Alpine Linux Security Advisory archive

309 months of Alpine-ecosystem security advisories indexed by Vulnetix.

Every advisory from the Alpine secdb feed, covering the aports source-package world for Alpine 3.18, 3.19, 3.20, 3.21, and edge, plus the same packages shipped across four container registries: Docker Hub's Official Alpine, Chainguard hardened, Wolfi undistro, and Red Hat hardened. Same upstream package, different vulnerability footprint per registry. Enriched live with Vulnetix VDB exploit intelligence. Latest month: September 2026 · 32 advisories.

Same upstream package, four different registries

Alpine packages are pulled from Docker Hub, Chainguard, Wolfi, and the Red Hat hardened registry. Each shows a different vulnerability footprint for the same upstream source.

Docker Hub (Official Alpine)

standard

Upstream Alpine Linux maintainers' official image, distributed via Docker Hub. The canonical "alpine:<version>" reference most projects pin against.

Total
10,824
30d
9,407
90d
9,765
$ docker pull docker.io/library/alpine
Open registry →

Chainguard Images

hardened

Chainguard hardened distroless / minimal images built on the Wolfi undistro. Alpine workloads frequently rebased here for reduced CVE footprint.

Total
22,003
30d
21,430
90d
21,438
$ docker pull cgr.dev/chainguard/wolfi-base
Open registry →

Wolfi Linux

minimal

Wolfi is a community Linux undistro from Chainguard, glibc-based but designed in the spirit of Alpine. Frequent destination when migrating off musl-Alpine.

Total
16,410
30d
15,728
90d
15,767
$ docker pull cgr.dev/chainguard/wolfi-base
Open registry →

Red Hat Hardened Registry

hardened

Red Hat Container Catalog hardened images. Includes Universal Base Image (UBI) variants suited for Alpine-style minimal workloads under Red Hat support.

Total
20,126
30d
1,522
90d
4,251
$ docker pull registry.access.redhat.com/ubi9-minimal
Open registry →

2026

2025

2024

2023

2022

2021

2020

2019

2018

2017

2016

2015

2014

2013

2012

2011

2010

2009

2008

2007

2006

2005

2004

2003

2002

2001

1999

1997

Track a CVE across registries

The same upstream Alpine package can have a different vulnerability footprint on every registry that ships it. Vulnetix VDB indexes all four.