registry.k8s.io/ingress-nginx/controller:v1.15.1
container imageDeployed by 1 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 0
- Low
- 90
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
90 findings on digest 594ceea76b01 · scanned 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of registry.k8s.io/ingress-nginx/controller:v1.15.1 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.
Findings
90 distinct on the current digest
Findings for digest 594ceea76b01 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.
| Advisory | Package | Fixed in | Contribution | EPSS | Since |
|---|---|---|---|---|---|
| ALPINE-CVE-2026-31789 | openssl@3.5.5-r0apk | 3.5.6-r0 | 10/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-63073 | openssl@3.5.5-r0apk | 3.5.8-r0 | 10/100 | — | 2 Sept 2026 |
| GHSA-5cv4-jp36-h3mw Go Net HTML parser is vulnerable to denial of service | golang.org/x/net@v0.52.0golang | 0.55.0 | 10/100 | 0.003 (25th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-34182 | openssl@3.5.5-r0apk | 3.5.7-r0 | 9/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-75803 | openssl@3.5.5-r0apk | 3.5.8-r0 | 9/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-45447 | openssl@3.5.5-r0apk | 3.5.7-r0 | 9/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-28387 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-40200 | musl@1.2.5-r21apk | 1.2.5-r23 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-7383 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 |
| GO-2026-4981 Crash when handling long CNAME response in net | stdlib@go1.26.1golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GO-2026-4977 Quadratic string concatenation in consumePhrase in net/mail | stdlib@go1.26.1golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GO-2026-4986 Quadratic string concatentation in consumeComment in net/mail | stdlib@go1.26.1golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | golang.org/x/net@v0.52.0golang | 0.53.0 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | stdlib@go1.26.1golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | stdlib@go1.26.1golang | 1.25.13 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | golang.org/x/net@v0.52.0golang | 0.55.0 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-14456 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-14457 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-18798 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-27135 | nghttp2@1.68.0-r0apk | 1.68.1 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-28388 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-28389 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-28390 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-31790 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-34180 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-34183 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-3805 | curl@8.17.0-r1apk | 8.19.0-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-42764 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-45445 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-54874 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-5773 | curl@8.17.0-r1apk | 8.20.0-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-6276 | curl@8.17.0-r1apk | 8.20.0-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-63072 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-63075 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-63076 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-6732 | libxml2@2.13.9-r0apk | 2.13.9-r1 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-9076 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-34181 | openssl@3.5.5-r0apk | 3.5.7-r0 | 7/100 | — | 2 Sept 2026 |
| GO-2026-4870 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls | stdlib@go1.26.1golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GO-2026-4947 Unexpected work during chain building in crypto/x509 | stdlib@go1.26.1golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GO-2026-5037 Inefficient candidate hostname parsing in crypto/x509 | stdlib@go1.26.1golang | 1.25.11 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GO-2026-4971 Panic in Dial and LookupPort when handling NUL byte on Windows in net | stdlib@go1.26.1golang | 1.25.10 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-5972 Enforce maximum recursion depth in encoding/asn1 | stdlib@go1.26.1golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6088 Add recursion depth guard during decode in encoding/xml | stdlib@go1.26.1golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6089 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http | stdlib@go1.26.1golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6090 Limit handshake messages we are willing to accept post-handshake in crypto/tls | stdlib@go1.26.1golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-5038 Quadratic complexity in WordDecoder.DecodeHeader in mime | stdlib@go1.26.1golang | 1.25.11 | 7/100 | 0.006 (44th pct) | 2 Sept 2026 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | stdlib@go1.26.1golang | 1.26.6 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | golang.org/x/net@v0.52.0golang | 0.56.0 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 |
