Vulnerability Reportanchore/syft:v1.43.0

anchore/syft:v1.43.0
DIGESTsha256:0bf6a5b15e854c53bd8b09abe5d1ff12c07bdb06c6edc9b2df99643049233d28

Executive Summary

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. It contains 13 low-severity vulnerabilities (max 5.1) and 5 post-exploit findings (max 3.92), but none pose a realistic threat to the container's operation. The image is from a high-reputation publisher and pinned by digest, ensuring integrity. No further action is required.

Vulnerabilities

Vulnerability Log

18 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33811MEDIUM5.1
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-45570LOW3.92
github.com/go-git/go-git/v5
v5.18.0
fixed in 5.19.1
0.4%
Theoretical Threat
Post-ExploitContext importance: MEDIUM
CVE-2026-45022LOW3.06
github.com/go-git/go-git/v5
v5.18.0
fixed in 5.19.0
0.1%
Theoretical Threat
Post-ExploitContext importance: MEDIUM
CVE-2026-39820LOW2.29
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39826LOW1.65
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-46680NONE0
github.com/containerd/containerd/v2
v2.2.2
fixed in 2.0.9, 2.2.4, 2.3.1
Not Applicable
CVE-2026-44973NONE0
github.com/go-git/go-billy/v5
v5.8.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44740NONE0
github.com/go-git/go-billy/v5
v5.8.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-45571NONE0
github.com/go-git/go-git/v5
v5.18.0
fixed in 5.19.1
0.3%
Theoretical Threat
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.18.0
fixed in 5.19.1
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable