Vulnerability Reportchromadb/chroma:1.5.10.dev128

chromadb/chroma:1.5.10.dev128
DIGESTsha256:55bb1c252252366d1c6d4c3cf9567a0ccbef09bd867e845fec66eac84df424d5

Executive Summary

Threat Score
30/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most notable risks are two glibc regex recursion flaws (CVE-2018-20796, CVE-2019-9192) that could lead to denial of service if the container processes untrusted regex patterns. These are low-severity (6.0) and their exploitability depends on whether Chroma exposes regex input to users. Updating glibc would fully eliminate these issues.

Vulnerabilities

Vulnerability Log

147 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2018-20796MEDIUM6
libc-bin
2.41-12+deb13u3
No fix yet
5.8%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2019-9192MEDIUM6
libc-bin
2.41-12+deb13u3
No fix yet
2.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2018-20796MEDIUM6
libc6
2.41-12+deb13u3
No fix yet
5.8%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2019-9192MEDIUM6
libc6
2.41-12+deb13u3
No fix yet
2.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-14104MEDIUM5.18
libblkid1
2.41-5
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
liblastlog2-2
2.41-5
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libmount1
2.41-5
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libsmartcols1
2.41-5
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libuuid1
2.41-5
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libblkid1
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
liblastlog2-2
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libmount1
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libsmartcols1
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libuuid1
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg+really1.3.1-1+b1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libblkid1
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
liblastlog2-2
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.8.1-1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libmount1
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libsmartcols1
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libsystemd0
257.13-1~deb13u1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libudev1
257.13-1~deb13u1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libuuid1
2.41-5
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2021-45346MEDIUM4.3
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-42250MEDIUM4.25
libbz2-1.0
1.0.8-6
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc-bin
2.41-12+deb13u3
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc-bin
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.41-12+deb13u3
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.41-5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
liblastlog2-2
2.41-5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.41-5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.41-5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.41-5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2010-4756MEDIUM4
libc-bin
2.41-12+deb13u3
No fix yet
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2010-4756MEDIUM4
libc6
2.41-12+deb13u3
No fix yet
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-48962LOW3.98
perl-base
5.40.1-6
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW3.7
libapt-pkg7.0
3.0.3
No fix yet
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2005-2541LOW3.6
tar
1.35+dfsg-3.1
No fix yet
4.0%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010022LOW3.53
libc-bin
2.41-12+deb13u3
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010022LOW3.53
libc6
2.41-12+deb13u3
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010023LOW3.17
libc-bin
2.41-12+deb13u3
No fix yet
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010023LOW3.17
libc6
2.41-12+deb13u3
No fix yet
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-14104LOW3.11
bsdutils
1:2.41-5
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
login
1:4.16.0-2+really2.41-5
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
mount
2.41-5
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
util-linux
2.41-5
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-8376LOW3
perl-base
5.40.1-6
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
bsdutils
1:2.41-5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
login
1:4.16.0-2+really2.41-5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
mount
2.41-5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.8
tar
1.35+dfsg-3.1
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
util-linux
2.41-5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-70873LOW2.8
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libsystemd0
257.13-1~deb13u1
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libsystemd0
257.13-1~deb13u1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libudev1
257.13-1~deb13u1
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
257.13-1~deb13u1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42496LOW2.78
perl-base
5.40.1-6
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
bsdutils
1:2.41-5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
login
1:4.16.0-2+really2.41-5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
mount
2.41-5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-12087LOW2.7
perl-base
5.40.1-6
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux
2.41-5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-48959LOW2.55
perl-base
5.40.1-6
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-48961LOW2.55
perl-base
5.40.1-6
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2007-5686LOW2.5
passwd
1:4.17.4-2
No fix yet
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.41-5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2017-18018LOW2.4
