Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could exploit CVE-2026-33630 by sending crafted DNS responses to trigger a use-after-free, potentially causing denial of service or arbitrary code execution in Trivy, which regularly performs DNS lookups. Restricting outbound DNS traffic to trusted resolvers and using network segmentation can reduce exposure to this threat. Overall, the presence of a high-severity exposed vulnerability in a critical dependency warrants caution, though the image is otherwise well-maintained and trusted.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-33630 | HIGH7.5 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | — | Directly ExposedContext importance: HIGH |
| CVE-2026-50151 | MEDIUM5.9 | oras.land/oras-go/v2 v2.6.0 fixed in 2.6.1 | — | Directly ExposedContext importance: HIGH |
| CVE-2026-50163 | MEDIUM5.9 | oras.land/oras-go/v2 v2.6.0 No fix yet | — | Directly ExposedContext importance: HIGH |
| CVE-2026-50162 | MEDIUM5.3 | oras.land/oras-go/v2 v2.6.0 fixed in 2.6.1 | — | Directly ExposedContext importance: HIGH |
| CVE-2026-9546 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-11564 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-48978 | LOW3.1 | oras.land/oras-go/v2 v2.6.0 fixed in 2.6.1 | — | Directly Exposed |
| CVE-2026-8925 | LOW2.92 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11352 | LOW2.7 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-9079 | LOW2.7 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW2.34 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11586 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-49835 | LOW2.12 | github.com/sigstore/timestamp-authority/v2 v2.0.6 fixed in 2.1.0 | — | Post-Exploit |
| CVE-2026-8458 | NONE0 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-49834 | NONE0 | github.com/sigstore/sigstore-go v1.1.4 fixed in 1.2.0 | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.53.0 No fix yet | — | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.55.0 fixed in 0.56.0 | — | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.38.0 fixed in 0.39.0 | — | Not Applicable |
| GHSA-vh4v-2xq2-g5cg | NONE0 | oras.land/oras-go/v2 v2.6.0 fixed in 2.6.1 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.