My question: Still errors. Seems like nothing is working to fix it: Last checked: 9/17/2026, 11:19:06 AM Checked against the current list of known security problems. 3 of your 3 apps have security advisories to review. These are known package advisories, not detected attacks. Counts can repeat across images. This scan does not establish whether a vulnerability is exploitable on this box. core: package advisories need review Review advisories 440 findings list a package fix. This does not confirm that a patched container image is available. Check Updates for supported image refreshes, then scan again after updating. 19 critical findings and 625 high-severity findings — review details media: package advisories need review Review advisories 298 findings list a package fix. This does not confirm that a patched container image is available. Check Updates for supported image refreshes, then scan again after updating. 15 critical findings and 350 high-severity findings — review details files: package advisories need review Review advisories 2 findings list a package fix. This does not confirm that a patched container image is available. Check Updates for supported image refreshes, then scan again after updating. 2 high-severity findings — review details SparkBox AI replied: Yeah, the scan is working now. It’s reporting the same advisories after the update. What this proves: - Containers were recreated successfully. - The …(reply truncated — full chat sent to Tom) After trying to fix it with the AI, I still have 3 known security problems: Last checked: 9/17/2026, 11:19:06 AM Checked against the current list of known security problems. 3 of your 3 apps have security advisories to review. These are known package advisories, not detected attacks. Counts can repeat across images. This scan does not establish whether a vulnerability is exploitable on this box. core: package advisories need review Review advisories 440 findings list a package fix. This does not confirm that a patched container image is available. Check Updates for supported image refreshes, then scan again after updating. 19 critical findings and 625 high-severity findings — review details Affected image checks: ghcr.io/gethomepage/homepage:v2.2.0 — 1 critical / 13 high findings jc21/nginx-proxy-manager:2.15.1 — 18 critical / 601 high findings portainer/portainer-ce:2.45.0 — 0 critical / 11 high findings Example findings from this scan (up to 10): CVE-2026-59873 · CRITICAL · tar 7.5.11 ghcr.io/gethomepage/homepage:v2.2.0 Package fix listed: 7.5.19 CVE-2026-13221 · CRITICAL · libperl5.40 5.40.1-6 jc21/nginx-proxy-manager:2.15.1 Package fix listed: 5.40.1-6+deb13u1 CVE-2026-13221 · CRITICAL · perl 5.40.1-6 jc21/nginx-proxy-manager:2.15.1 Package fix listed: 5.40.1-6+deb13u1 CVE-2026-13221 · CRITICAL · perl-base 5.40.1-6 jc21/nginx-proxy-manager:2.15.1 Package fix listed: 5.40.1-6+deb13u1 CVE-2026-13221 · CRITICAL · perl-modules-5.40 5.40.1-6 jc21/nginx-proxy-manager:2.15.1 Package fix listed: 5.40.1-6+deb13u1 CVE-2026-42496 · CRITICAL · libperl5.40 5.40.1-6 jc21/nginx-proxy-manager:2.15.1 Package fix listed: 5.40.1-6+deb13u1 CVE-2026-13149 · HIGH · brace-expansion 2.0.2 ghcr.io/gethomepage/homepage:v2.2.0 Package fix listed: 5.0.7, 1.1.16, 2.1.2 CVE-2026-14257 · HIGH · brace-expansion 2.0.2 ghcr.io/gethomepage/homepage:v2.2.0 Package fix listed: 5.0.8, 3.0.3, 2.1.3, 1.1.17 CVE-2026-14456 · HIGH · libcrypto3 3.5.7-r0 ghcr.io/gethomepage/homepage:v2.2.0 Package fix listed: 3.5.8-r0 CVE-2026-14456 · HIGH · libssl3 3.5.7-r0 ghcr.io/gethomepage/homepage:v2.2.0 Package fix listed: 3.5.8-r0 media: package advisories need review Review advisories 298 findings list a package fix. This does not confirm that a patched container image is available. Check Updates for supported image refreshes, then scan again after updating. 