Vulnerability Reportbash:5.2.37

bash:5.2.37-alpine3.22bash:5.2.37bash:5.2-alpine3.22bash:5.2
digestsha256:3bee76a96d86d5d2d5efc7c1c570e5a7c95db22348a26944e0e546fa174e3324

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. The scan reports 2 exposed-surface items and 18 post-exploit-only items, but their maximum severities are 0.0 and 2.7 respectively, and none reach the >=6.0 threshold. No CVE IDs were provided in the top exposed or post-exploit findings, so there are no named high-impact vulnerabilities to act on. Images built on top of this base inherit this low-risk profile, and the official Docker Hub provenance with digest pinning supports its use as a reliable building block. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

20 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-18798LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-14456LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63072LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63072LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63073LOW1.81
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-63073LOW1.81
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-75803NONE0
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-75803NONE0
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.