Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Scanning shows 41 exposed findings with 4 at severity 6.0 or above (maximum 6.38), plus 17 post-exploit findings that all sit at severity 3.53 or below. The notable items are denial-of-service issues in bundled libraries, such as CVE-2026-84445 (a malformed gRPC request can panic an xDS-based gRPC server process) and CVE-2026-56862 (indefinite TLS KeyUpdate messages forcing repeated key derivation). In practical terms the worst outcome is service disruption or memory exhaustion rather than code execution or data exposure. Note that CVE-2026-84445 only applies to servers created through the xDS gRPC server constructor, so a standard tunnel deployment should not be affected. Upgrading the bundled OpenSSL and Go components when a patched image is published would remove these paths entirely.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-63074 | MEDIUM6.38 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | MEDIUM6.38 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-84445 | MEDIUM6.38 | google.golang.org/grpc v1.81.1 fixed in 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56862 | MEDIUM6.38 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-86805 | MEDIUM5.95 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-95818 | MEDIUM5.95 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-63073 | MEDIUM5.9 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-19499 | MEDIUM5.78 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56854 | MEDIUM5.78 | golang.org/x/crypto v0.52.0 fixed in 0.55.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM5.58 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-56852 | MEDIUM5.1 | golang.org/x/text v0.37.0 fixed in 0.39.0 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-56860 | MEDIUM5.1 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6791 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-77117 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-80489 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6368 | MEDIUM4.67 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-8674 | MEDIUM4.5 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56855 | MEDIUM4.5 | golang.org/x/crypto v0.52.0 fixed in 0.56.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-78662 | MEDIUM4.5 | golang.org/x/crypto v0.52.0 fixed in 0.56.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.41-12+deb13u3 fixed in 2.41-12+deb13u4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.41-12+deb13u3 fixed in 2.41-12+deb13u4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69725 | MEDIUM4 | github.com/go-chi/chi/v5 v5.2.2 fixed in 5.2.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc6 2.41-12+deb13u3 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-19542 | LOW3.57 | libc6 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-89092 | LOW3.57 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2019-1010022 | LOW3.53 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010023 | LOW3.17 | libc6 2.41-12+deb13u3 No fix yet | 3.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-75803 | LOW3.15 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2018-20796 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9192 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2026-18798 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63072 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63076 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-14457 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-54874 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-56858 | LOW2.48 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | LOW2.39 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-14456 | LOW2.29 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-46600 | LOW2.29 | golang.org/x/net v0.55.0 fixed in 0.56.0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-33818 | LOW2.29 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-46600 | LOW2.29 | stdlib v1.26.4 fixed in 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-56853 | LOW2.29 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-56859 | LOW2.29 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-85091 | NONE0 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.6% Theoretical Threat | Not Applicable |
| GHSA-w67g-5rqw-f597 | NONE0 | github.com/gorilla/websocket v1.5.0 fixed in 1.5.3 | — | Not Applicable |
| CVE-2026-81870 | NONE0 | go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 fixed in 1.45.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-81870 | NONE0 | go.opentelemetry.io/otel/sdk v1.43.0 fixed in 1.45.0 | 0.2% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.52.0 No fix yet | — | Not Applicable |
| CVE-2026-84304 | NONE0 | google.golang.org/grpc v1.81.1 fixed in 1.83.1 | 0.6% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.81.1 fixed in 1.82.1 | — | Not Applicable |
| CVE-2026-84303 | NONE0 | google.golang.org/grpc v1.81.1 fixed in 1.83.1 | 0.3% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.