackageFixed inContributionEPSSSince
GHSA-vp52-pcj8-j9qc

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

google.golang.org/grpc@v1.82.1golang1.83.19/1002 Sept 2026
GO-2026-6303

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.54.0golang0.55.06/1000.003 (25th pct)2 Sept 2026
GO-2026-6180

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

golang.org/x/mod@v0.38.0golang0.40.06/1000.003 (22th pct)2 Sept 2026
GO-2026-6179

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

golang.org/x/mod@v0.38.0golang0.40.04/1000.001 (1th pct)2 Sept 2026
GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

golang.org/x/crypto@v0.54.0golangno fix listed4/1002 Sept 2026

Tags and digests

Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.

TagDigestPlatformFirst seenLast seenRadar Score
v0.34.0current690c7b525f43linux/amd642 Sept 20262 Sept 202628

Used by

Charts whose default render references this repository, with the workload that carries it.

syft 1.42.1 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.