15 critical findings and 350 high-severity findings — review details Affected image checks: ghcr.io/thephaseless/byparr:2.1.0 — 0 critical / 10 high findings jellyfin/jellyfin:12.0 — 4 critical / 72 high findings lscr.io/linuxserver/bazarr:1.6.1 — 0 critical / 3 high findings lscr.io/linuxserver/lidarr:3.1.0 — 1 critical / 11 high findings lscr.io/linuxserver/prowlarr:2.5.2 — 0 critical / 6 high findings lscr.io/linuxserver/qbittorrent:5.2.3 — 0 critical / 0 high findings lscr.io/linuxserver/radarr:6.3.0 — 0 critical / 6 high findings lscr.io/linuxserver/sabnzbd:4.4.1 — 3 critical / 78 high findings lscr.io/linuxserver/sonarr:4.0.19 — 0 critical / 7 high findings qmcgaw/deunhealth:latest@sha256:db1e4fcd3aceeb0da34a83f7a8a5432df586e6d0388ddb6ad8dd7b479e4aa25d — 1 critical / 31 high findings qmcgaw/gluetun:v3.41.3 — 0 critical / 26 high findings seerr/seerr:v3.4.1 — 6 critical / 100 high findings Example findings from this scan (up to 10): CVE-2026-13221 · CRITICAL · perl-base 5.40.1-6 jellyfin/jellyfin:12.0 Package fix listed: 5.40.1-6+deb13u1 CVE-2026-42496 · CRITICAL · perl-base 5.40.1-6 jellyfin/jellyfin:12.0 Package fix listed: 5.40.1-6+deb13u1 CVE-2026-8376 · CRITICAL · perl-base 5.40.1-6 jellyfin/jellyfin:12.0 Package fix listed: 5.40.1-6+deb13u1 CVE-2025-55315 · CRITICAL · Microsoft.AspNetCore.App.Runtime.linux-musl-x64 8.0.12 lscr.io/linuxserver/lidarr:3.1.0 Package fix listed: 10.0.0-rc.2.25502.107, 9.0.10, 8.0.21 CVE-2025-3277 · CRITICAL · sqlite-libs 3.48.0-r0 lscr.io/linuxserver/sabnzbd:4.4.1 Package fix listed: 3.48.0-r1 CVE-2026-31789 · CRITICAL · libcrypto3 3.3.3-r0 lscr.io/linuxserver/sabnzbd:4.4.1 Package fix listed: 3.3.7-r0 CVE-2026-31789 · CRITICAL · libssl3 3.3.3-r0 lscr.io/linuxserver/sabnzbd:4.4.1 Package fix listed: 3.3.7-r0 CVE-2025-68121 · CRITICAL · stdlib v1.25.5 qmcgaw/deunhealth:latest@sha256:db1e4fcd3aceeb0da34a83f7a8a5432df586e6d0388ddb6ad8dd7b479e4aa25d Package fix listed: 1.24.13, 1.25.7, 1.26.0-rc.3 CVE-2026-33937 · CRITICAL · handlebars 4.7.8 seerr/seerr:v3.4.1 Package fix listed: 4.7.9 CVE-2026-59873 · CRITICAL · tar 6.2.1 seerr/seerr:v3.4.1 Package fix listed: 7.5.19 files: package advisories need review Review advisories 2 findings list a package fix. This does not confirm that a patched container image is available. Check Updates for supported image refreshes, then scan again after updating. 2 high-severity findings — review details Affected image checks: gtstef/filebrowser:1.5.6-stable — 0 critical / 2 high findings Example findings from this scan (up to 10): CVE-2026-14456 · HIGH · libcrypto3 3.5.7-r0 gtstef/filebrowser:1.5.6-stable Package fix listed: 3.5.8-r0 CVE-2026-14456 · HIGH · libssl3 3.5.7-r0 gtstef/filebrowser:1.5.6-stable Package fix listed: 3.5.8-r0
13 replies
Chris wrote:
Sorry — the earlier AI explanation overclaimed what the update proved. Recreating containers does not make package advisories disappear: a listed package fix is not proof that a patched container image exists, and these findings are not evidence of an attack. I also cannot verify that the update actually changed the images on your box from this scan alone. Please run this on the SparkBox host and reply with only its one-line output (no logs or configuration): sudo sparkbox version Do not delete or rebuild anything yet. Once I have that version, I can tell whether the scanner behavior fix is present; the advisory list itself may still contain upstream findings until the affected image pins receive updates. I have corrected what I know here so this unsupported containers-recreated-proves-the-advisories-are-fixed explanation is not repeated to the next person.
Bigmayes wrote:
SparkBox v1.6.708 The last few times I was denied to continue communicating with you because I was only allowed 10 comments a day so if I don't respond after that you know why ahead of time
Chris wrote:
Thanks — v1.6.708 confirms the scanner behavior fix is present, so this is not evidence that the scan itself is broken. The three warnings are package advisories found in the images currently running; they are not proof of an attack, and a package fix listed by the scanner does not prove that a patched SparkBox image exists. Recreating containers or scanning again will not clear an advisory by itself. Please open Updates and check whether core, media, or files has a supported image update. Apply only an update shown there, then run the security scan again. If no supported update is offered, leave the compose files alone: there is no safe customer-side command to install those package fixes into SparkBox’s pinned images. I have recorded the version you supplied, so you do not need to resend it if the comment limit blocks another reply.
