Vulnerability Reportcalico/node:v3.31.5-58-g302912362136-fips

calico/node:v3.31.5-58-g302912362136-fips
digestsha256:d21e8ef8601d37c18d46301421e0143b8701e667628a11a80e31fa923b508b8e

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This base/runtime image is a reasonable foundation, but it ships vulnerabilities worth remediating in the images built on top of it. The most notable findings are moderate-severity DoS issues in OpenSSL (CVE-2023-2650 and CVE-2023-0464), which could lead to service disruption under specific conditions. CVE-2023-0464 and CVE-2026-28388 only apply if policy or delta CRL processing is explicitly enabled—both are disabled by default. Disabling these non-default features fully eliminates those risks. No critical RCE or data exposure vulnerabilities are present, and the image's high community trust reduces supply chain concerns. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

103 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2023-2650MEDIUM6.76
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
75.1%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2023-0464MEDIUM6
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
3.7%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-28388MEDIUM6
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-4105MEDIUM5.7
systemd-libs
239-82.el8_10.17
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-common
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-minimal-langpack
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41184MEDIUM5.52
github.com/projectcalico/calico
v3.31.5-58-g302912362136
fixed in 3.31.6, 1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2019-14250MEDIUM5.5
libgcc
8.5.0-28.el8_10
No fix yet
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-0727MEDIUM5.5
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-3997MEDIUM5.5
systemd-libs
239-82.el8_10.17
No fix yet
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.2.53-3.el8
fixed in 2.4.0-1.el8_10
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54371MEDIUM5.35
libattr
2.4.48-3.el8
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2023-0466MEDIUM5.3
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-0465MEDIUM5.3
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-13757MEDIUM5.27
p11-kit-trust
0.23.22-2.el8
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-2511MEDIUM4.81
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
54.0%
Actively Exploited
Directly Exposed
CVE-2024-41996MEDIUM4.72
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2022-3606MEDIUM4.67
libbpf
0.5.0-1.el8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc
8.5.0-28.el8_10
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-15469MEDIUM4.67
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.11-25.el8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
xz-libs
5.2.4-4.el8_6
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41185MEDIUM4.42
github.com/projectcalico/calico
v3.31.5-58-g302912362136
fixed in 3.31.6, 1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2018-20839MEDIUM4.3
systemd-libs
239-82.el8_10.17
No fix yet
2.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-42250MEDIUM4.25
bzip2-libs
1.0.6-28.el8_10
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2021-24032MEDIUM4
libzstd
1.4.4-1.el8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-4598MEDIUM4
systemd-libs
239-82.el8_10.17
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-25260LOW3.4
elfutils-libelf
0.190-2.el8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-common
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-minimal-langpack
2.28-251.el8_10.37
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-46836LOW3.37
net-tools
2.0-0.52.20160912git.el8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5958LOW3.21
sed
4.5-5.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39822LOW3.18
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-ExploitContext importance: MEDIUM
CVE-2021-45940LOW3.12
libbpf
0.5.0-1.el8
No fix yet
1.1%
Low-Moderate Risk
Post-ExploitContext importance: MEDIUM
CVE-2021-45941LOW3.12
libbpf
0.5.0-1.el8
No fix yet
1.1%
Low-Moderate Risk
Post-ExploitContext importance: MEDIUM
CVE-2026-56391LOW3.11
coreutils-single
8.30-17.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-54369LOW2.9
libacl
2.2.53-3.el8
fixed in 2.4.0-1.el8_10
0.1%
Theoretical Threat
Post-ExploitContext importance: MEDIUM
CVE-2018-20657LOW2.7
libgcc
8.5.0-28.el8_10
No fix yet
4.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-4899LOW2.7
libzstd
1.4.4-1.el8
No fix yet
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl-libs
1:1.1.1k-16.el8_6
fixed in 1:1.1.1k-17.el8_6
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-41409LOW2.7
pcre2
10.32-3.el8_6
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-13595LOW2.7
util-linux
2.32.1-48.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-41991LOW2.4
gzip
1.9-13.el8_5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.32.1-48.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-29111LOW2.39
systemd-libs
239-82.el8_10.17
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.30-17.el8_10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-56392LOW2.24
coreutils-single
8.30-17.el8_10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42771LOW1.99
openssl-libs
1:1.1.1k-16.el8_6
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
shadow-utils
2:4.6-23.el8_10
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-11961LOW1.61
libpcap
14:1.9.1-5.el8
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2021-39537NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
3.2%
Low-Moderate Risk
Not Applicable
CVE-2021-39537NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
3.2%
Low-Moderate Risk
Not Applicable
CVE-2020-19185NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2020-19185NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2018-19211NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
0.9%
Theoretical Threat
Not Applicable
CVE-2018-19211NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
0.9%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.79.3
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.