Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could cause a denial of service by crashing the Redis process when it makes a TLS connection to a malicious server, but this only occurs if certificate name checks are enabled. Disabling certificate name checks or restricting outbound TLS connections to trusted servers fully mitigates CVE-2024-6119. The image is otherwise from a reliable publisher and pinned by digest, but the single high-severity OpenSSL vulnerability warrants caution.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2024-6119 | HIGH7.8 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 66.6% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2024-0727 | MEDIUM5.5 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-2511 | MEDIUM4.81 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 54.0% Actively Exploited | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.2.13-5.ph5 fixed in 1.3.2-1.ph5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | util-linux-libs 2.41.4-2.ph5 fixed in 2.41.4-3.ph5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | krb5 1.20.2-13.ph5 fixed in 1.20.2-14.ph5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-6129 | LOW3.9 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-55199 | LOW3.82 | libssh2 1.11.1-3.ph5 fixed in 1.11.1-5.ph5 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW3.77 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-0306 | LOW3.77 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2024-9143 | LOW3.7 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | LOW3.54 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-6237 | LOW3.54 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9231 | LOW3.54 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-6119 | LOW3.51 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 66.6% Actively Exploited | Post-Exploit |
| CVE-2025-69418 | LOW3.4 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | LOW3.36 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-0727 | LOW3.3 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34181 | LOW3.21 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42768 | LOW3.21 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-5678 | LOW3.18 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45446 | LOW3.15 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42765 | LOW3.01 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW3.01 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-55200 | LOW2.99 | libssh2 1.11.1-3.ph5 fixed in 1.11.1-4.ph5 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2511 | LOW2.89 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 54.0% Actively Exploited | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-40468 | LOW2.78 | gawk 5.3.2-4.ph5 fixed in 5.3.2-5.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-40469 | LOW2.78 | gawk 5.3.2-4.ph5 fixed in 5.3.2-5.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-40468 | LOW2.78 | gawk-bin 5.3.2-4.ph5 fixed in 5.3.2-5.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-40469 | LOW2.78 | gawk-bin 5.3.2-4.ph5 fixed in 5.3.2-5.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | logger 2.41.4-2.ph5 fixed in 2.41.4-3.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | logger-bin 2.41.4-2.ph5 fixed in 2.41.4-3.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-42767 | LOW2.7 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | util-linux 2.41.4-2.ph5 fixed in 2.41.4-3.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-13176 | LOW2.4 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2023-6129 | LOW2.34 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34182 | LOW2.26 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-0306 | LOW2.26 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2024-9143 | LOW2.22 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42764 | LOW2.12 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-6237 | LOW2.12 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9231 | LOW2.12 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69418 | LOW2.04 | openssl 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-9230 | LOW2.02 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-9149 | LOW1.99 | libsolv 0.7.35-1.ph5 fixed in 0.7.39-1.ph5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9150 | LOW1.99 | libsolv 0.7.35-1.ph5 fixed in 0.7.39-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-5678 | LOW1.91 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42765 | LOW1.81 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW1.81 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW1.81 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-2.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW1.81 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW1.81 | openssl-libs 3.5.6-3.ph5 fixed in 3.5.7-1.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | NONE0 | stdlib v1.26.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42505 | NONE0 | stdlib v1.26.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-11822 | NONE0 | sqlite-libs 3.43.2-6.ph5 fixed in 3.43.2-7.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-11824 | NONE0 | sqlite-libs 3.43.2-6.ph5 fixed in 3.43.2-7.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.33.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.