Vulnerability Reportdebian:12

debian:bookworm-20260518debian:bookwormdebian:12.14debian:12
DIGESTsha256:ed4fcc40bb1162b6d2d32e7bec15044d13963779abbe63f67f1cd62b06220519

Executive Summary

DANGEROUS

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could achieve arbitrary code execution, cause a denial of service, or potentially bypass authentication for services running inside the container. Specifically, CVE-2018-20796 in glibc could lead to a denial of service through crafted regular expressions, a common operation in a `bash` environment. Furthermore, CVE-2023-45853 in zlib poses a threat of arbitrary code execution if the container processes maliciously crafted zip files using vulnerable MiniZip functionality. Several other high-severity vulnerabilities also exist, further increasing the attack surface.

Threat Score
100/100
DANGEROUS
Reputation
TRUSTED
Docker Official
BaseImage/
debian:12
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

131 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2023-45853HIGH7.84
zlib1g
1:1.2.13.dfsg-1
No fix yet
1.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2018-20796HIGH7.5
libc-bin
2.36-9+deb12u14
No fix yet
1.5%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2018-20796HIGH7.5
libc6
2.36-9+deb12u14
No fix yet
1.5%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2019-1010022MEDIUM6.66
libc-bin
2.36-9+deb12u14
No fix yet
0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2019-1010022MEDIUM6.66
libc6
2.36-9+deb12u14
No fix yet
0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42010MEDIUM6.66
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-69720MEDIUM6.63
libtinfo6
6.4-4
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69720MEDIUM6.63
ncurses-base
6.4-4
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42013MEDIUM6.56
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly ExposedContext importance: MEDIUM
CVE-2026-5260MEDIUM6.56
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly ExposedContext importance: MEDIUM
CVE-2019-9192MEDIUM6.38
libc-bin
2.36-9+deb12u14
No fix yet
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2019-9192MEDIUM6.38
libc6
2.36-9+deb12u14
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-41989MEDIUM6.38
libgcrypt20
1.10.1-3
fixed in 1.10.1-3+deb12u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33846MEDIUM6.38
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33845MEDIUM6.18
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42009MEDIUM6
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly ExposedContext importance: MEDIUM
CVE-2026-42012MEDIUM5.68
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly ExposedContext importance: MEDIUM
CVE-2026-6238MEDIUM5.52
libc-bin
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc6
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-50495MEDIUM5.52
libtinfo6
6.4-4
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-50495MEDIUM5.52
ncurses-base
6.4-4
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM5.3
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly Exposed
CVE-2025-14104MEDIUM5.18
libblkid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libmount1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libsmartcols1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libuuid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2018-6829MEDIUM5.1
libgcrypt20
1.10.1-3
No fix yet
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5435MEDIUM5.02
libc-bin
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-2236MEDIUM5.02
libgcrypt20
1.10.1-3
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.02
libtasn1-6
4.19.0-2+deb12u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42250MEDIUM5
libbz2-1.0
1.0.8-5+b1
No fix yet
Directly Exposed
CVE-2005-2541MEDIUM4.8
tar
1.34+dfsg-1.2+deb12u1
No fix yet
3.8%
Low-Moderate Risk
Post-ExploitContext importance: MEDIUM
CVE-2026-8376MEDIUM4.7
perl-base
5.36.0-7+deb12u3
No fix yet
Post-ExploitContext importance: MEDIUM
CVE-2026-48962MEDIUM4.68
perl-base
5.36.0-7+deb12u3
No fix yet
Post-Exploit
CVE-2022-0563MEDIUM4.67
libblkid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc-s1
12.2.0-14+deb12u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libmount1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libsmartcols1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libstdc++6
12.2.0-14+deb12u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libuuid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.2.13.dfsg-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libblkid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM4.5
libc-bin
2.36-9+deb12u14
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc-bin
2.36-9+deb12u14
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM4.5
libc6
2.36-9+deb12u14
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc6
2.36-9+deb12u14
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.4.1-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libmount1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libsmartcols1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libsystemd0
252.39-1~deb12u2
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libsystemd0
252.39-1~deb12u2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libsystemd0
252.39-1~deb12u2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libudev1
