Vulnerability Reportaquasec/trivy:latest

aquasec/trivy:latestaquasec/trivy:0.72.0
digestsha256:cffe3f5161a47a6823fbd23d985795b3ed72a4c806da4c4df16266c02accdd6f

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could exploit CVE-2026-33630 by sending crafted DNS responses to trigger a use-after-free, potentially causing denial of service or arbitrary code execution in Trivy, which regularly performs DNS lookups. Restricting outbound DNS traffic to trusted resolvers and using network segmentation can reduce exposure to this threat. Overall, the presence of a high-severity exposed vulnerability in a critical dependency warrants caution, though the image is otherwise well-maintained and trusted.

Vulnerabilities

Vulnerability Log

29 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33630HIGH7.5
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Directly ExposedContext importance: HIGH
CVE-2026-50151MEDIUM5.9
oras.land/oras-go/v2
v2.6.0
fixed in 2.6.1
Directly ExposedContext importance: HIGH
CVE-2026-50163MEDIUM5.9
oras.land/oras-go/v2
v2.6.0
No fix yet
Directly ExposedContext importance: HIGH
CVE-2026-50162MEDIUM5.3
oras.land/oras-go/v2
v2.6.0
fixed in 2.6.1
Directly ExposedContext importance: HIGH
CVE-2026-9546LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-48978LOW3.1
oras.land/oras-go/v2
v2.6.0
fixed in 2.6.1
Directly Exposed
CVE-2026-8925LOW2.92
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11352LOW2.7
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-9079LOW2.7
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-8286LOW2.48
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW2.34
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11586LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-49835LOW2.12
github.com/sigstore/timestamp-authority/v2
v2.0.6
fixed in 2.1.0
Post-Exploit
CVE-2026-8458NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-49834NONE0
github.com/sigstore/sigstore-go
v1.1.4
fixed in 1.2.0
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.55.0
fixed in 0.56.0
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
Not Applicable
GHSA-vh4v-2xq2-g5cgNONE0
oras.land/oras-go/v2
v2.6.0
fixed in 2.6.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.