Vulnerability Reportarangodb:3.12.7

arangodb:3.12.7.2arangodb:3.12.7
DIGESTsha256:d89d6b6b27e0593e47ec16bcf6374445ce78f429517aa811bf2fec69be86d0ba

Executive Summary

Threat Score
75/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could achieve remote code execution via CVE-2026-4800 if untrusted input reaches lodash template compilation, which is possible given ArangoDB's use of JavaScript for Foxx services. The image contains 28 exposed vulnerabilities, including one critical and four high-severity flaws. Upgrading lodash to version 4.18.0 would eliminate the RCE risk, but until then the container should not be deployed in production.

Vulnerabilities

Vulnerability Log

72 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-4800HIGH7.84
lodash
4.17.21
fixed in 4.18.0
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-28390MEDIUM6.38
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28390MEDIUM6.38
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33750MEDIUM6.38
brace-expansion
1.1.11
fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42306MEDIUM6.12
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27904MEDIUM5.52
minimatch
3.1.2
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-28388MEDIUM5.1
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-28388MEDIUM5.1
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-69873MEDIUM5.1
ajv
8.12.0
fixed in 8.18.0, 6.14.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-15284MEDIUM5.1
qs
6.11.2
fixed in 6.14.1
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-2391MEDIUM5.1
qs
6.11.2
fixed in 6.14.2
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-31790MEDIUM5.02
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
libssl3
3.3.6-r0
fixed in 3.3.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-27903MEDIUM5.02
minimatch
3.1.2
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-64718MEDIUM4.5
js-yaml
3.14.1
fixed in 4.1.1, 3.14.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-13465MEDIUM4.5
lodash
4.17.21
fixed in 4.17.23
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2950MEDIUM4.5
lodash
4.17.21
fixed in 4.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41176MEDIUM4.06
github.com/rclone/rclone
v1.65.2+dirty
fixed in 1.73.5
35.4%
High Exploitation Risk
Post-Exploit
CVE-2025-69725MEDIUM4
github.com/go-chi/chi/v5
v5.2.3
fixed in 5.2.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40200LOW3.98
musl-utils
1.2.5-r9
fixed in 1.2.5-r11
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-41179LOW3.53
github.com/rclone/rclone
v1.65.2+dirty
fixed in 1.73.5
7.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-52522LOW3.47
github.com/rclone/rclone
v1.65.2+dirty
fixed in 1.68.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-41568LOW3.31
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-31789LOW3
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1229LOW3
github.com/cloudflare/circl
v1.6.1
fixed in 1.6.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34040LOW2.81
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
8.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-6042LOW2.8
musl-utils
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33186LOW2.78
google.golang.org/grpc
v1.59.0
fixed in 1.79.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-5889LOW2.63
brace-expansion
1.1.11
fixed in 2.0.2, 1.1.12, 3.0.1, 4.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-28387LOW2.48
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33997LOW2.48
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-40200LOW2.39
musl
1.2.5-r9
fixed in 1.2.5-r11
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22184LOW2.39
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-26996LOW2.29
minimatch
3.1.2
fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-68121NONE0
stdlib
v1.24.11
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Not Applicable
CVE-2025-61726NONE0
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
0.8%
Theoretical Threat
Not Applicable
CVE-2026-25679NONE0
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Not Applicable
CVE-2026-32280NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-32281NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32283NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-33811NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Not Applicable
CVE-2026-33814NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39820NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39836NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2025-61728NONE0
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Not Applicable
CVE-2026-32282NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32289NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32288NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27142NONE0
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39826NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2025-61730NONE0
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27139NONE0
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Not Applicable
CVE-2026-48038NONE0
joi
14.3.1
fixed in 18.2.1, 17.13.4
Not Applicable
CVE-2026-53550NONE0
js-yaml
3.14.1
fixed in 4.2.0
Not Applicable
CVE-2026-8723NONE0
qs
6.11.2
fixed in 6.15.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41567NONE0
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44973NONE0
github.com/go-git/go-billy/v5
v5.5.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44740NONE0
github.com/go-git/go-billy/v5
v5.5.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-49980NONE0
github.com/rclone/rclone
v1.65.2+dirty
fixed in 1.74.3
Not Applicable