Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Scanning reports 38 exposed-surface findings, though none are high severity — the maximum is 6.38 and only three cross the 6.0 threshold, all denial-of-service issues in OpenSSL QUIC (CVE-2026-14456) and gRPC-Go (CVE-2026-84445). In this container cloudflared runs as a client process, so the OpenSSL QUIC server code path behind CVE-2026-14456 is not exercised, and CVE-2026-84445 only affects servers created with xds.NewGRPCServer(); keeping QUIC server mode and xds-based gRPC serving disabled fully avoids both. The 16 post-exploit-only findings are low severity (max 3.53) and do not change the verdict, and the image itself is well-trusted (226M+ pulls, digest-pinned) from cloudflare.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-14456 | MEDIUM6.38 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | MEDIUM6.38 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-84445 | MEDIUM6.38 | google.golang.org/grpc v1.83.0 fixed in 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-86805 | MEDIUM5.95 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-95818 | MEDIUM5.95 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-63073 | MEDIUM5.9 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-19499 | MEDIUM5.78 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56854 | MEDIUM5.78 | golang.org/x/crypto v0.53.0 fixed in 0.55.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM5.58 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33818 | MEDIUM5.1 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-56860 | MEDIUM5.1 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6791 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-77117 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-80489 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6368 | MEDIUM4.67 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-8674 | MEDIUM4.5 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56855 | MEDIUM4.5 | golang.org/x/crypto v0.53.0 fixed in 0.56.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-78662 | MEDIUM4.5 | golang.org/x/crypto v0.53.0 fixed in 0.56.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.41-12+deb13u3 fixed in 2.41-12+deb13u4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.41-12+deb13u3 fixed in 2.41-12+deb13u4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc6 2.41-12+deb13u3 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-19542 | LOW3.57 | libc6 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-89092 | LOW3.57 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2019-1010022 | LOW3.53 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010023 | LOW3.17 | libc6 2.41-12+deb13u3 No fix yet | 3.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-75803 | LOW3.15 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2018-20796 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9192 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2026-18798 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63072 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63076 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-14457 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-54874 | LOW2.7 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-56858 | LOW2.48 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | LOW2.39 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-63074 | LOW2.29 | libssl3t64 3.5.6-1~deb13u2 fixed in 3.5.7-1~deb13u2 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-46600 | LOW2.29 | stdlib v1.26.4 fixed in 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-56853 | LOW2.29 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-56859 | LOW2.29 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-56862 | LOW2.29 | stdlib v1.26.4 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-85091 | NONE0 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.6% Theoretical Threat | Not Applicable |
| GHSA-w67g-5rqw-f597 | NONE0 | github.com/gorilla/websocket v1.5.0 fixed in 1.5.3 | — | Not Applicable |
| CVE-2026-81870 | NONE0 | go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 fixed in 1.45.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-81870 | NONE0 | go.opentelemetry.io/otel/sdk v1.44.0 fixed in 1.45.0 | 0.2% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.53.0 No fix yet | — | Not Applicable |
| CVE-2026-84304 | NONE0 | google.golang.org/grpc v1.83.0 fixed in 1.83.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-84303 | NONE0 | google.golang.org/grpc v1.83.0 fixed in 1.83.1 | 0.3% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.