Vulnerability Reportarangodb:3.12.7.1

arangodb:3.12.7.1
DIGESTsha256:81dc1e0f812b5439f225b9fbdb6e0ac2ca583cf5a81aa82d4387e3a8a3de9571

Executive Summary

Threat Score
75/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could achieve remote code execution via CVE-2026-4800 if Foxx services process untrusted template inputs, or cause denial of service via crafted OpenSSL CMS messages (CVE-2026-28390). The OpenSSL and brace-expansion vulnerabilities are conditional on specific contexts (CMS processing, brace pattern expansion), but the lodash RCE is a direct threat to any JavaScript-driven functionality. Upgrading lodash to 4.18.0 and patching OpenSSL would fully mitigate the most severe issues, but the overall exposure remains unacceptable.

Vulnerabilities

Vulnerability Log

72 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-4800HIGH7.84
lodash
4.17.21
fixed in 4.18.0
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-28390MEDIUM6.38
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28390MEDIUM6.38
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33750MEDIUM6.38
brace-expansion
1.1.11
fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42306MEDIUM6.12
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27904MEDIUM5.52
minimatch
3.1.2
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-28388MEDIUM5.1
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-28388MEDIUM5.1
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-69873MEDIUM5.1
ajv
8.12.0
fixed in 8.18.0, 6.14.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-15284MEDIUM5.1
qs
6.11.2
fixed in 6.14.1
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-2391MEDIUM5.1
qs
6.11.2
fixed in 6.14.2
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-31790MEDIUM5.02
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
libssl3
3.3.6-r0
fixed in 3.3.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-27903MEDIUM5.02
minimatch
3.1.2
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl-utils
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-64718MEDIUM4.5
js-yaml
3.14.1
fixed in 4.1.1, 3.14.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-13465MEDIUM4.5
lodash
4.17.21
fixed in 4.17.23
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2950MEDIUM4.5
lodash
4.17.21
fixed in 4.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41176MEDIUM4.06
github.com/rclone/rclone
v1.65.2+dirty
fixed in 1.73.5
35.4%
High Exploitation Risk
Post-Exploit
CVE-2025-69725MEDIUM4
github.com/go-chi/chi/v5
v5.2.3
fixed in 5.2.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41179LOW3.53
github.com/rclone/rclone
v1.65.2+dirty
fixed in 1.73.5
7.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-52522LOW3.47
github.com/rclone/rclone
v1.65.2+dirty
fixed in 1.68.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-41568LOW3.31
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-31789LOW3
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1229LOW3
github.com/cloudflare/circl
v1.6.1
fixed in 1.6.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34040LOW2.81
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
8.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-33186LOW2.78
google.golang.org/grpc
v1.59.0
fixed in 1.79.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-5889LOW2.63
brace-expansion
1.1.11
fixed in 2.0.2, 1.1.12, 3.0.1, 4.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-28387LOW2.48
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33997LOW2.48
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-40200LOW2.39
musl
1.2.5-r9
fixed in 1.2.5-r11
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-40200LOW2.39
musl-utils
1.2.5-r9
fixed in 1.2.5-r11
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22184LOW2.39
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-26996LOW2.29
minimatch
3.1.2
fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-68121NONE0
stdlib
v1.24.11
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Not Applicable
CVE-2025-61726NONE0
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
0.8%
Theoretical Threat
Not Applicable
CVE-2026-25679NONE0
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Not Applicable
CVE-2026-32280NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-32281NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32283NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-33811NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Not Applicable
CVE-2026-33814NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39820NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39836NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2025-61728NONE0
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Not Applicable
CVE-2026-32282NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32289NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32288NONE0
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27142NONE0
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39826NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2025-61730NONE0
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27139NONE0
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Not Applicable
CVE-2026-48038NONE0
joi
14.3.1
fixed in 18.2.1, 17.13.4
Not Applicable
CVE-2026-53550NONE0
js-yaml
3.14.1
fixed in 4.2.0
Not Applicable
CVE-2026-8723NONE0
qs
6.11.2
fixed in 6.15.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41567NONE0
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44973NONE0
github.com/go-git/go-billy/v5
v5.5.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44740NONE0
github.com/go-git/go-billy/v5
v5.5.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-49980NONE0
github.com/rclone/rclone
v1.65.2+dirty
fixed in 1.74.3
Not Applicable