| GO-2026-6218 Avoid quadratic complexity in resolvePath in net/url | stdlib@go1.26.1golang | 1.25.13 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GO-2026-5970 Infinite loop on invalid input in golang.org/x/text | golang.org/x/text@v0.35.0golang | 0.39.0 | 7/100 | 0.005 (39th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-1965 | curl@8.17.0-r1apk | 8.19.0-r0 | 7/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-2673 | openssl@3.5.5-r0apk | 3.5.6-r0 | 7/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-3784 | curl@8.17.0-r1apk | 8.19.0-r0 | 7/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-5545 | curl@8.17.0-r1apk | 8.20.0-r0 | 7/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2025-14017 | curl@8.17.0-r1apk | 8.19.0-r0 | 6/100 | — | 2 Sept 2026 |
| GO-2026-4976 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | stdlib@go1.26.1golang | 1.25.10 | 6/100 | 0.004 (32th pct) | 2 Sept 2026 |
| GO-2026-5856 Invoking Encrypted Client Hello privacy leak in crypto/tls | stdlib@go1.26.1golang | 1.25.12 | 6/100 | 0.004 (31th pct) | 2 Sept 2026 |
| GO-2026-4980 Escaper bypass leads to XSS in html/template | stdlib@go1.26.1golang | 1.25.10 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GO-2026-5039 Arbitrary inputs are included in errors without any escaping in net/textproto | stdlib@go1.26.1golang | 1.25.11 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GO-2026-4946 Inefficient policy validation in crypto/x509 | stdlib@go1.26.1golang | 1.25.9 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 |
| GO-2026-4866 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 | stdlib@go1.26.1golang | 1.26.2 | 6/100 | 0.003 (27th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-42766 | openssl@3.5.5-r0apk | 3.5.7-r0 | 6/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-42767 | openssl@3.5.5-r0apk | 3.5.7-r0 | 6/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-4873 | curl@8.17.0-r1apk | 8.20.0-r0 | 6/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-6253 | curl@8.17.0-r1apk | 8.20.0-r0 | 6/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-63074 | openssl@3.5.5-r0apk | 3.5.8-r0 | 6/100 | — | 2 Sept 2026 |
| GO-2026-4982 Bypass of meta content URL escaping causes XSS in html/template | stdlib@go1.26.1golang | 1.25.10 | 6/100 | 0.003 (24th pct) | 2 Sept 2026 |
| GO-2026-6091 Fix Javascript regexp context tracking in html/template | stdlib@go1.26.1golang | 1.25.13 | 6/100 | 0.003 (23th pct) | 2 Sept 2026 |
| GO-2026-4864 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix | stdlib@go1.26.1golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2026-4865 JsBraceDepth Context Tracking Bugs (XSS) in html/template | stdlib@go1.26.1golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2026-4869 Unbounded allocation for old GNU sparse in archive/tar | stdlib@go1.26.1golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2026-5025 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.52.0golang | 0.55.0 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 |
| ALPINE-CVE-2025-14524 | curl@8.17.0-r1apk | 8.19.0-r0 | 5/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2025-14819 | curl@8.17.0-r1apk | 8.19.0-r0 | 5/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-34743 | xz@5.8.2-r0apk | 5.8.3-r0 | 5/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-3783 | curl@8.17.0-r1apk | 8.19.0-r0 | 5/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-42769 | openssl@3.5.5-r0apk | 3.5.7-r0 | 5/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-6429 | curl@8.17.0-r1apk | 8.20.0-r0 | 5/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-7009 | curl@8.17.0-r1apk | 8.20.0-r0 | 5/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-7168 | curl@8.17.0-r1apk | 8.20.0-r0 | 5/100 | — | 2 Sept 2026 |
| GO-2026-4970 Root escape via symlink plus trailing slash in os | stdlib@go1.26.1golang | 1.25.12 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 |
| GO-2026-5027 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.52.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| GO-2026-5029 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | golang.org/x/net@v0.52.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| GO-2026-5030 Invoking duplicate attributes can cause XSS in golang.org/x/net/html | golang.org/x/net@v0.52.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-45446 | openssl@3.5.5-r0apk | 3.5.7-r0 | 5/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-6042 | musl@1.2.5-r21apk | 1.2.5-r22 | 5/100 | — | 2 Sept 2026 |
| GO-2026-5024 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | golang.org/x/sys@v0.42.0golang | 0.44.0 | 4/100 | 0.001 (2th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-42768 | openssl@3.5.5-r0apk | 3.5.7-r0 | 4/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-42770 | openssl@3.5.5-r0apk | 3.5.7-r0 | 4/100 | — | 2 Sept 2026 |
Tags and digests
Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.
| Tag | Digest | Platform | First seen | Last seen | Radar Score |
|---|---|---|---|---|---|
| v1.15.1current | 594ceea76b01 | linux/amd64 | 2 Sept 2026 | 2 Sept 2026 | 611 |
Used by
Charts whose default render references this repository, with the workload that carries it.
- ingress-nginxingress-nginx