252.39-1~deb12u2
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libudev1
252.39-1~deb12u2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libudev1
252.39-1~deb12u2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libuuid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42496MEDIUM4.37
perl-base
5.36.0-7+deb12u3
No fix yet
Post-ExploitContext importance: MEDIUM
CVE-2011-3389MEDIUM4.3
libgnutls30
3.7.9-2+deb12u6
No fix yet
3.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc-bin
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc-bin
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2007-5686MEDIUM4.17
login
1:4.13+dfsg1-1+deb12u2
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-31486MEDIUM4.13
perl-base
5.36.0-7+deb12u3
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-27456MEDIUM4
libblkid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-10041MEDIUM4
libpam-modules
1.5.2-6+deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-10041MEDIUM4
libpam-runtime
1.5.2-6+deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-10041MEDIUM4
libpam0g
1.5.2-6+deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69720LOW3.98
ncurses-bin
6.4-4
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW3.7
libapt-pkg6.0
2.6.1
No fix yet
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-5419LOW3.7
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly Exposed
CVE-2026-42497LOW3.6
perl-base
5.36.0-7+deb12u3
No fix yet
Post-ExploitContext importance: MEDIUM
CVE-2026-9538LOW3.6
perl-base
5.36.0-7+deb12u3
No fix yet
Post-ExploitContext importance: MEDIUM
CVE-2024-56433LOW3.6
login
1:4.13+dfsg1-1+deb12u2
No fix yet
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2010-4756LOW3.4
libc-bin
2.36-9+deb12u14
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2010-4756LOW3.4
libc6
2.36-9+deb12u14
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2016-2781LOW3.31
coreutils
9.1-1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2023-50495LOW3.31
ncurses-bin
6.4-4
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
bsdutils
1:2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
mount
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
util-linux
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
util-linux-extra
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
bsdutils
1:2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
mount
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.8
tar
1.34+dfsg-1.2+deb12u1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
util-linux
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
util-linux-extra
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2013-4392LOW2.8
libsystemd0
252.39-1~deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libsystemd0
252.39-1~deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-6141LOW2.8
libtinfo6
6.4-4
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libudev1
252.39-1~deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
252.39-1~deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-6141LOW2.8
ncurses-base
6.4-4
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184LOW2.7
bsdutils
1:2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
mount
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux-extra
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc-bin
2.36-9+deb12u14
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc6
2.36-9+deb12u14
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2007-5686LOW2.5
passwd
1:4.13+dfsg1-1+deb12u2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2017-18018LOW2.4
coreutils
9.1-1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-30258LOW2.4
gpgv
2.2.40-1.1+deb12u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpgv
2.2.40-1.1+deb12u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2024-10041LOW2.4
libpam-modules-bin
1.5.2-6+deb12u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux-extra
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils
9.1-1
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW2.22
apt
2.6.1
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW2.16
passwd
1:4.13+dfsg1-1+deb12u2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-3219LOW1.68
gpgv
2.2.40-1.1+deb12u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-6141LOW1.68
ncurses-bin
6.4-4
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2011-4116LOW1.68
perl-base
5.36.0-7+deb12u3
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2022-27943NONE0
gcc-12-base
12.2.0-14+deb12u1
No fix yet
<0.1%
Theoretical Threat
Not Applicable
TEMP-0841856-B18BAFNONE0
bash
5.2.15-2+b13
No fix yet
Not Applicable
CVE-2026-42014NONE0
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Not Applicable
TEMP-0628843-DBAD28NONE0
login
1:4.13+dfsg1-1+deb12u2
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
passwd
1:4.13+dfsg1-1+deb12u2
No fix yet
Not Applicable
CVE-2026-48959NONE0
perl-base
5.36.0-7+deb12u3
No fix yet
Not Applicable
CVE-2025-15649NONE0
perl-base
5.36.0-7+deb12u3
No fix yet
Not Applicable
CVE-2026-7010NONE0
perl-base
5.36.0-7+deb12u3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-48961NONE0
perl-base
5.36.0-7+deb12u3
No fix yet
Not Applicable
TEMP-0517018-A83CE6NONE0
sysvinit-utils
3.06-4
No fix yet
Not Applicable
TEMP-0290435-0B57B5NONE0
tar
1.34+dfsg-1.2+deb12u1
No fix yet
Not Applicable