Vulnerability Reportbitnami/valkey-sentinel:latest

bitnami/valkey-sentinel:latest
digestsha256:85a651635eb8d2e6039d90111d4ca8056e982ced4e73e2ceec99e5b12a18dfb6

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
UNVERIFIED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. A malicious Redis/Valkey server could exploit CVE-2024-6119 to crash the sentinel process, causing a denial of service, if TLS certificate name checks are enabled. This vulnerability is not reachable under default configurations and can be fully mitigated by disabling the certificate name-check feature. The image also has a large number of lower-severity vulnerabilities, and its trust status is unverified, so strict access controls and constant monitoring are required.

Vulnerabilities

Vulnerability Log

78 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2024-6119HIGH7.8
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
66.6%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2024-0727MEDIUM5.5
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-2511MEDIUM4.81
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
54.0%
Actively Exploited
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.13-5.ph5
fixed in 1.3.2-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
util-linux-libs
2.41.4-2.ph5
fixed in 2.41.4-3.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5
1.20.2-13.ph5
fixed in 1.20.2-14.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-6129LOW3.9
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-55199LOW3.82
libssh2
1.11.1-3.ph5
fixed in 1.11.1-5.ph5
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW3.77
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-0306LOW3.77
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2024-9143LOW3.7
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764LOW3.54
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-6237LOW3.54
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-9231LOW3.54
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2024-6119LOW3.51
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
66.6%
Actively Exploited
Post-Exploit
CVE-2025-69418LOW3.4
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-9230LOW3.36
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-0727LOW3.3
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-34181LOW3.21
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-5678LOW3.18
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-45446LOW3.15
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42765LOW3.01
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-22796LOW3.01
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW3
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34180LOW3
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-55200LOW2.99
libssh2
1.11.1-3.ph5
fixed in 1.11.1-4.ph5
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2024-2511LOW2.89
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
54.0%
Actively Exploited
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-22795LOW2.8
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-40468LOW2.78
gawk
5.3.2-4.ph5
fixed in 5.3.2-5.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-40469LOW2.78
gawk
5.3.2-4.ph5
fixed in 5.3.2-5.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-40468LOW2.78
gawk-bin
5.3.2-4.ph5
fixed in 5.3.2-5.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-40469LOW2.78
gawk-bin
5.3.2-4.ph5
fixed in 5.3.2-5.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.7
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-3184LOW2.7
logger
2.41.4-2.ph5
fixed in 2.41.4-3.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
logger-bin
2.41.4-2.ph5
fixed in 2.41.4-3.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux
2.41.4-2.ph5
fixed in 2.41.4-3.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-13176LOW2.4
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-68160LOW2.4
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2023-6129LOW2.34
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-34182LOW2.26
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-0306LOW2.26
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2024-9143LOW2.22
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
5.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-42764LOW2.12
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-6237LOW2.12
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-9231LOW2.12
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-69418LOW2.04
openssl
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-9230LOW2.02
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-9149LOW1.99
libsolv
0.7.35-1.ph5
fixed in 0.7.39-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9150LOW1.99
libsolv
0.7.35-1.ph5
fixed in 0.7.39-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-5678LOW1.91
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42765LOW1.81
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-22796LOW1.81
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-2.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW1.81
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW1.81
openssl-libs
3.5.6-3.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11822NONE0
sqlite-libs
3.43.2-6.ph5
fixed in 3.43.2-7.ph5
0.2%
Theoretical Threat
Not Applicable
CVE-2026-11824NONE0
sqlite-libs
3.43.2-6.ph5
fixed in 3.43.2-7.ph5
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.