Vulnerability Reportdrupal:php8.5-fpm-alpine

drupal:php8.5-fpm-alpinedrupal:11.3.11-php8.5-fpm-alpine
digestsha256:035fd1203e2919ad249e6e16a7947c0a0f74985c579986a00168589b041d6483

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
TRUSTED

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The primary concern is CVE-2026-33630, a medium-severity use-after-free in c-ares that could let a malicious DNS server crash the PHP-FPM process during name resolution, leading to a denial of service. There are no high-severity exposed vulnerabilities, and post-exploit findings are low severity. As an official Drupal image with strong trust, the practical risk is limited to service disruption rather than data compromise.

Vulnerabilities

Vulnerability Log

72 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33630MEDIUM6
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Directly ExposedContext importance: MEDIUM
CVE-2026-8927LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2024-45440LOW3.18
drupal/core
9.8.0
fixed in 10.3.6, 11.0.5, 10.2.9
9.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-45440LOW3.18
drupal/core-recommended
9.8.0
fixed in 10.3.6, 11.0.5, 10.2.9
9.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-8286LOW2.48
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.48
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8286LOW2.48
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.48
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11352LOW2.29
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW2.29
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW2.29
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11352LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW2.29
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59882LOW1.99
guzzlehttp/psr7
2.8.1
fixed in 2.12.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-59883LOW1.87
guzzlehttp/guzzle
7.10.5
fixed in 7.12.3
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-48998LOW1.62
guzzlehttp/psr7
2.8.1
fixed in 2.10.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-8458NONE0
curl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-8458NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-55568NONE0
guzzlehttp/guzzle
7.10.5
fixed in 7.12.1
0.1%
Theoretical Threat
Not Applicable
CVE-2026-55767NONE0
guzzlehttp/guzzle
7.10.5
fixed in 7.12.1
0.1%
Theoretical Threat
Not Applicable
GHSA-94pj-82f3-465wNONE0
guzzlehttp/guzzle
7.10.5
fixed in 7.14.2
Not Applicable
GHSA-f283-ghqc-fg79NONE0
guzzlehttp/guzzle
7.10.5
fixed in 7.15.1
Not Applicable
GHSA-h95v-h523-3mw8NONE0
guzzlehttp/guzzle
7.10.5
fixed in 7.15.1
Not Applicable
GHSA-wm3w-8rrp-j577NONE0
guzzlehttp/guzzle
7.10.5
fixed in 7.15.1
Not Applicable
CVE-2026-49214NONE0
guzzlehttp/psr7
2.8.1
fixed in 2.10.2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-55766NONE0
guzzlehttp/psr7
2.8.1
fixed in 2.12.1
0.2%
Theoretical Threat
Not Applicable
CVE-2026-9082NONE0
drupal/core
9.8.0
fixed in 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, 11.3.10
88.3%
Actively Exploited
Not ApplicableContext importance: HIGH
CVE-2024-55637NONE0
drupal/core
9.8.0
fixed in 10.2.11, 10.3.9, 11.0.8
0.8%
Theoretical Threat
Not Applicable
CVE-2024-55638NONE0
drupal/core
9.8.0
fixed in 10.2.11, 10.3.9, 7.102
1.0%
Theoretical Threat
Not Applicable
CVE-2024-12393NONE0
drupal/core
9.8.0
fixed in 10.2.11, 10.3.9, 11.0.8
0.3%
Theoretical Threat
Not Applicable
CVE-2024-55634NONE0
drupal/core
9.8.0
fixed in 10.2.11, 10.3.9, 11.0.8
0.4%
Theoretical Threat
Not Applicable
CVE-2025-13081NONE0
drupal/core
9.8.0
fixed in 10.4.9, 10.5.6, 11.1.9, 11.2.8
0.3%
Theoretical Threat
Not Applicable
CVE-2025-3057NONE0
drupal/core
9.8.0
fixed in 10.3.13, 10.4.3, 11.0.12, 11.1.3
0.3%
Theoretical Threat
Not Applicable
CVE-2025-31673NONE0
drupal/core
9.8.0
fixed in 10.3.13, 10.4.3, 11.0.12, 11.1.3
0.3%
Theoretical Threat
Not Applicable
CVE-2025-31674NONE0
drupal/core
9.8.0
fixed in 10.3.13, 10.4.3, 11.0.12, 11.1.3
0.5%
Theoretical Threat
Not Applicable
CVE-2026-6365NONE0
drupal/core
9.8.0
fixed in 10.5.9, 10.6.7, 11.2.11, 11.3.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6366NONE0
drupal/core
9.8.0
fixed in 10.5.9, 10.6.7, 11.2.11, 11.3.7
0.4%
Theoretical Threat
Not Applicable
GHSA-6ccv-8fgf-cjpwNONE0
drupal/core
9.8.0
fixed in 10.1.8, 10.2.2
Not Applicable
CVE-2024-55636NONE0
drupal/core
9.8.0
fixed in 10.2.11, 10.3.9, 11.0.8
0.9%
Theoretical Threat
Not Applicable
CVE-2025-13080NONE0
drupal/core
9.8.0
fixed in 10.4.9, 10.5.6, 11.1.9, 11.2.8
0.3%
Theoretical Threat
Not Applicable
CVE-2025-13082NONE0
drupal/core
9.8.0
fixed in 10.4.9, 10.5.6, 11.1.9, 11.2.8
0.2%
Theoretical Threat
Not Applicable
CVE-2025-13083NONE0
drupal/core
9.8.0
fixed in 10.4.9, 10.5.6, 11.1.9, 11.2.8, 7.103
0.3%
Theoretical Threat
Not Applicable
CVE-2025-31675NONE0
drupal/core
9.8.0
fixed in 10.3.14, 10.4.5, 11.0.13, 11.1.5
0.5%
Theoretical Threat
Not Applicable
CVE-2024-55637NONE0
drupal/core-recommended
9.8.0
fixed in 10.2.11, 10.3.9, 11.0.8
0.8%
Theoretical Threat
Not Applicable
CVE-2024-55638NONE0
drupal/core-recommended
9.8.0
fixed in 10.2.11, 10.3.9, 7.102
1.0%
Theoretical Threat
Not Applicable
CVE-2024-12393NONE0
drupal/core-recommended
9.8.0
fixed in 10.2.11, 10.3.9, 11.0.8
0.3%
Theoretical Threat
Not Applicable
CVE-2024-55634NONE0
drupal/core-recommended
9.8.0
fixed in 10.2.11, 10.3.9, 11.0.8
0.4%
Theoretical Threat
Not Applicable
CVE-2024-55636NONE0
drupal/core-recommended
9.8.0
fixed in 10.2.11, 10.3.9, 11.0.8
0.9%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.