Last scanned:
This image is safe for production use. While the vulnerability scan reports 16 exposed and 19 post-exploit findings, their maximum severities are low (5.58 and 2.7 respectively), and no specific CVE identifiers were provided. The image is an official Docker Hub image pinned by digest, further reducing supply chain risk. No actionable high-severity issues are present, so it can be deployed without additional security concerns.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-39821 | MEDIUM5.58 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-39822 | MEDIUM5.3 | stdlib v1.26.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-46600 | MEDIUM5.1 | golang.org/x/net v0.55.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-56852 | MEDIUM5.1 | golang.org/x/text v0.37.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-27145 | MEDIUM5.1 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-46600 | MEDIUM5.1 | stdlib v1.26.3 fixed in 1.26.6, 1.27.0-rc.3 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42507 | LOW3.6 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33630 | LOW2.7 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | — | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-7009 | LOW2.7 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-7009 | LOW2.7 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-5773 | LOW2.29 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW2.29 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5773 | LOW2.29 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW2.29 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-42504 | LOW2.29 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW1.99 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW1.99 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW1.99 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW1.99 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42505 | LOW1.62 | stdlib v1.26.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Post-Exploit |
| GHSA-gcjh-h69q-9w9g | NONE0 | github.com/google/cel-go v0.28.1 fixed in 0.29.0 | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.52.0 No fix yet | — | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.81.0 fixed in 1.82.1 | — | Not Applicable |
| CVE-2026-33818 | NONE0 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | — | Not Applicable |
| CVE-2026-56853 | NONE0 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | — | Not Applicable |
| CVE-2026-56858 | NONE0 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | — | Not Applicable |
| CVE-2026-56859 | NONE0 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | — | Not Applicable |
| CVE-2026-56860 | NONE0 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | — | Not Applicable |
| CVE-2026-56862 | NONE0 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.