Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could crash the container via a malicious DNS response (CVE-2026-33630) or leak memory and corrupt heap via crafted images (CVE-2026-54058). Many of the Pillow vulnerabilities require the container to process untrusted user images, so restricting image uploads reduces exposure, but the c-ares flaw is remotely triggerable without special conditions.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-33630 | HIGH7.5 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | — | Directly ExposedContext importance: HIGH |
| CVE-2026-54058 | HIGH7.28 | pillow 12.2.0 fixed in 12.3.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59197 | MEDIUM6.56 | pillow 12.2.0 fixed in 12.3.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59199 | MEDIUM6 | pillow 12.2.0 fixed in 12.3.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59200 | MEDIUM6 | pillow 12.2.0 fixed in 12.3.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59204 | MEDIUM6 | pillow 12.2.0 fixed in 12.3.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59205 | MEDIUM6 | pillow 12.2.0 fixed in 12.3.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59198 | MEDIUM6 | pillow 12.2.0 fixed in 12.3.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59203 | MEDIUM6 | pillow 12.2.0 fixed in 12.3.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59885 | MEDIUM6 | pyasn1 0.6.3 fixed in 0.6.4 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59886 | MEDIUM6 | pyasn1 0.6.3 fixed in 0.6.4 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54059 | MEDIUM5.1 | pillow 12.2.0 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54060 | MEDIUM5.1 | pillow 12.2.0 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-55379 | MEDIUM5.1 | pillow 12.2.0 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-55380 | MEDIUM5.1 | pillow 12.2.0 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-9546 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-55798 | LOW3.82 | pillow 12.2.0 fixed in 12.3.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-9547 | LOW3.77 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-11564 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-59890 | LOW3.11 | setuptools 82.0.1 fixed in 83.0.0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8925 | LOW2.92 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-44405 | LOW2.89 | paramiko 3.5.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-11352 | LOW2.7 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-9079 | LOW2.7 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW2.34 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11586 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW2.29 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59939 | LOW2.29 | httplib2 0.31.2 fixed in 0.32.0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8458 | NONE0 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Not Applicable |
| GHSA-f66q-9rf6-8795 | NONE0 | Flask-Security-Too 5.8.1 No fix yet | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.