Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. One moderate-severity vulnerability (CVE-2026-33630) exists in the c-ares library, which could lead to denial of service or memory corruption if the container receives a crafted malicious DNS response. However, exploitation requires the attacker to control the DNS server or be on the network path, making it not directly triggerable from inbound HTTP traffic. The image is from Docker Official and pinned by digest, ensuring a trusted baseline. As a best practice, ensure the container uses a trusted DNS resolver and restrict network exposure to limit attack surface.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-33630 | MEDIUM6 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | — | Directly ExposedContext importance: MEDIUM |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.