Vulnerability Reportcloudflare/cloudflared:2026.8.2

cloudflare/cloudflared:latestcloudflare/cloudflared:1910-733bfb939963cloudflare/cloudflared:1910-733bfb9cloudflare/cloudflared:2026.8.2
digestsha256:0aa26e284f05e6c77ae375b8c9c11d9eb6a448fb7bcd8d40f31cb6176189eb38

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. The image has 6 exposed and 20 post-exploit findings, but all are low severity (maximum 5.5) and no practical exploit was identified in the provided findings. The image is pinned by digest and comes from a trusted publisher, Cloudflare. Given the low risk and reliable source, it is suitable for production deployment.

Vulnerabilities

Vulnerability Log

26 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-6368MEDIUM5.5
libc6
2.41-12+deb13u3
No fix yet
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg+really1.3.1-1+b1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.41-12+deb13u3
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.41-12+deb13u3
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2019-1010022LOW3.53
libc6
2.41-12+deb13u3
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010023LOW3.17
libc6
2.41-12+deb13u3
No fix yet
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-56858LOW2.92
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
Post-Exploit
CVE-2018-20796LOW2.7
libc6
2.41-12+deb13u3
No fix yet
5.8%
Low-Moderate Risk
Post-Exploit
CVE-2019-9192LOW2.7
libc6
2.41-12+deb13u3
No fix yet
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-33818LOW2.7
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
Post-Exploit
CVE-2026-56853LOW2.7
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
Post-Exploit
CVE-2026-56859LOW2.7
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
Post-Exploit
CVE-2026-56860LOW2.7
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
Post-Exploit
CVE-2026-56862LOW2.7
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
Post-Exploit
CVE-2026-39821LOW2.51
stdlib
v1.26.4
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-46600LOW2.29
stdlib
v1.26.4
fixed in 1.26.6, 1.27.0-rc.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6791LOW2.12
libc6
2.41-12+deb13u3
No fix yet
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.41-12+deb13u3
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2019-1010024LOW1.91
libc6
2.41-12+deb13u3
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010025LOW1.91
libc6
2.41-12+deb13u3
No fix yet
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.41-12+deb13u3
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42505LOW1.62
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2010-4756LOW1.44
libc6
2.41-12+deb13u3
No fix yet
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-14456NONE0
libssl3t64
3.5.6-1~deb13u2
No fix yet
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.