Alpine Linux Security Advisory archive

308 months of Alpine-ecosystem security advisories indexed by Vulnetix.

Every advisory from the Alpine secdb feed, covering the aports source-package world for Alpine 3.18, 3.19, 3.20, 3.21, and edge, plus the same packages shipped across four container registries: Docker Hub's Official Alpine, Chainguard hardened, Wolfi undistro, and Red Hat hardened. Same upstream package, different vulnerability footprint per registry. Enriched live with Vulnetix VDB exploit intelligence. Latest month: August 2026 · 205 advisories.

Same upstream package, four different registries

Alpine packages are pulled from Docker Hub, Chainguard, Wolfi, and the Red Hat hardened registry. Each shows a different vulnerability footprint for the same upstream source.

Docker Hub (Official Alpine)

standard

Upstream Alpine Linux maintainers' official image, distributed via Docker Hub. The canonical "alpine:<version>" reference most projects pin against.

Total
10,497
30d
9,122
90d
10,497
$ docker pull docker.io/library/alpine
Open registry →

Chainguard Images

hardened

Chainguard hardened distroless / minimal images built on the Wolfi undistro. Alpine workloads frequently rebased here for reduced CVE footprint.

Total
19,914
30d
19,347
90d
19,914
$ docker pull cgr.dev/chainguard/wolfi-base
Open registry →

Wolfi Linux

minimal

Wolfi is a community Linux undistro from Chainguard, glibc-based but designed in the spirit of Alpine. Frequent destination when migrating off musl-Alpine.

Total
14,135
30d
13,492
90d
14,135
$ docker pull cgr.dev/chainguard/wolfi-base
Open registry →

Red Hat Hardened Registry

hardened

Red Hat Container Catalog hardened images. Includes Universal Base Image (UBI) variants suited for Alpine-style minimal workloads under Red Hat support.

Total
19,687
30d
2,931
90d
19,687
$ docker pull registry.access.redhat.com/ubi9-minimal
Open registry →

2026

2025

2024

2023

2022

2021

2020

2019

2018

2017

2016

2015

2014

2013

2012

2011

2010

2009

2008

2007

2006

2005

2004

2003

2002

2001

1999

1997

Track a CVE across registries

The same upstream Alpine package can have a different vulnerability footprint on every registry that ships it. Vulnetix VDB indexes all four.