Vulnerability Reportdenoland/deno:distroless-2.6.4

denoland/deno:distroless-2.6.4
digestsha256:9c76b672638b3996186a20523db5dca6854e9e7e9be6e8eba74c82f766378c2c

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. It has a threat score of 0 and no high-severity vulnerabilities in the exposed surface; the maximum exposed severity is 5.3, and post-exploit findings are low (max 4.06). The only notable CVE, CVE-2025-15467, affects libssl3 and requires the workload to parse untrusted CMS/PKCS#7 messages with AEAD ciphers, which is not part of the default Deno startup command. Because the container runs a simple Deno eval and does not expose such parsing, the practical risk remains negligible. No specific mitigations are required for this deployment context.

Vulnerabilities

Vulnerability Log

46 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2019-1010025MEDIUM5.3
libc6
2.36-9+deb12u13
No fix yet
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.36-9+deb12u13
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15281MEDIUM5.02
libc6
2.36-9+deb12u13
fixed in 2.36-9+deb12u14
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libssl3
3.0.17-1~deb12u3
fixed in 3.0.18-1~deb12u2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libssl3
3.0.17-1~deb12u3
fixed in 3.0.18-1~deb12u2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
libssl3
3.0.17-1~deb12u3
fixed in 3.0.19-1~deb12u2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2022-27943MEDIUM4.67
gcc-12-base
12.2.0-14+deb12u1
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc-s1
12.2.0-14+deb12u1
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgomp1
12.2.0-14+deb12u1
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libssl3
3.0.17-1~deb12u3
fixed in 3.0.18-1~deb12u2
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
0.6%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libstdc++6
12.2.0-14+deb12u1
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-28388MEDIUM4.5
libssl3
3.0.17-1~deb12u3
fixed in 3.0.19-1~deb12u2
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-0915MEDIUM4.5
libc6
2.36-9+deb12u13
fixed in 2.36-9+deb12u14
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.36-9+deb12u13
fixed in 2.36-9+deb12u14
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.0.17-1~deb12u3
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.36-9+deb12u13
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.36-9+deb12u13
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM4.13
libssl3
3.0.17-1~deb12u3
fixed in 3.0.19-1~deb12u2
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
libssl3
3.0.17-1~deb12u3
fixed in 3.0.18-1~deb12u2
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-68160MEDIUM4
libssl3
3.0.17-1~deb12u3
fixed in 3.0.18-1~deb12u2
0.2%
Theoretical Threat
Directly Exposed
CVE-2010-4756MEDIUM4
libc6
2.36-9+deb12u13
No fix yet
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2019-1010022LOW3.53
libc6
2.36-9+deb12u13
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-4438LOW3.4
libc6
2.36-9+deb12u13
fixed in 2.36-9+deb12u14
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libssl3
3.0.17-1~deb12u3
fixed in 3.0.18-1~deb12u2
0.1%
Theoretical Threat
Directly Exposed
CVE-2019-1010023LOW3.17
libc6
2.36-9+deb12u13
No fix yet
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-45446LOW3.15
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45447LOW2.92
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
0.6%
Theoretical Threat
Post-Exploit
CVE-2018-20796LOW2.7
libc6
2.36-9+deb12u13
No fix yet
5.8%
Low-Moderate Risk
Post-Exploit
CVE-2019-9192LOW2.7
libc6
2.36-9+deb12u13
No fix yet
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libssl3
3.0.17-1~deb12u3
fixed in 3.0.19-1~deb12u2
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libssl3
3.0.17-1~deb12u3
fixed in 3.0.19-1~deb12u2
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-0861LOW2.48
libc6
2.36-9+deb12u13
fixed in 2.36-9+deb12u14
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
libssl3
3.0.17-1~deb12u3
fixed in 3.0.18-1~deb12u2
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-69419LOW2.26
libssl3
3.0.17-1~deb12u3
fixed in 3.0.18-1~deb12u2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
libssl3
3.0.17-1~deb12u3
fixed in 3.0.20-1~deb12u2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-31790LOW2.12
libssl3
3.0.17-1~deb12u3
fixed in 3.0.19-1~deb12u2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-4437LOW1.99
libc6
2.36-9+deb12u13
fixed in 2.36-9+deb12u14
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.36-9+deb12u13
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2019-1010024LOW1.91
libc6
2.36-9+deb12u13
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-27587NONE0
libssl3
3.0.17-1~deb12u3
No fix yet
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.