Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The most concerning findings are CVE-2026-29111, which could enable arbitrary code execution or denial of service in systemd-based environments, and CVE-2026-40356, which can cause denial of service via a NULL pointer dereference in Kerberos. However, these require specific conditions: systemd as PID 1 is not present (tini is used), and the Kerberos issue only applies if the NegoEx mechanism is registered in /etc/gss/mech. The exposed surface also includes 79 total vulnerabilities, with 16 rated at or above 6.0 severity, but none reach 7.0. Remediating the affected packages or applying network restrictions is recommended to lower the attack surface before production deployment.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-29111 | MEDIUM6.63 | libudev1 249.11-0ubuntu3.17 fixed in 249.11-0ubuntu3.19 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-41989 | MEDIUM6.38 | libgcrypt20 1.9.4-3ubuntu3 fixed in 1.9.4-3ubuntu3.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.21 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-3833 | MEDIUM6.29 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42011 | MEDIUM6.29 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.21 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42012 | MEDIUM6.03 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4878 | MEDIUM5.95 | libcap2 1:2.44-1ubuntu0.22.04.2 fixed in 1:2.44-1ubuntu0.22.04.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-2236 | MEDIUM5.9 | libgcrypt20 1.9.4-3ubuntu3 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.23 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1-6 4.18.0-4ubuntu0.1 fixed in 4.18.0-4ubuntu0.2 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42010 | MEDIUM5.88 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42014 | MEDIUM5.61 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-40225 | MEDIUM5.44 | libsystemd0 249.11-0ubuntu3.17 fixed in 249.11-0ubuntu3.19 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libsystemd0 249.11-0ubuntu3.17 fixed in 249.11-0ubuntu3.21 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40225 | MEDIUM5.44 | libudev1 249.11-0ubuntu3.17 fixed in 249.11-0ubuntu3.19 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libudev1 249.11-0ubuntu3.17 fixed in 249.11-0ubuntu3.21 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.24.0-6build1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-15281 | MEDIUM5.02 | libc-bin 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.13 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15281 | MEDIUM5.02 | libc6 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.13 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.21 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.21 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-7008 | MEDIUM5.02 | libsystemd0 249.11-0ubuntu3.17 fixed in 249.11-0ubuntu3.21 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-7008 | MEDIUM5.02 | libudev1 249.11-0ubuntu3.17 fixed in 249.11-0ubuntu3.21 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libgcc-s1 12.3.0-1ubuntu1~22.04.2 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.21 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libstdc++6 12.3.0-1ubuntu1~22.04.2 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-33845 | MEDIUM4.64 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-33846 | MEDIUM4.5 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42009 | MEDIUM4.5 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28388 | MEDIUM4.5 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.23 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-0915 | MEDIUM4.5 | libc-bin 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.13 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc-bin 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0915 | MEDIUM4.5 | libc6 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.13 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc6 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-14831 | MEDIUM4.5 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42015 | MEDIUM4.5 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | liblzma5 5.2.5-2ubuntu1 fixed in 5.2.5-2ubuntu1.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42013 | MEDIUM4.18 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5260 | MEDIUM4.18 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM4.13 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.23 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-15467 | MEDIUM4.06 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.21 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.37.2-4ubuntu3.4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.37.2-4ubuntu3.4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.37.2-4ubuntu3.4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.21 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.37.2-4ubuntu3.4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9820 | LOW3.4 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.8 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.21 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2021-46848 | LOW3.28 | libtasn1-6 4.18.0-4ubuntu0.1 fixed in 4.18.0-4ubuntu0.2 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5958 | LOW3.21 | sed 4.8-1ubuntu2 fixed in 4.8-1ubuntu2.1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3832 | LOW3.15 | libgnutls30 3.7.3-4ubuntu1.7 fixed in 3.7.3-4ubuntu1.9 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | LOW3 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.23 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | perl-base 5.34.0-3ubuntu1.5 fixed in 5.34.0-3ubuntu1.7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-45582 | LOW2.86 | tar 1.34+dfsg-1ubuntu0.1.22.04.2 fixed in 1.34+dfsg-1ubuntu0.1.22.04.4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.34+dfsg-1ubuntu0.1.22.04.2 fixed in 1.34+dfsg-1ubuntu0.1.22.04.6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-40228 | LOW2.8 | libsystemd0 249.11-0ubuntu3.17 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 249.11-0ubuntu3.17 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45445 | LOW2.78 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.25 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-42496 | LOW2.78 | perl-base 5.34.0-3ubuntu1.5 fixed in 5.34.0-3ubuntu1.7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-41409 | LOW2.7 | libpcre2-8-0 10.39-3ubuntu0.1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.23 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | libssl3 3.0.2-0ubuntu1.20 fixed in 3.0.2-0ubuntu1.23 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2022-4899 | LOW2.7 | libzstd1 1.4.8+dfsg-3build1 No fix yet | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-0861 | LOW2.48 | libc-bin 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.13 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-0861 | LOW2.48 | libc6 2.35-0ubuntu3.11 fixed in 2.35-0ubuntu3.13 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.37.2-4ubuntu3.4 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.10-4ubuntu4.1 fixed in 1.10-4ubuntu4.2 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.37.2-4ubuntu3.4 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.37.2-4ubuntu3.4 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-29111 | LOW2.39 | libsystemd0 249.11-0ubuntu3.17 fixed in 249.11-0ubuntu3.19 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41992 | LOW2.29 | gzip 1.10-4ubuntu4.1 fixed in 1.10-4ubuntu4.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | login 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | login 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | passwd 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69720 | NONE0 | libncurses6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libncursesw6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libtinfo6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-base 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-bin 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncurses6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncursesw6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libtinfo6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-base 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-bin 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2022-27943 | NONE0 | gcc-12-base 12.3.0-1ubuntu1~22.04.2 No fix yet | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules-bin 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-runtime 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam0g 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.