Last scanned:
This base/runtime image is a reasonable foundation, but it ships vulnerabilities worth remediating in the images built on top of it. Two OpenSSL denial-of-service vulnerabilities (CVE-2026-28388, CVE-2026-28389) are present, each with CVSS 6.0, but both require uncommon non-default configurations (delta CRL processing or CMS decryption) to be exploitable. An attacker would need to provide a malformed CRL or CMS message to cause a crash, which is unlikely in typical Calico networking nodes. The image has a strong reputation and no high-severity issues, so it poses minimal risk for most deployments. Remediation through updating the openssl-libs package is recommended for defense-in-depth. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-28388 | MEDIUM6 | openssl-libs 1:3.5.5-4.el9_8 No fix yet | 1.1% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-28389 | MEDIUM6 | openssl-libs 1:3.5.5-4.el9_8 No fix yet | 1.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-4105 | MEDIUM5.7 | systemd-libs 252-67.el9_8.2 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM5.5 | openssl-libs 1:3.5.5-4.el9_8 No fix yet | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54370 | MEDIUM5.35 | libacl 2.3.1-4.el9 fixed in 2.4.0-1.el9_8 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54371 | MEDIUM5.35 | libattr 2.5.1-3.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | p11-kit-trust 0.26.2-1.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-41996 | MEDIUM4.72 | openssl-libs 1:3.5.5-4.el9_8 No fix yet | 1.1% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-1371 | MEDIUM4.67 | elfutils-libelf 0.194-1.el9 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-1377 | MEDIUM4.67 | elfutils-libelf 0.194-1.el9 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2021-46195 | MEDIUM4.67 | libgcc 11.5.0-14.el9 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libgcc 11.5.0-14.el9 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.2.11-40.el9 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM4.42 | openssl-libs 1:3.5.5-4.el9_8 No fix yet | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42250 | MEDIUM4.25 | bzip2-libs 1.0.8-11.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | glibc 2.34-270.el9_8 fixed in 2.34-272.el9_8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | glibc 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | glibc-common 2.34-270.el9_8 fixed in 2.34-272.el9_8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | glibc-common 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | glibc-minimal-langpack 2.34-270.el9_8 fixed in 2.34-272.el9_8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | glibc-minimal-langpack 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-1376 | MEDIUM4 | elfutils-libelf 0.194-1.el9 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | openssl-libs 1:3.5.5-4.el9_8 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | LOW3.6 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2024-25260 | LOW3.4 | elfutils-libelf 0.194-1.el9 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5958 | LOW3.21 | sed 4.8-10.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-56391 | LOW3.11 | coreutils-single 8.32-40.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW3.1 | openssl-libs 1:3.5.5-4.el9_8 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31789 | LOW3 | openssl-libs 1:3.5.5-4.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2022-41409 | LOW2.7 | pcre2 10.40-6.el9 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2022-41409 | LOW2.7 | pcre2-syntax 10.40-6.el9 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-13595 | LOW2.7 | util-linux 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-13595 | LOW2.7 | util-linux-core 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.12-1.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux-core 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | LOW2.39 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-5278 | LOW2.24 | coreutils-single 8.32-40.el9 fixed in 8.32-41.el9_8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-56392 | LOW2.24 | coreutils-single 8.32-40.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-54369 | LOW2.17 | libacl 2.3.1-4.el9 fixed in 2.4.0-1.el9_8 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | glibc 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | glibc-common 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | glibc-minimal-langpack 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | glibc 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | glibc-common 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | glibc-minimal-langpack 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-34743 | LOW1.62 | xz-libs 5.2.5-8.el9_0 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-11961 | LOW1.61 | libpcap 14:1.10.0-4.el9 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-50495 | NONE0 | ncurses-base 6.2-12.20210508.el9 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-libs 6.2-12.20210508.el9 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| GHSA-gcjh-h69q-9w9g | NONE0 | github.com/google/cel-go v0.26.0 fixed in 0.29.0 | — | Not Applicable |
| CVE-2026-54332 | NONE0 | github.com/gopacket/gopacket v1.4.0 fixed in 1.6.1 | — | Not Applicable |
| CVE-2026-54345 | NONE0 | github.com/gopacket/gopacket v1.4.0 fixed in 1.6.1 | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.53.0 No fix yet | — | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.38.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.81.1 fixed in 1.82.1 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.