Last scanned:
This image is safe for production use. The image has an excellent reputation and is pinned by digest, ensuring integrity. While there are a few low-severity vulnerabilities (exposed_total=4), they have minimal or no practical impact due to their low severity and the container's context. No high-severity or critical findings are present. The threat score of 0 confirms the low risk.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-6791 | NONE0 | glibc 2.43-r8 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | glibc-locale-posix 2.43-r8 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | ld-linux 2.43-r8 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | libcrypt1 2.43-r8 fixed in 2.43-r10 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.