Last scanned:
This image is safe for production use. The image is an official Docker Hub image pinned by digest, ensuring immutability and trusted provenance. Although the vulnerability scan reports 25 exposed and 32 post-exploit findings, all are low severity with a maximum exposed severity of 5.27 and a maximum post-exploit severity of 3.01, so they do not present a practical risk. The absence of any high-severity findings and the low threat score further support this verdict.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.24.0-6build1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libgcc-s1 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libstdc++6 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54411 | MEDIUM4.08 | libpam-modules 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54411 | MEDIUM4.08 | libpam-modules-bin 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54411 | MEDIUM4.08 | libpam-runtime 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54411 | MEDIUM4.08 | libpam0g 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | LOW3.83 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | LOW3.83 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | LOW3.83 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | LOW3.83 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | LOW3.83 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | LOW3.83 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | LOW3.83 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | LOW3.83 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-15146 | LOW3.01 | wget 1.21.2-2ubuntu1.1 fixed in 1.21.2-2ubuntu1.4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-45582 | LOW2.86 | tar 1.34+dfsg-1ubuntu0.1.22.04.3 fixed in 1.34+dfsg-1ubuntu0.1.22.04.4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | busybox 1:1.30.1-7ubuntu3.1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.34+dfsg-1ubuntu0.1.22.04.3 fixed in 1.34+dfsg-1ubuntu0.1.22.04.6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-40228 | LOW2.8 | libsystemd0 249.11-0ubuntu3.21 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 249.11-0ubuntu3.21 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-60876 | LOW2.75 | busybox 1:1.30.1-7ubuntu3.1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2022-41409 | LOW2.7 | libpcre2-8-0 10.39-3ubuntu0.1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2022-4899 | LOW2.7 | libzstd1 1.4.8+dfsg-3build1 No fix yet | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-58470 | LOW2.7 | wget 1.21.2-2ubuntu1.1 fixed in 1.21.2-2ubuntu1.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.10-4ubuntu4.1 fixed in 1.10-4ubuntu4.2 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41992 | LOW2.29 | gzip 1.10-4ubuntu4.1 fixed in 1.10-4ubuntu4.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2021-31879 | LOW2.2 | wget 1.21.2-2ubuntu1.1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-58471 | LOW2.17 | wget 1.21.2-2ubuntu1.1 fixed in 1.21.2-2ubuntu1.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-58472 | LOW2.17 | wget 1.21.2-2ubuntu1.1 fixed in 1.21.2-2ubuntu1.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-2236 | LOW2.12 | libgcrypt20 1.9.4-3ubuntu3.2 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc-bin 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc6 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-58469 | LOW1.99 | wget 1.21.2-2ubuntu1.1 fixed in 1.21.2-2ubuntu1.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc-bin 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc6 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1:1.30.1-7ubuntu3.1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | passwd 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4046 | LOW1.62 | libc-bin 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4046 | LOW1.62 | libc6 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11850 | LOW1.53 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-11850 | LOW1.53 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-11850 | LOW1.53 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-11850 | LOW1.53 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-69720 | NONE0 | libncurses6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libncursesw6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libtinfo6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-base 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-bin 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncurses6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncursesw6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libtinfo6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-6238 | NONE0 | locales 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-base 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-bin 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-5435 | NONE0 | locales 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2022-27943 | NONE0 | gcc-12-base 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-4046 | NONE0 | locales 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-5450 | NONE0 | locales 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-5928 | NONE0 | locales 2.35-0ubuntu3.13 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-56433 | NONE0 | login 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29383 | NONE0 | login 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox 1:1.30.1-7ubuntu3.1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.