Vulnerability Reportcloudflare/cloudflared:2026.6.1

cloudflare/cloudflared:2026.6.1
digestsha256:6d91c121b803126f7a5344005d17a9324788fc09d305b6e2560ec6040a7ae283

Executive Summary

Last scanned:

Threat Score
30/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Scanning shows 41 exposed findings with 4 at severity 6.0 or above (maximum 6.38), plus 17 post-exploit findings that all sit at severity 3.53 or below. The notable items are denial-of-service issues in bundled libraries, such as CVE-2026-84445 (a malformed gRPC request can panic an xDS-based gRPC server process) and CVE-2026-56862 (indefinite TLS KeyUpdate messages forcing repeated key derivation). In practical terms the worst outcome is service disruption or memory exhaustion rather than code execution or data exposure. Note that CVE-2026-84445 only applies to servers created through the xDS gRPC server constructor, so a standard tunnel deployment should not be affected. Upgrading the bundled OpenSSL and Go components when a patched image is published would remove these paths entirely.

Vulnerabilities

Vulnerability Log

58 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-63074MEDIUM6.38
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-63075MEDIUM6.38
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-84445MEDIUM6.38
google.golang.org/grpc
v1.81.1
fixed in 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56862MEDIUM6.38
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-86805MEDIUM5.95
libc6
2.41-12+deb13u3
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-95818MEDIUM5.95
libc6
2.41-12+deb13u3
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-63073MEDIUM5.9
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-19499MEDIUM5.78
libc6
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56854MEDIUM5.78
golang.org/x/crypto
v0.52.0
fixed in 0.55.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-6238MEDIUM5.52
libc6
2.41-12+deb13u3
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM5.3
libc6
2.41-12+deb13u3
No fix yet
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2019-1010025MEDIUM5.3
libc6
2.41-12+deb13u3
No fix yet
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-56852MEDIUM5.1
golang.org/x/text
v0.37.0
fixed in 0.39.0
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-56860MEDIUM5.1
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5435MEDIUM5.02
libc6
2.41-12+deb13u3
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6791MEDIUM5.02
libc6
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-77117MEDIUM5.02
libc6
2.41-12+deb13u3
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-80489MEDIUM5.02
libc6
2.41-12+deb13u3
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6368MEDIUM4.67
libc6
2.41-12+deb13u3
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg+really1.3.1-1+b1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-8674MEDIUM4.5
libc6
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56855MEDIUM4.5
golang.org/x/crypto
v0.52.0
fixed in 0.56.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-78662MEDIUM4.5
golang.org/x/crypto
v0.52.0
fixed in 0.56.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.41-12+deb13u3
fixed in 2.41-12+deb13u4
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.41-12+deb13u3
fixed in 2.41-12+deb13u4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-18374MEDIUM4.17
libc6
2.41-12+deb13u3
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69725MEDIUM4
github.com/go-chi/chi/v5
v5.2.2
fixed in 5.2.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2010-4756MEDIUM4
libc6
2.41-12+deb13u3
No fix yet
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-19542LOW3.57
libc6
2.41-12+deb13u3
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-89092LOW3.57
libc6
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2019-1010022LOW3.53
libc6
2.41-12+deb13u3
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010023LOW3.17
libc6
2.41-12+deb13u3
No fix yet
3.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-75803LOW3.15
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
0.2%
Theoretical Threat
Directly Exposed
CVE-2018-20796LOW2.7
libc6
2.41-12+deb13u3
No fix yet
5.8%
Low-Moderate Risk
Post-Exploit
CVE-2019-9192LOW2.7
libc6
2.41-12+deb13u3
No fix yet
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63072LOW2.7
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-14457LOW2.7
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-54874LOW2.7
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-56858LOW2.48
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
libssl3t64
3.5.6-1~deb13u2
fixed in 3.5.7-1~deb13u2
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-46600LOW2.29
golang.org/x/net
v0.55.0
fixed in 0.56.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33818LOW2.29
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-46600LOW2.29
stdlib
v1.26.4
fixed in 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-56853LOW2.29
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-56859LOW2.29
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-85091NONE0
zlib1g
1:1.3.dfsg+really1.3.1-1+b1
No fix yet
0.6%
Theoretical Threat
Not Applicable
GHSA-w67g-5rqw-f597NONE0
github.com/gorilla/websocket
v1.5.0
fixed in 1.5.3
—
Not Applicable
CVE-2026-81870NONE0
go.opentelemetry.io/otel/exporters/otlp/otlptrace
v1.43.0
fixed in 1.45.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-81870NONE0
go.opentelemetry.io/otel/sdk
v1.43.0
fixed in 1.45.0
0.2%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.52.0
No fix yet
—
Not Applicable
CVE-2026-84304NONE0
google.golang.org/grpc
v1.81.1
fixed in 1.83.1
0.6%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.81.1
fixed in 1.82.1
—
Not Applicable
CVE-2026-84303NONE0
google.golang.org/grpc
v1.81.1
fixed in 1.83.1
0.3%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.