Vulnerability Reportconcourse/concourse:8.2.0

concourse/concourse:8.2.0
DIGESTsha256:c26e993959ac79f202c481c4f9d048bdf7a65d6afb13eb5df5e414edbf97a3e5

Executive Summary

Threat Score
75/100DANGEROUS
Reputation
RELIABLE

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could impersonate a legitimate user by matching full names, gaining unauthorized access to Concourse teams and potentially to CI/CD pipeline controls. Disabling the GitLab auth connector or enforcing GitLab group-based authentication would fully eliminate CVE-2020-5415. Note: CVE-2020-5415 only applies if the GitLab auth connector is enabled, which is a non-default configuration. Despite the image's popularity and high reputation, the vulnerability is severe and easily exploitable over the network without authentication.

Vulnerabilities

Vulnerability Log

62 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2020-5415HIGH8
github.com/concourse/dex
v1.13.0
fixed in 6.4.1, 6.3.1, 0.0.0-20200730150203-821b48abfd88
1.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-34181MEDIUM5.35
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39820MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39820MEDIUM5.1
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-9076MEDIUM5.02
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2023-39810LOW3.98
busybox
1.37.0-r57
fixed in 1.37.0-r58
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-26157LOW3.57
busybox
1.37.0-r57
fixed in 1.37.0-r58
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-26158LOW3.57
busybox
1.37.0-r57
fixed in 1.37.0-r58
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW3.15
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45447LOW2.92
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.6.2-r3
fixed in 3.6.3-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-45445LOW2.78
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42764LOW1.81
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW1.81
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW1.81
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42764LOW1.81
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW1.81
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW1.81
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-35188NONE0
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42765NONE0
libcrypto3
3.6.2-r3
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-35188NONE0
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42765NONE0
libssl3
3.6.2-r3
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46680NONE0
github.com/containerd/containerd/v2
v2.3.0
fixed in 2.0.9, 2.2.4, 2.3.1
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46680NONE0
github.com/containerd/containerd/v2
v2.2.3
fixed in 2.0.9, 2.2.4, 2.3.1
Not Applicable