Vulnerability Reportbuildkite/agent:3

buildkite/agent:latestbuildkite/agent:oldstablebuildkite/agent:3.129.0buildkite/agent:3.129buildkite/agent:3buildkite/agent:stablebuildkite/agent:alpine
digestsha256:6b902f84eec437fa821e3b22e6c815d020dd86ace222e418792d53ead8297d54

Executive Summary

Last scanned:

Threat Score
0/100NEEDS ATTENTION
Reputation
RELIABLE

AI verdict failed due to an error.

Vulnerabilities

Vulnerability Log

56 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-8286MEDIUM4.13
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8925MEDIUM4.13
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11352LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8286NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-8925NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39822NONE0
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-33630NONE0
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Not Applicable
CVE-2026-11352NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-11586NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-12064NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-8927NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-8932NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-9079NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-9545NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-9546NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-50274NONE0
github.com/DataDog/dd-trace-go/v2
v2.7.1
fixed in 2.8.1
0.4%
Theoretical Threat
Not Applicable
CVE-2026-9547NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-9080NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56132NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56403NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56404NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56405NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56406NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56407NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56410NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56411NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-11564NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-11856NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8924NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-50219NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56412NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-42505NONE0
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-8926NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-10536NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-8458NONE0
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-8458NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56131NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56408NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.81.1
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.