Vulnerability Reportanchore/grype:v0.110.0

anchore/grype:v0.110.0
DIGESTsha256:af65fbc0c664691067788fe95ff88760b435543e45595eb2ca6f102fc476fbe1

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The only notable vulnerability (CVE-2026-45570) in the go-git library could lead to remote code execution when cloning a malicious SSH repository, but this requires the container to be configured to perform SSH git clone operations, which is not the default. Using HTTPS instead of SSH fully mitigates this risk. Other reported vulnerabilities have low severity (max 2.81) and pose minimal threat.

Vulnerabilities

Vulnerability Log

38 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45570MEDIUM6.53
github.com/go-git/go-git/v5
v5.17.0
fixed in 5.19.1
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.40.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.25.8
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45022MEDIUM5.1
github.com/go-git/go-git/v5
v5.17.0
fixed in 5.19.0
0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34986MEDIUM5.1
github.com/go-jose/go-jose/v4
v4.1.3
fixed in 4.1.4
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4660MEDIUM5.1
github.com/hashicorp/go-getter
v1.8.5
fixed in 1.8.6
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32280MEDIUM5.1
stdlib
v1.25.8
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32281MEDIUM5.1
stdlib
v1.25.8
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32283MEDIUM5.1
stdlib
v1.25.8
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.25.8
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.25.8
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-41506MEDIUM5.03
github.com/go-git/go-git/v5
v5.17.0
fixed in 5.18.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32288MEDIUM4.67
stdlib
v1.25.8
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34165MEDIUM4.25
github.com/go-git/go-git/v5
v5.17.0
fixed in 5.17.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34040LOW2.81
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
8.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-33997LOW2.48
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-33762LOW2.38
github.com/go-git/go-git/v5
v5.17.0
fixed in 5.17.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-29181LOW2.29
go.opentelemetry.io/otel
v1.40.0
fixed in 1.41.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.25.8
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.25.8
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42306LOW2.2
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-32289LOW1.87
stdlib
v1.25.8
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39826LOW1.65
stdlib
v1.25.8
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
GHSA-xmrv-pmrh-hhx2NONE0
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
v1.7.4
fixed in 1.7.8
Not Applicable
GHSA-xmrv-pmrh-hhx2NONE0
github.com/aws/aws-sdk-go-v2/service/s3
v1.96.0
fixed in 1.97.3
Not Applicable
CVE-2026-46680NONE0
github.com/containerd/containerd/v2
v2.2.1
fixed in 2.0.9, 2.2.4, 2.3.1
Not Applicable
CVE-2026-41567NONE0
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-41568NONE0
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-44973NONE0
github.com/go-git/go-billy/v5
v5.8.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44740NONE0
github.com/go-git/go-billy/v5
v5.8.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-45571NONE0
github.com/go-git/go-git/v5
v5.17.0
fixed in 5.19.1
0.3%
Theoretical Threat
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.17.0
fixed in 5.19.1
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.25.8
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.25.8
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.25.8
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.25.8
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.25.8
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.25.8
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable