Last scanned:
This image is safe for production use. Although the surface scan reports 28 findings, their maximum severity is 0.0 and none reach the severity threshold for concern, and there are no post-exploit findings. As an official Docker image pinned by digest, the overall threat score is 0, making this image suitable for production deployment.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-14662 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14663 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14664 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14666 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14668 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14669 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14670 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14671 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14672 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14673 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14676 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14677 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14678 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14679 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14680 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-14681 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-15741 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-15742 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-16238 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-16239 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-16241 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-18024 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-18408 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-19385 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-6464 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-6469 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-6470 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
| CVE-2026-6471 | NONE0 | libpq 18.4-r0 fixed in 18.5-r0 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.