The current Docker image (ghcr.io/mobilitydata/gtfs-realtime-validator@sha256:ef437eb291259ba16a3a4a0e9a83b18f597a365e3a0fdc9a8a5b73d4a541333d) seems to be based on maven:3.8.5-jdk-11-slim, which includes several critical vulnerabilities.
I recommend setting up some automated system (e.g. Dependabot or Renovate Bot) that submits PRs updating the base image(s).