Vulnerability Reportfullstorydev/grpcui:latest

fullstorydev/grpcui:latestfullstorydev/grpcui:v1.5.2
digestsha256:a528a3e36e075bba4b3f34b42fa437bb6eb9682be99f28c1095438d24bcfa587

Executive Summary

Last scanned:

Threat Score
5/100SAFE
Reputation
UNVERIFIED

This image is safe for production use. The three exposed and two post-exploit vulnerabilities are all low severity (max CVSS 3.6) and do not pose a practical risk in this context. The image runs as a gRPC UI server binding to all interfaces, but no exploitable weaknesses exist. Pinning by digest adds supply chain assurance.

Vulnerabilities

Vulnerability Log

5 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42505LOW3.6
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33186LOW3.28
google.golang.org/grpc
v1.66.2
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.66.2
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.