Last scanned:
This image is safe for production use. It does carry some known vulnerabilities (11 exposed-surface and 14 post-exploit entries), but none of them reach the 6.0 severity threshold, with the highest reported severity sitting at 5.95, so they do not rise to a practically exploitable risk in this container's context. The image is a widely pulled, digest-pinned Cloudflare artifact with a minimal runtime footprint, which supports stable and predictable production deployment. Continue routine image refresh and digest pinning as hygiene, but no remediation is blocking.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-86805 | MEDIUM5.95 | libc6 2.41-12+deb13u4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-95818 | MEDIUM5.95 | libc6 2.41-12+deb13u4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-19499 | MEDIUM5.78 | libc6 2.41-12+deb13u4 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6368 | MEDIUM4.67 | libc6 2.41-12+deb13u4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-8674 | MEDIUM4.5 | libc6 2.41-12+deb13u4 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.41-12+deb13u4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-19542 | LOW3.57 | libc6 2.41-12+deb13u4 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-89092 | LOW3.57 | libc6 2.41-12+deb13u4 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2019-1010022 | LOW3.53 | libc6 2.41-12+deb13u4 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010023 | LOW3.17 | libc6 2.41-12+deb13u4 No fix yet | 3.0% Low-Moderate Risk | Post-Exploit |
| CVE-2018-20796 | LOW2.7 | libc6 2.41-12+deb13u4 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9192 | LOW2.7 | libc6 2.41-12+deb13u4 No fix yet | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc6 2.41-12+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2019-1010024 | LOW1.91 | libc6 2.41-12+deb13u4 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010025 | LOW1.91 | libc6 2.41-12+deb13u4 No fix yet | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc6 2.41-12+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6791 | LOW1.81 | libc6 2.41-12+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-77117 | LOW1.81 | libc6 2.41-12+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-80489 | LOW1.81 | libc6 2.41-12+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-56855 | LOW1.62 | golang.org/x/crypto v0.55.0 fixed in 0.56.0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-78662 | LOW1.62 | golang.org/x/crypto v0.55.0 fixed in 0.56.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2010-4756 | LOW1.44 | libc6 2.41-12+deb13u4 No fix yet | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-85091 | NONE0 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.6% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.55.0 No fix yet | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.