Bigmayes wrote:
I only have one update that says it's optional: These are optional security rebuilds of apps you already have — safe to skip. They apply automatically overnight; you can also pull any of them now. media / jellyfin-media rebuild ? jellyfin/jellyfin:10.11.11 Pull rebuild
Chris wrote:
That optional entry is the supported update the scan is offering: a media / jellypin-media rebuild of the pinned Jellyfin 10.11.11 image. It refreshes that same pinned image; it is not a move to a newer Jellyfin version, and it does not guarantee that advisories in the other media images (such as Seerr, SABnzbd, or the VPN image) will disappear. Please click Pull rebuild for that media entry, let it finish, and then run the security scan again. Do not edit the image tag or install package fixes inside the container. The new scan will show whether that rebuild changed the Jellyfin findings and which remaining advisories still have no supported SparkBox image update.
Bigmayes wrote:
Sorry for the stupid question ahead of time. The jellyfin version I have now says it's 12 and this rebuild update image says 10.11.11, so I guess my question is will this revert the current build back to version 10 or am I looking at this wrong? I'm a newbie so please bare with me
Chris wrote:
I'm sorry — I told you to click Pull rebuild before checking which Jellyfin image you are actually running. Your concern is valid: SparkBox's jellyfin-media service is pinned to Jellyfin 10.11.11, so rebuilding that service would recreate it from 10.11.11; it should not be used to replace a Jellyfin 12 installation. Please do not click Pull rebuild yet. On the SparkBox host, run this one read-only check: sudo docker ps --filter 'name=sb-jellyfin' --format '{{.Names}}\t{{.Image}}' Reply with only that one line. It will show whether this is the media service (sb-jellyfin-media) or the separate standalone service, so we can match the update to the installation you actually use. I have corrected what I know here so this unsupported downgrade advice is not repeated to the next person.
Bigmayes wrote:
sb-jellyfin-media jellyfin/jellyfin:12.0
Chris wrote:
Thanks — that output confirms the container you are using is sb-jellyfin-media running Jellyfin 12.0. Please do not click Pull rebuild: the dashboard entry is for SparkBox’s pinned Jellyfin 10.11.11 image, so applying it to this service would replace your Jellyfin 12 container with 10.11.11. I’m sorry I sent you toward that rebuild before checking the running image. The advisory scan can still list findings for Jellyfin 12, but this SparkBox rebuild is not a safe match for it. Please leave that update untouched and tell me only whether you intentionally installed or upgraded this service to Jellyfin 12; do not delete or rebuild anything. I’ve corrected this guidance so the unsupported downgrade advice is not repeated to the next person.
Bigmayes wrote:
No I didn't install it. I just installed the sparkbox update in the update section on the dashboard. Well I guess theres nothing that can be done to remove or fix those security risk. I was just wanting to clear everything up with the sparkbox build before I made another backup. Anyway thanks again
Chris wrote:
Thanks — that confirms you did not choose Jellyfin 12 yourself. The SparkBox update left sb-jellyfin-media running Jellyfin 12.0 while the supported media image is pinned to 10.11.11, so the optional Pull rebuild entry is not a safe match for the container you are using. Please leave that rebuild untouched and do not delete or recreate the container. You can proceed with your backup while leaving the current service as it is. The remaining advisory findings are not proof of an attack, and there is no safe customer-side command to install those package fixes into SparkBox's pinned images. This version mismatch is recorded for correction; I cannot claim it is fixed yet.
Bigmayes wrote:
One last question and it may be my last allowed by this website. Is there anyway I can use my mega.nz cloud storage account to save my sparkbox scheduled backups automatically
Chris wrote:
Yes, but not as a destination for SparkBox's built-in scheduled backups. Those backups are kept on the SparkBox storage. For an off-site copy, the supported route is the optional Duplicati backup module, which sends the local backup data to a cloud destination. I cannot verify from the current official Duplicati documentation that MEGA/Mega.nz is still an available backend, so I do not want to promise that it is. Without changing SparkBox settings, open the Duplicati web UI, start a new backup job, and check its destination/backend list. If MEGA or Mega.nz is listed, follow Duplicati's current provider instructions there; if it is not listed, use one of the backends it offers. Do not paste your Mega credentials into SparkBox's own backup settings. This is separate from the Jellyfin image mismatch, so you can leave that rebuild untouched while setting up an off-site copy.