Vulnerability Reportdenoland/deno:distroless-2.7.11

denoland/deno:distroless-2.7.11
digestsha256:49997c246238b31655ce4b1cd5c59e6b43526004c9bdd9d63a3edbc4cb0adfa1

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. Although the scanner reports 20 exposed and 17 post-exploit findings, the maximum severity is only 5.35 and 3.53 respectively, with no findings reaching the 6.0 threshold. The image is a popular community build from Denoland, pinned by digest, and the minimal startup command limits practical exploitability. The empty top-findings lists confirm that none of these low-severity issues warrant specific mitigation for this deployment context.

Vulnerabilities

Vulnerability Log

37 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-34181MEDIUM5.35
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.41-12+deb13u2
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.5-1~deb13u2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg+really1.3.1-1+b1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-28388MEDIUM4.5
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.5-1~deb13u2
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.41-12+deb13u2
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.41-12+deb13u2
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM4.13
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.5-1~deb13u2
0.8%
Theoretical Threat
Directly Exposed
CVE-2010-4756MEDIUM4
libc6
2.41-12+deb13u2
No fix yet
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2019-1010022LOW3.53
libc6
2.41-12+deb13u2
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-4438LOW3.4
libc6
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
0.3%
Theoretical Threat
Directly Exposed
CVE-2019-1010023LOW3.17
libc6
2.41-12+deb13u2
No fix yet
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-45446LOW3.15
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45447LOW2.92
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45445LOW2.78
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.6%
Theoretical Threat
Post-Exploit
CVE-2018-20796LOW2.7
libc6
2.41-12+deb13u2
No fix yet
5.8%
Low-Moderate Risk
Post-Exploit
CVE-2019-9192LOW2.7
libc6
2.41-12+deb13u2
No fix yet
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.5-1~deb13u2
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.5-1~deb13u2
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34182LOW2.26
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-31790LOW2.12
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.5-1~deb13u2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-42764LOW2.12
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.6-1~deb13u2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-4437LOW1.99
libc6
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.41-12+deb13u2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW1.99
libssl3t64
3.5.5-1~deb13u1
fixed in 3.5.5-1~deb13u2
0.4%
Theoretical Threat
Post-Exploit
CVE-2019-1010024LOW1.91
libc6
2.41-12+deb13u2
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010025LOW1.91
libc6
2.41-12+deb13u2
No fix yet
2.3%
Low-Moderate Risk
Post-Exploit

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.