Last scanned:
This image is safe for production use. Vulnerability data does show findings - 11 exposed entries and 16 post-exploit-only entries - but the maximum severity in either set is low (4.67 exposed, 3.53 post-exploit) and none reach the 6.0 threshold that would warrant escalation, so no CVE IDs are flagged as impactful. Publisher reputation supports this: cloudflare is a high-reputation community publisher with over 215 million pulls and the image is pinned by immutable digest. The container runs a simple version command rather than a long-lived network service, which further limits practical exposure.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-6368 | MEDIUM4.67 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.41-12+deb13u3 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-19542 | MEDIUM4.2 | libc6 2.41-12+deb13u3 No fix yet | — | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2019-1010022 | LOW3.53 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010023 | LOW3.17 | libc6 2.41-12+deb13u3 No fix yet | 3.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-56854 | LOW2.78 | golang.org/x/crypto v0.53.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2018-20796 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9192 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2026-19499 | LOW2.45 | libc6 2.41-12+deb13u3 No fix yet | — | Post-Exploit |
| CVE-2026-77117 | LOW2.12 | libc6 2.41-12+deb13u3 No fix yet | — | Post-Exploit |
| CVE-2026-80489 | LOW2.12 | libc6 2.41-12+deb13u3 No fix yet | — | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2019-1010024 | LOW1.91 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010025 | LOW1.91 | libc6 2.41-12+deb13u3 No fix yet | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-56855 | LOW1.91 | golang.org/x/crypto v0.53.0 fixed in 0.56.0 | — | Post-Exploit |
| CVE-2026-78662 | LOW1.91 | golang.org/x/crypto v0.53.0 fixed in 0.56.0 | — | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc6 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-6791 | LOW1.81 | libc6 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2010-4756 | LOW1.44 | libc6 2.41-12+deb13u3 No fix yet | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-85091 | NONE0 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.53.0 No fix yet | — | Not Applicable |
| CVE-2026-84304 | NONE0 | google.golang.org/grpc v1.83.0 fixed in 1.83.1 | — | Not Applicable |
| CVE-2026-84445 | NONE0 | google.golang.org/grpc v1.83.0 fixed in 1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e | — | Not Applicable |
| CVE-2026-84303 | NONE0 | google.golang.org/grpc v1.83.0 fixed in 1.83.1 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.