coreutils
9.7-3
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
login
1:4.16.0-2+really2.41-5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.41-5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.41-5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42497LOW2.29
perl-base
5.40.1-6
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9538LOW2.29
perl-base
5.40.1-6
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils
9.7-3
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW2.22
apt
3.0.3
No fix yet
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-6238LOW1.99
libc-bin
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-15649LOW1.99
perl-base
5.40.1-6
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010024LOW1.91
libc-bin
2.41-12+deb13u3
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010025LOW1.91
libc-bin
2.41-12+deb13u3
No fix yet
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010024LOW1.91
libc6
2.41-12+deb13u3
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010025LOW1.91
libc6
2.41-12+deb13u3
No fix yet
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW1.84
passwd
1:4.17.4-2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc-bin
2.41-12+deb13u3
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.41-12+deb13u3
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2011-4116LOW1.68
perl-base
5.40.1-6
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-31437LOW1.62
libsystemd0
257.13-1~deb13u1
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-31438LOW1.62
libsystemd0
257.13-1~deb13u1
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-31437LOW1.62
libudev1
257.13-1~deb13u1
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-31438LOW1.62
libudev1
257.13-1~deb13u1
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-69720NONE0
libtinfo6
6.5+20250216-2
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69720NONE0
ncurses-base
6.5+20250216-2
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69720NONE0
ncurses-bin
6.5+20250216-2
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2007-5686NONE0
login.defs
1:4.17.4-2
No fix yet
0.9%
Theoretical Threat
Not Applicable
CVE-2026-54411NONE0
libpam-modules
1.7.0-5
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54411NONE0
libpam-modules-bin
1.7.0-5
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54411NONE0
libpam-runtime
1.7.0-5
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54411NONE0
libpam0g
1.7.0-5
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2024-56433NONE0
login.defs
1:4.17.4-2
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
libtinfo6
6.5+20250216-2
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
ncurses-base
6.5+20250216-2
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
ncurses-bin
6.5+20250216-2
No fix yet
0.2%
Theoretical Threat
Not Applicable
TEMP-0841856-B18BAFNONE0
bash
5.2.37-2+b9
No fix yet
Not Applicable
CVE-2026-53612NONE0
bsdutils
1:2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
bsdutils
1:2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
bsdutils
1:2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
bsdutils
1:2.41-5
No fix yet
Not Applicable
CVE-2026-53612NONE0
libblkid1
2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
libblkid1
2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
libblkid1
2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
libblkid1
2.41-5
No fix yet
Not Applicable
CVE-2026-53612NONE0
liblastlog2-2
2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
liblastlog2-2
2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
liblastlog2-2
2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
liblastlog2-2
2.41-5
No fix yet
Not Applicable
CVE-2026-53612NONE0
libmount1
2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
libmount1
2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
libmount1
2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
libmount1
2.41-5
No fix yet
Not Applicable
CVE-2026-53612NONE0
libsmartcols1
2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
libsmartcols1
2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
libsmartcols1
2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
libsmartcols1
2.41-5
No fix yet
Not Applicable
CVE-2026-11822NONE0
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-11824NONE0
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-53612NONE0
libuuid1
2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
libuuid1
2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
libuuid1
2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
libuuid1
2.41-5
No fix yet
Not Applicable
CVE-2026-53612NONE0
login
1:4.16.0-2+really2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
login
1:4.16.0-2+really2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
login
1:4.16.0-2+really2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
login
1:4.16.0-2+really2.41-5
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
login.defs
1:4.17.4-2
No fix yet
Not Applicable
CVE-2026-53612NONE0
mount
2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
mount
2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
mount
2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
mount
2.41-5
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
passwd
1:4.17.4-2
No fix yet
Not Applicable
CVE-2026-7010NONE0
perl-base
5.40.1-6
No fix yet
0.2%
Theoretical Threat
Not Applicable
TEMP-0517018-A83CE6NONE0
sysvinit-utils
3.14-4
No fix yet
Not Applicable
TEMP-0290435-0B57B5NONE0
tar
1.35+dfsg-3.1
No fix yet
Not Applicable
CVE-2026-53612NONE0
util-linux
2.41-5
No fix yet
Not Applicable
CVE-2026-53613NONE0
util-linux
2.41-5
No fix yet
Not Applicable
CVE-2026-53614NONE0
util-linux
2.41-5
No fix yet
Not Applicable
CVE-2026-53615NONE0
util-linux
2.41-5
No fix yet
Not Applicable