home / Nextcloud / linuxserver/nextcloud:35.0.1-ls454 linuxserver/nextcloud:35.0.1-ls454 docker pull linuxserver/nextcloud:35.0.1-ls454 click to select
Image metadata PULL COUNT
325.5M
repository-level (not per-tag)
RUNS AS
root
image config.User
LAST PUSHED
3d ago
2026-10-06 18:35:10
MANIFEST DIGEST
sha256:da439b3e182d…
from registry manifest
Latest scan 2026-10-09 23:33:33 UTC · today OPEN CVES BY SEVERITY
Grype DB 2026-10-09T06:32:32.000Z
· rubric cerodeo-v1
RUBRIC BREAKDOWN (9 signals that moved the score) -75 · Critical CVEs (fixable) -150 · High CVEs (fixable) -15 · Medium CVEs (fixable) -312 · Critical CVEs (no fix) -966 · High CVEs (no fix) +10 · Rebuilt in last 90 days +3 · OCI standard labels (≥4) +2 · Multi-arch +2 · readme_has_example
Raw data
Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or
massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.
Reproduce this score yourself
We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB.
Run the script below on any host with skopeo, syft,
grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.
curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh
./verify-score.sh linuxserver/nextcloud:35.0.1-ls454 \
--rubric cerodeo-v1 \
--grype-db 2026-10-09T06:32:32.000Z
All open CVEs (500) sorted by severity, then CVSS score CVE ID SEV CVSS PACKAGE FIX
CVE-2014-9826 CRITICAL 9.8 imagemagick-libs 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-jpeg 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-jxl 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-openexr 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-webp 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-tiff 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-svg 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-pdf 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-pango 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick 7.1.2.15-r0 no fix available CVE-2014-9826 CRITICAL 9.8 imagemagick-heic 7.1.2.15-r0 no fix available CVE-2026-56154 CRITICAL 9.8 apache2-utils 2.4.68-r0 fixed in 2.4.69-r0 CVE-2026-57941 CRITICAL 9.8 apache2-utils 2.4.68-r0 fixed in 2.4.69-r0 CVE-2026-59797 CRITICAL 9.8 apache2-utils 2.4.68-r0 fixed in 2.4.69-r0 CVE-2011-2411 HIGH 9.0 samba-util-libs 4.21.9-r1 no fix available CVE-2011-2411 HIGH 9.0 samba-client-libs 4.21.9-r1 no fix available CVE-2025-1594 HIGH 8.8 ffmpeg-libavformat 6.1.2-r2 no fix available CVE-2025-1594 HIGH 8.8 ffmpeg-libavfilter 6.1.2-r2 no fix available CVE-2025-1594 HIGH 8.8 ffmpeg-libavcodec 6.1.2-r2 no fix available CVE-2025-1594 HIGH 8.8 ffmpeg-libavdevice 6.1.2-r2 no fix available CVE-2025-1594 HIGH 8.8 ffmpeg-libavutil 6.1.2-r2 no fix available CVE-2025-1594 HIGH 8.8 ffmpeg-libpostproc 6.1.2-r2 no fix available CVE-2025-1594 HIGH 8.8 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2025-1594 HIGH 8.8 ffmpeg-libswscale 6.1.2-r2 no fix available CVE-2026-66036 HIGH 8.8 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-66040 HIGH 8.8 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-8461 HIGH 8.8 ffmpeg-libswscale 6.1.2-r2 no fix available CVE-2026-8461 HIGH 8.8 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-8461 HIGH 8.8 ffmpeg-libpostproc 6.1.2-r2 no fix available CVE-2026-8461 HIGH 8.8 ffmpeg-libavutil 6.1.2-r2 no fix available CVE-2026-8461 HIGH 8.8 ffmpeg-libavformat 6.1.2-r2 no fix available CVE-2026-8461 HIGH 8.8 ffmpeg-libavfilter 6.1.2-r2 no fix available CVE-2026-8461 HIGH 8.8 ffmpeg-libavdevice 6.1.2-r2 no fix available CVE-2026-8461 HIGH 8.8 ffmpeg-libavcodec 6.1.2-r2 no fix available CVE-2026-64830 HIGH 8.7 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-64832 HIGH 8.7 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-64834 HIGH 8.7 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-64835 HIGH 8.7 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-65703 HIGH 8.5 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-65706 HIGH 8.5 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2026-70632 HIGH 8.5 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2023-49501 HIGH 8.0 ffmpeg-libswresample 6.1.2-r2 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-jpeg 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-pdf 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-pango 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-openexr 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-jxl 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-heic 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-webp 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-tiff 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-libs 7.1.2.15-r0 no fix available CVE-2017-5506 HIGH 7.8 imagemagick-svg 7.1.2.15-r0 no fix available CVE-2025-12495 HIGH 7.8 openexr-libopenexrcore 3.3.11-r0 no fix available CVE-2025-12495 HIGH 7.8 openexr-libilmthread 3.3.11-r0 no fix available CVE-2025-12839 HIGH 7.8 openexr-libopenexrcore 3.3.11-r0 no fix available CVE-2025-12839 HIGH 7.8 openexr-libilmthread 3.3.11-r0 no fix available CVE-2025-12840 HIGH 7.8 openexr-libilmthread 3.3.11-r0 no fix available CVE-2025-12840 HIGH 7.8 openexr-libopenexrcore 3.3.11-r0 no fix available CVE-2026-66039 HIGH 7.8 ffmpeg-libswresample 6.1.2-r2 no fix available
Scan history 2 total · first today SCANNED AT GRADE SCORE CRIT HIGH MED GRYPE DB
today F 0 42 337 266 2026-10-09T06:32:32.000Z · (same SBOM)
today F 0 42 337 266 2026-10-09T06:32:32.000Z
Methodology:
This image is re-matched against the fresh Grype vulnerability DB every hour. Snapshot rows marked
(same SBOM) reuse the prior scan's content via a pointer — about
90% of hourly cycles do. New CVE disclosures land in a new content row and bump the grade on the next match.
Full rubric at /about/grades ; for publishers wanting to
raise their grade, see /about/for-publishers .