Vulnerability Reportcalico/node:v3.31.5-58-g302912362136

calico/node:v3.31.5-58-g302912362136
digestsha256:f104957040dd0e2351ee0c86905ebe3c5d96d165cdf3d0f85c721d5c62ad8f4a

Executive Summary

Last scanned:

Threat Score
30/100NEEDS ATTENTION
Reputation
RELIABLE

This base/runtime image is a reasonable foundation, but it ships vulnerabilities worth remediating in the images built on top of it. The most notable are CVE-2023-2650 (potential DoS when connecting to a malicious server) and CVE-2026-31789 (heap buffer overflow on 32-bit systems only). Both are medium severity and are partially mitigated by typical deployment contexts—e.g., the container likely runs on 64-bit Linux and only connects to trusted endpoints. Additionally, CVE-2023-0464 and CVE-2026-28388 require enabling non-default certificate policy or delta CRL processing, so they pose no risk under standard configurations. Upgrading the openssl-libs package to a patched version is recommended to eliminate these inherited flaws. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

103 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2023-2650MEDIUM6.76
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
75.1%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2026-31789MEDIUM6.66
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2023-0464MEDIUM6
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
3.7%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-28388MEDIUM6
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-4105MEDIUM5.7
systemd-libs
239-82.el8_10.17
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-common
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-minimal-langpack
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41184MEDIUM5.52
github.com/projectcalico/calico
v3.31.5-58-g302912362136
fixed in 3.31.6, 1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-41185MEDIUM5.52
github.com/projectcalico/calico
v3.31.5-58-g302912362136
fixed in 3.31.6, 1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2019-14250MEDIUM5.5
libgcc
8.5.0-28.el8_10
No fix yet
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-0727MEDIUM5.5
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-3997MEDIUM5.5
systemd-libs
239-82.el8_10.17
No fix yet
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.2.53-3.el8
fixed in 2.4.0-1.el8_10
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54371MEDIUM5.35
libattr
2.4.48-3.el8
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2023-0466MEDIUM5.3
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-0465MEDIUM5.3
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-13757MEDIUM5.27
p11-kit-trust
0.23.22-2.el8
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-2511MEDIUM4.81
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
54.0%
Actively Exploited
Directly Exposed
CVE-2022-3606MEDIUM4.67
libbpf
0.5.0-1.el8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc
8.5.0-28.el8_10
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-15469MEDIUM4.67
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.11-25.el8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
xz-libs
5.2.4-4.el8_6
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2018-20839MEDIUM4.3
systemd-libs
239-82.el8_10.17
No fix yet
2.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-42250MEDIUM4.25
bzip2-libs
1.0.6-28.el8_10
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2021-24032MEDIUM4
libzstd
1.4.4-1.el8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-4598MEDIUM4
systemd-libs
239-82.el8_10.17
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-25260LOW3.4
elfutils-libelf
0.190-2.el8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-common
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-minimal-langpack
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-46836LOW3.37
net-tools
2.0-0.52.20160912git.el8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5958LOW3.21
sed
4.5-5.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-56391LOW3.11
coreutils-single
8.30-17.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2018-20657LOW2.7
libgcc
8.5.0-28.el8_10
No fix yet
4.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-4899LOW2.7
libzstd
1.4.4-1.el8
No fix yet
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl-libs
1:1.1.1k-16.el8_6
fixed in 1:1.1.1k-17.el8_6
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-41409LOW2.7
pcre2
10.32-3.el8_6
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-13595LOW2.7
util-linux
2.32.1-48.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-41991LOW2.4
gzip
1.9-13.el8_5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.32.1-48.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-29111LOW2.39
systemd-libs
239-82.el8_10.17
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2021-45940LOW2.34
libbpf
0.5.0-1.el8
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2021-45941LOW2.34
libbpf
0.5.0-1.el8
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-69421LOW2.29
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.30-17.el8_10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-56392LOW2.24
coreutils-single
8.30-17.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-54369LOW2.17
libacl
2.2.53-3.el8
fixed in 2.4.0-1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2024-41996LOW2.12
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-42771LOW1.99
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
shadow-utils
2:4.6-23.el8_10
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-11961LOW1.61
libpcap
14:1.9.1-5.el8
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2021-39537NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
3.2%
Low-Moderate Risk
Not Applicable
CVE-2021-39537NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
3.2%
Low-Moderate Risk
Not Applicable
CVE-2020-19185NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2020-19185NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2018-19211NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
0.9%
Theoretical Threat
Not Applicable
CVE-2018-19211NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
0.9%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.79.3
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.