linuxserver/ubooquity

by linuxserver ← project: Ubooquity
SCOUT
F
score 0
Pull →
docker pull linuxserver/ubooquity click to select

Image metadata

PULL COUNT
—
repository-level (not per-tag)
SIZE (COMPRESSED)
111 MB
ARCHITECTURES
2
RUNS AS
root
image config.User
LAST PUSHED
3d ago
2026-10-07 01:48:20
MANIFEST DIGEST
sha256:d4017ee0d38c…
from registry manifest

Latest scan

2026-10-08 16:36:03 UTC · yesterday

OPEN CVES BY SEVERITY

10
CRITICAL
31
HIGH
48
MEDIUM
7
LOW/NEG
Grype DB 2026-10-08T06:33:47.000Z · rubric cerodeo-v1

RUBRIC BREAKDOWN (9 signals that moved the score)

-50 · Critical CVEs (fixable) -140 · High CVEs (fixable) -51 · Medium CVEs (fixable) -64 · Critical CVEs (no fix) -51 · High CVEs (no fix) +10 · Rebuilt in last 90 days +3 · OCI standard labels (≥4) +2 · Multi-arch +2 · readme_has_example

Raw data

Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.

Latest scan JSON (CVE matches) Full scan history JSON (1 snapshots)

All open CVEs (96)

