Vulnerability Reportbuildkite/agent:3

buildkite/agent:latestbuildkite/agent:oldstablebuildkite/agent:3.129.0buildkite/agent:3.129buildkite/agent:3buildkite/agent:stablebuildkite/agent:alpine
digestsha256:6b902f84eec437fa821e3b22e6c815d020dd86ace222e418792d53ead8297d54

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most significant exposed issue is CVE-2026-33630, which could cause a crash or memory corruption in DNS resolution if a malicious DNS server responds, leading to a denial-of-service condition. While 19 exposed findings and 37 post-exploit findings are present, the maximum exposed severity is 6.0 and post-exploit max severity is 3.82, so the practical risk is limited. The image is pinned by digest and comes from a popular community publisher, reducing supply-chain concerns.

Vulnerabilities

Vulnerability Log

56 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33630MEDIUM6
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Directly ExposedContext importance: MEDIUM
CVE-2026-56132MEDIUM5.87
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56404MEDIUM5.87
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM5.3
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-50219MEDIUM5.02
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-8927LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-56131LOW3.82
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-9547LOW3.77
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42505LOW2.7
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-8286LOW2.48
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.48
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8286LOW2.48
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.48
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11352LOW2.29
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW2.29
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW2.29
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11352LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-50274LOW2.29
github.com/DataDog/dd-trace-go/v2
v2.7.1
fixed in 2.8.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8458NONE0
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-8458NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56408NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.81.1
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.