Vulnerability Reportdpage/pgadmin4:9

dpage/pgadmin4:latestdpage/pgadmin4:9.16dpage/pgadmin4:9dpage/pgadmin4:2026-06-17-2
digestsha256:40fa840c5bb7c8463957f1255b01283732c2d8c9396a956d180f8e6c296753b3

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could crash the container via a malicious DNS response (CVE-2026-33630) or leak memory and corrupt heap via crafted images (CVE-2026-54058). Many of the Pillow vulnerabilities require the container to process untrusted user images, so restricting image uploads reduces exposure, but the c-ares flaw is remotely triggerable without special conditions.

Vulnerabilities

Vulnerability Log

38 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33630HIGH7.5
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Directly ExposedContext importance: HIGH
CVE-2026-54058HIGH7.28
pillow
12.2.0
fixed in 12.3.0
Directly ExposedContext importance: MEDIUM
CVE-2026-59197MEDIUM6.56
pillow
12.2.0
fixed in 12.3.0
Directly ExposedContext importance: MEDIUM
CVE-2026-59199MEDIUM6
pillow
12.2.0
fixed in 12.3.0
Directly ExposedContext importance: MEDIUM
CVE-2026-59200MEDIUM6
pillow
12.2.0
fixed in 12.3.0
Directly ExposedContext importance: MEDIUM
CVE-2026-59204MEDIUM6
pillow
12.2.0
fixed in 12.3.0
Directly ExposedContext importance: MEDIUM
CVE-2026-59205MEDIUM6
pillow
12.2.0
fixed in 12.3.0
Directly ExposedContext importance: MEDIUM
CVE-2026-59198MEDIUM6
pillow
12.2.0
fixed in 12.3.0
Directly ExposedContext importance: MEDIUM
CVE-2026-59203MEDIUM6
pillow
12.2.0
fixed in 12.3.0
Directly ExposedContext importance: MEDIUM
CVE-2026-59885MEDIUM6
pyasn1
0.6.3
fixed in 0.6.4
Directly ExposedContext importance: MEDIUM
CVE-2026-59886MEDIUM6
pyasn1
0.6.3
fixed in 0.6.4
Directly ExposedContext importance: MEDIUM
CVE-2026-54059MEDIUM5.1
pillow
12.2.0
fixed in 12.3.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-54060MEDIUM5.1
pillow
12.2.0
fixed in 12.3.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-55379MEDIUM5.1
pillow
12.2.0
fixed in 12.3.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-55380MEDIUM5.1
pillow
12.2.0
fixed in 12.3.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-9546LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-55798LOW3.82
pillow
12.2.0
fixed in 12.3.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-9547LOW3.77
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-59890LOW3.11
setuptools
82.0.1
fixed in 83.0.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.92
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-44405LOW2.89
paramiko
3.5.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-11352LOW2.7
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-9079LOW2.7
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-8286LOW2.48
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW2.34
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11586LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-59939LOW2.29
httplib2
0.31.2
fixed in 0.32.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8458NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Not Applicable
GHSA-f66q-9rf6-8795NONE0
Flask-Security-Too
5.8.1
No fix yet
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.