Vulnerability Reportenvoyproxy/envoy:contrib-distroless-dev-7391e85629947836c65ca9f7e591326e51b5c084

envoyproxy/envoy:contrib-distroless-dev-7391e85629947836c65ca9f7e591326e51b5c084
digestsha256:959db4f9985c2d1cf9118fc7fd70fcbd2f20f7290596211357a6dc697d73e745

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Two medium-severity vulnerabilities (CVE-2018-20796, CVE-2019-9192) in glibc's regex engine could cause denial of service, but Envoy commonly uses its own RE2 regex library, so the practical exploitability is limited in typical deployments. Upgrading glibc to a patched version would fully address these issues.

Vulnerabilities

Vulnerability Log

11 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2018-20796MEDIUM6
libc6
2.36-9+deb12u14
No fix yet
5.8%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2019-9192MEDIUM6
libc6
2.36-9+deb12u14
No fix yet
2.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-5450MEDIUM4.25
libc6
2.36-9+deb12u14
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.36-9+deb12u14
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2019-1010022LOW3.53
libc6
2.36-9+deb12u14
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010023LOW3.17
libc6
2.36-9+deb12u14
No fix yet
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.36-9+deb12u14
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2019-1010024LOW1.91
libc6
2.36-9+deb12u14
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010025LOW1.91
libc6
2.36-9+deb12u14
No fix yet
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.36-9+deb12u14
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2010-4756LOW1.44
libc6
2.36-9+deb12u14
No fix yet
2.6%
Low-Moderate Risk
Post-Exploit

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.