sorted by severity, then CVSS score
CVE ID SEV CVSS PACKAGE FIX
CVE-2026-10536 CRITICAL 9.8 curl 8.14.1-r3 no fix available
CVE-2026-11856 CRITICAL 9.8 curl 8.14.1-r3 no fix available
CVE-2026-19931 CRITICAL 9.8 curl 8.14.1-r3 no fix available
CVE-2026-9079 CRITICAL 9.8 curl 8.14.1-r3 no fix available
CVE-2026-18924 CRITICAL 9.1 curl 8.14.1-r3 no fix available
CVE-2026-8924 CRITICAL 9.1 curl 8.14.1-r3 no fix available
CVE-2026-8926 CRITICAL 9.1 curl 8.14.1-r3 no fix available
CVE-2026-8927 CRITICAL 9.1 curl 8.14.1-r3 no fix available
GHSA-9pwp-9qqc-pr26 CRITICAL 9.1 bcprov-jdk18on 1.78.1 fixed in 1.85
GHSA-574f-3g2m-x479 CRITICAL 7.5 bcprov-jdk18on 1.78.1 fixed in 1.80.2
GHSA-r7wm-3cxj-wff9 HIGH 8.7 jackson-core 2.15.2 fixed in 2.18.8
CVE-2026-85091 HIGH 8.3 zlib 1.3.2-r0 fixed in 1.3.2-r1
CVE-2026-82209 HIGH 8.2 curl 8.14.1-r3 no fix available
CVE-2026-8286 HIGH 8.1 curl 8.14.1-r3 no fix available
GHSA-j3rv-43j4-c7qm HIGH 8.1 jackson-databind 2.15.2 fixed in 2.18.8
GHSA-rmj7-2vxq-3g9f HIGH 8.1 jackson-databind 2.15.2 fixed in 2.18.8
CVE-2026-12064 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-3805 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-5773 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-6276 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-80229 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-80230 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-80231 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-80255 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-82208 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-8932 HIGH 7.5 curl 8.14.1-r3 no fix available
CVE-2026-9545 HIGH 7.5 curl 8.14.1-r3 no fix available
GHSA-65r4-943x-97jj HIGH 7.5 jsoup 1.16.1 fixed in 1.23.2
GHSA-78wr-2p64-hpwj HIGH 7.5 commons-io 2.13.0 fixed in 2.14.0
GHSA-7hhh-6rmp-j9qf HIGH 7.5 jackson-core 2.15.2 fixed in 2.18.11
GHSA-9299-c6m4-mjhc HIGH 7.5 jetty-server 11.0.15 fixed in 11.0.23
GHSA-cxp5-3px4-pw24 HIGH 7.5 jackson-databind 2.15.2 fixed in 2.18.11
GHSA-m6cj-93v6-cvr5 HIGH 7.5 junrar 3.0.1-Ubooquity fixed in 7.4.1
GHSA-q4xh-88c3-wmh7 HIGH 7.5 jackson-databind 2.15.2 fixed in 2.18.10
GHSA-qp49-qgx5-5m26 HIGH 7.5 bcprov-jdk18on 1.78.1 fixed in 1.85
GHSA-wv8q-qhhj-9h54 HIGH 7.5 jackson-databind 2.15.2 fixed in 2.18.11
CVE-2026-13608 HIGH 7.4 curl 8.14.1-r3 no fix available
CVE-2026-9547 HIGH 7.4 curl 8.14.1-r3 no fix available
GHSA-355h-qmc2-wpwf HIGH 7.4 jetty-http 11.0.15 fixed in 11.0.29
CVE-2026-9080 HIGH 7.3 curl 8.14.1-r3 no fix available
CVE-2026-56109 HIGH 7.0 alsa-lib 1.2.14-r0 no fix available
GHSA-72hv-8253-57qq MEDIUM 6.9 jackson-core 2.15.2 fixed in 2.18.6
CVE-2016-2781 MEDIUM 6.5 coreutils 9.7-r1 no fix available
CVE-2016-2781 MEDIUM 6.5 coreutils-sha512sum 9.7-r1 no fix available
CVE-2016-2781 MEDIUM 6.5 coreutils-env 9.7-r1 no fix available
CVE-2016-2781 MEDIUM 6.5 coreutils-fmt 9.7-r1 no fix available
CVE-2025-60876 MEDIUM 6.5 busybox 1.37.0-r20 no fix available
CVE-2025-60876 MEDIUM 6.5 busybox-binsh 1.37.0-r20 no fix available
CVE-2025-60876 MEDIUM 6.5 ssl_client 1.37.0-r20 no fix available
CVE-2026-1965 MEDIUM 6.5 curl 8.14.1-r3 no fix available
CVE-2026-3784 MEDIUM 6.5 curl 8.14.1-r3 no fix available
CVE-2026-8458 MEDIUM 6.5 curl 8.14.1-r3 no fix available
GHSA-3pjw-73gf-8qr5 MEDIUM 6.5 jackson-databind 2.15.2 fixed in 2.18.8
GHSA-j288-q9x7-2f5v MEDIUM 6.5 commons-lang3 3.12.0 fixed in 3.18.0
CVE-2025-14017 MEDIUM 6.3 curl 8.14.1-r3 no fix available
CVE-2026-58055 MEDIUM 6.3 nghttp2-libs 1.69.0-r0 no fix available
CVE-2026-56391 MEDIUM 6.1 coreutils-fmt 9.7-r1 no fix available
CVE-2026-56391 MEDIUM 6.1 coreutils-env 9.7-r1 no fix available
CVE-2026-56391 MEDIUM 6.1 coreutils 9.7-r1 no fix available
CVE-2026-56391 MEDIUM 6.1 coreutils-sha512sum 9.7-r1 no fix available
CVE-2025-13034 MEDIUM 5.9 curl 8.14.1-r3 no fix available
CVE-2026-4873 MEDIUM 5.9 curl 8.14.1-r3 no fix available
CVE-2026-6253 MEDIUM 5.9 curl 8.14.1-r3 no fix available
GHSA-25qh-j22f-pwp8 MEDIUM 5.9 logback-core 1.5.6 fixed in 1.5.19
GHSA-g8m5-722r-8whq MEDIUM 5.9 jetty-server 11.0.15 fixed in 11.0.24
GHSA-hf5p-q87m-crj7 MEDIUM 5.9 junrar 3.0.1-Ubooquity fixed in 7.5.10
GHSA-j273-m5qq-6825 MEDIUM 5.9 junrar 3.0.1-Ubooquity fixed in 7.5.8
GHSA-pr98-23f8-jwxv MEDIUM 5.9 logback-core 1.5.6 fixed in 1.5.13
GHSA-gx83-3vf8-gh7j MEDIUM 5.6 jackson-databind 2.15.2 fixed in 2.18.10
GHSA-c3fc-8qff-9hwx MEDIUM 5.5 bcprov-jdk18on 1.78.1 fixed in 1.84
CVE-2025-14524 MEDIUM 5.3 curl 8.14.1-r3 no fix available
CVE-2025-14819 MEDIUM 5.3 curl 8.14.1-r3 no fix available
CVE-2025-15079 MEDIUM 5.3 curl 8.14.1-r3 no fix available
CVE-2026-23865 MEDIUM 5.3 freetype 2.13.3-r0 no fix available
CVE-2026-3783 MEDIUM 5.3 curl 8.14.1-r3 no fix available
CVE-2026-6429 MEDIUM 5.3 curl 8.14.1-r3 no fix available
CVE-2026-7168 MEDIUM 5.3 curl 8.14.1-r3 no fix available
GHSA-5jmj-h7xm-6q6v MEDIUM 5.3 jackson-databind 2.15.2 fixed in 2.18.9
GHSA-7p3p-8qv8-m2vh MEDIUM 5.3 jetty-server 11.0.15 no fix available
GHSA-hgj6-7826-r7m5 MEDIUM 5.3 jackson-databind 2.15.2 fixed in 2.18.8
GHSA-hmr7-m48g-48f6 MEDIUM 5.3 jetty-http 11.0.15 fixed in 11.0.16
GHSA-vvgp-rfg2-7rr6 MEDIUM 5.3 jackson-databind 2.15.2 fixed in 2.18.9
GHSA-wjgm-6hv5-3cvf MEDIUM 5.3 jackson-databind 2.15.2 fixed in 2.18.10
CVE-2026-90781 MEDIUM 4.8 alsa-lib 1.2.14-r0 no fix available
CVE-2026-96674 MEDIUM 4.8 alsa-lib 1.2.14-r0 no fix available
CVE-2026-96675 MEDIUM 4.8 alsa-lib 1.2.14-r0 no fix available
GHSA-pmhh-3w7g-xqp8 MEDIUM 4.7 jsoup 1.16.1 fixed in 1.23.1
CVE-2025-10966 MEDIUM 4.3 curl 8.14.1-r3 no fix available
GHSA-qh8g-58pp-2wxh MEDIUM 3.7 jetty-http 11.0.15 fixed in 12.0.12
GHSA-89m4-43j5-vhhx LOW 3.7 junrar 3.0.1-Ubooquity fixed in 7.6.1
GHSA-wjpw-4j6x-6rwh LOW 3.7 jetty-http 11.0.15 no fix available
CVE-2025-15224 LOW 3.1 curl 8.14.1-r3 no fix available
GHSA-jhq6-gfmj-v8fx LOW 2.9 logback-core 1.5.6 fixed in 1.5.34
GHSA-6v67-2wr5-gvf4 LOW 2.4 logback-core 1.5.6 fixed in 1.5.13
GHSA-qqpg-mvqg-649v LOW 1.8 logback-core 1.5.6 fixed in 1.5.25
GHSA-p47f-322f-whfh LOW 1.2 logback-core 1.5.6 fixed in 1.5.33

Scan history

1 total · first yesterday
SCANNED AT GRADE SCORE CRIT HIGH MED GRYPE DB
yesterday F 0 10 31 48 2026-10-08T06:33:47.000Z