Vulnerability Reportcalico/node:v3.33.0-0.dev-866-gf868484449e7-ppc64le

calico/node:v3.33.0-0.dev-866-gf868484449e7-ppc64le
digestsha256:ab0d5ffa582ee5ad4cc4d78c1d2758c5b095550d77777a76d7d68d7d4e49e2d1

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This base/runtime image is a reasonable foundation, but it ships vulnerabilities worth remediating in the images built on top of it. The only notable finding is CVE-2026-28388 in openssl-libs, a denial-of-service vulnerability that is only exploitable if delta CRL processing is enabled, which is not default. All other 34 exposed vulnerabilities are low severity (below 6.0) and post-exploit findings are minimal (max 3.21), posing no practical risk in typical deployments. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

56 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-28388MEDIUM6
openssl-libs
1:3.5.5-4.el9_8
No fix yet
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-4105MEDIUM5.7
systemd-libs
252-67.el9_8.2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54371MEDIUM5.35
libattr
2.5.1-3.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-13757MEDIUM5.27
p11-kit-trust
0.26.2-1.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-41996MEDIUM4.72
openssl-libs
1:3.5.5-4.el9_8
No fix yet
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-1371MEDIUM4.67
elfutils-libelf
0.194-1.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-1377MEDIUM4.67
elfutils-libelf
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libgcc
11.5.0-14.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc
11.5.0-14.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.11-40.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-28389MEDIUM4.5
openssl-libs
1:3.5.5-4.el9_8
No fix yet
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-2673MEDIUM4.42
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42250MEDIUM4.25
bzip2-libs
1.0.8-11.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.34-270.el9_8
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.34-270.el9_8
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.34-270.el9_8
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM4.13
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-1376MEDIUM4
elfutils-libelf
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34743LOW3.6
xz-libs
5.2.5-8.el9_0
No fix yet
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2024-25260LOW3.4
elfutils-libelf
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5958LOW3.21
sed
4.8-10.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-56391LOW3.11
coreutils-single
8.32-40.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW3.1
openssl-libs
1:3.5.5-4.el9_8
No fix yet
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2022-41409LOW2.7
pcre2
10.40-6.el9
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2022-41409LOW2.7
pcre2-syntax
10.40-6.el9
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-13595LOW2.7
util-linux
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-13595LOW2.7
util-linux-core
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42505LOW2.7
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41991LOW2.4
gzip
1.12-1.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux-core
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.32-40.el9
fixed in 8.32-41.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-56392LOW2.24
coreutils-single
8.32-40.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-54369LOW2.17
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
glibc
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
glibc-common
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
glibc-minimal-langpack
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
glibc
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
glibc-common
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
glibc-minimal-langpack
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-11961LOW1.61
libpcap
14:1.10.0-4.el9
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-50495NONE0
ncurses-base
6.2-12.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.2-12.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
GHSA-gcjh-h69q-9w9gNONE0
github.com/google/cel-go
v0.26.0
fixed in 0.29.0
Not Applicable
CVE-2026-54332NONE0
github.com/gopacket/gopacket
v1.4.0
fixed in 1.6.1
Not Applicable
CVE-2026-54345NONE0
github.com/gopacket/gopacket
v1.4.0
fixed in 1.6.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.81.1
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.