quay.io/prometheus/pushgateway

container image

Deployed by 1 of 300 indexed charts (latest versions).Counts say nothing about images outside the indexed set.

Radar Score

112
worst finding Low
Critical
0
High
0
Medium
0
Low
17
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

17 findings on digest 74fa117cef2d · scanned 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of quay.io/prometheus/pushgateway across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.

2 Sept 2026 · Radar Score 112 · OSV as of 2 Sept 2026 · digest 74fa117cef2d
history since 2 Sept 2026

Findings

17 distinct on the current digest

Findings for digest 74fa117cef2d as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.

AdvisoryPackageFixed inContributionEPSSSince
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

stdlib@go1.26.3golang1.25.138/1000.007 (50th pct)2 Sept 2026
GO-2026-5037

Inefficient candidate hostname parsing in crypto/x509

stdlib@go1.26.3golang1.25.117/1000.006 (46th pct)2 Sept 2026
GO-2026-5972

Enforce maximum recursion depth in encoding/asn1

stdlib@go1.26.3golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6088

Add recursion depth guard during decode in encoding/xml

stdlib@go1.26.3golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6089

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

stdlib@go1.26.3golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6090

Limit handshake messages we are willing to accept post-handshake in crypto/tls

stdlib@go1.26.3golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-5038

Quadratic complexity in WordDecoder.DecodeHeader in mime

stdlib@go1.26.3golang1.25.117/1000.006 (44th pct)2 Sept 2026
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

golang.org/x/net@v0.55.0golang0.56.07/1000.005 (44th pct)2 Sept 2026
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

stdlib@go1.26.3golang1.26.67/1000.005 (44th pct)2 Sept 2026
GO-2026-6218

Avoid quadratic complexity in resolvePath in net/url

stdlib@go1.26.3golang1.25.137/1000.005 (42th pct)2 Sept 2026
GO-2026-5970

Infinite loop on invalid input in golang.org/x/text

golang.org/x/text@v0.37.0golang0.39.07/1000.005 (39th pct)2 Sept 2026
GO-2026-5856

Invoking Encrypted Client Hello privacy leak in crypto/tls

stdlib@go1.26.3golang1.25.126/1000.004 (31th pct)2 Sept 2026
GO-2026-5039

Arbitrary inputs are included in errors without any escaping in net/textproto

stdlib@go1.26.3golang1.25.116/1000.004 (30th pct)2 Sept 2026
GO-2026-6303

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.52.0golang0.55.06/1000.003 (25th pct)2 Sept 2026
GO-2026-6091

Fix Javascript regexp context tracking in html/template

stdlib@go1.26.3golang1.25.136/1000.003 (23th pct)2 Sept 2026
GO-2026-4970

Root escape via symlink plus trailing slash in os

stdlib@go1.26.3golang1.25.125/1000.002 (14th pct)2 Sept 2026
GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

golang.org/x/crypto@v0.52.0golangno fix listed4/1002 Sept 2026

Tags and digests

Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.

TagDigestPlatformFirst seenLast seenRadar Score
v1.11.3current74fa117cef2dlinux/amd642 Sept 20262 Sept 2026112
v1.11.249ed9fdf3780linux/amd642 Sept 20262 Sept 2026570

Used by

Charts whose default render references this repository, with the workload that carries it.

syft 1.42.1 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.