Vulnerability Reportgitea/gitea:1.20.6-rootless

gitea/gitea:1.20.6-rootless
digestsha256:7e3e00fac37a79b623f990cb5217925e914d130b7f43b4544aaf4da2b221efeb

Executive Summary

Last scanned:

Threat Score
100/100DANGEROUS
Reputation
RELIABLE

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit stored XSS to hijack admin sessions, or leverage HTTP/2 CONTINUATION frame flooding to crash the service, while other library flaws could enable SSRF or memory corruption. These vulnerabilities are reachable without special configuration, so this image is unsuitable for deployment until all critical and high-severity findings are fixed.

Vulnerabilities

Vulnerability Log

313 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2024-6886CRITICAL10
code.gitea.io/gitea
1.20.6
fixed in 1.22.1
33.0%
High Exploitation Risk
Directly ExposedContext importance: HIGH
CVE-2023-45288CRITICAL9.75
golang.org/x/net
v0.13.0
fixed in 0.23.0
92.0%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2023-45288CRITICAL9.75
stdlib
v1.20.11
fixed in 1.21.9, 1.22.2
92.0%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2024-24790HIGH7.84
stdlib
v1.20.11
fixed in 1.21.11, 1.22.4
2.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-0553HIGH7.5
gnutls
3.8.0-r2
fixed in 3.8.3-r0
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-0567HIGH7.5
gnutls
3.8.0-r2
fixed in 3.8.3-r0
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2023-5363HIGH7.5
libcrypto3
3.1.3-r0
fixed in 3.1.4-r0
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-28757HIGH7.5
libexpat
2.5.0-r1
fixed in 2.6.2-r0
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-45490HIGH7.5
libexpat
2.5.0-r1
fixed in 2.6.3-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2024-8176HIGH7.5
libexpat
2.5.0-r1
fixed in 2.7.0-r0
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-5363HIGH7.5
libssl3
3.1.3-r0
fixed in 3.1.4-r0
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-25062HIGH7.5
libxml2
2.11.6-r0
fixed in 2.11.7-r0
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2025-27113HIGH7.5
libxml2
2.11.6-r0
fixed in 2.11.8-r2
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-32952HIGH7.5
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-39325HIGH7.5
golang.org/x/net
v0.13.0
fixed in 0.17.0
3.8%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2024-34156HIGH7.5
stdlib
v1.20.11
fixed in 1.22.7, 1.23.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-61726HIGH7.5
stdlib
v1.20.11
fixed in 1.24.12, 1.25.6
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-39828HIGH7.48
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39832HIGH7.39
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2023-7104HIGH7.3
sqlite-libs
3.41.2-r2
fixed in 3.41.2-r3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-39821MEDIUM6.97
golang.org/x/net
v0.13.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-44973MEDIUM6.88
github.com/go-git/go-billy/v5
v5.4.1
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-3445MEDIUM6.88
github.com/mholt/archiver/v3
v3.5.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39831MEDIUM6.88
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-25681MEDIUM6.88
golang.org/x/net
v0.13.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27136MEDIUM6.88
golang.org/x/net
v0.13.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-0406MEDIUM6.63
github.com/mholt/archiver/v3
v3.5.1
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM6.63
stdlib
v1.20.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-45337MEDIUM6.56
golang.org/x/crypto
v0.11.0
fixed in 0.31.0
3.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-24928MEDIUM6.54
libxml2
2.11.6-r0
fixed in 2.11.8-r1
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-6129MEDIUM6.5
libcrypto3
3.1.3-r0
fixed in 3.1.4-r3
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-6129MEDIUM6.5
libssl3
3.1.3-r0
fixed in 3.1.4-r3
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-32414MEDIUM6.38
libxml2
2.11.6-r0
fixed in 2.11.8-r3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-32415MEDIUM6.38
libxml2
2.11.6-r0
fixed in 2.11.8-r3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-31115MEDIUM6.38
xz-libs
5.4.3-r0
fixed in 5.4.3-r1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-20736MEDIUM6.38
code.gitea.io/gitea
1.20.6
fixed in 1.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44740MEDIUM6.38
github.com/go-git/go-billy/v5
v5.4.1
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-49568MEDIUM6.38
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.11.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-21614MEDIUM6.38
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.13.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-45022MEDIUM6.38
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.19.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt/v4
v4.5.0
fixed in 4.5.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-65637MEDIUM6.38
github.com/sirupsen/logrus
v1.9.0
fixed in 1.8.3, 1.9.1, 1.9.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-22869MEDIUM6.38
golang.org/x/crypto
v0.11.0
fixed in 0.35.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-47913MEDIUM6.38
golang.org/x/crypto
v0.11.0
fixed in 0.43.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-45338MEDIUM6.38
golang.org/x/net
v0.13.0
fixed in 0.33.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.13.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-22868MEDIUM6.38
golang.org/x/oauth2
v0.8.0
fixed in 0.27.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM6.38
stdlib
v1.20.11
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.8, 1.26.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.20.11
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.20.11
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-41506MEDIUM6.29
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2023-48795MEDIUM6.14
golang.org/x/crypto
v0.11.0
fixed in 0.17.0
93.3%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-26519MEDIUM5.95
musl
1.2.4-r1
fixed in 1.2.4-r3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47907MEDIUM5.95
stdlib
v1.20.11
fixed in 1.23.12, 1.24.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-5981MEDIUM5.9
gnutls
3.8.0-r2
fixed in 3.8.3-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-6237MEDIUM5.9
libcrypto3
3.1.3-r0
fixed in 3.1.4-r4
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-5535MEDIUM5.9
libcrypto3
3.1.3-r0
fixed in 3.1.6-r0
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-50602MEDIUM5.9
libexpat
2.5.0-r1
fixed in 2.6.4-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-6237MEDIUM5.9
libssl3
3.1.3-r0
fixed in 3.1.4-r4
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-5535MEDIUM5.9
libssl3
3.1.3-r0
fixed in 3.1.6-r0
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-24786MEDIUM5.9
google.golang.org/protobuf
v1.30.0
fixed in 1.33.0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-24791MEDIUM5.9
stdlib
v1.20.11
fixed in 1.21.12, 1.22.5
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2024-34158MEDIUM5.9
stdlib
v1.20.11
fixed in 1.22.7, 1.23.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-4673MEDIUM5.78
stdlib
v1.20.11
fixed in 1.23.10, 1.24.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-4741MEDIUM5.6
libcrypto3
3.1.3-r0
fixed in 3.1.6-r0
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2024-4741MEDIUM5.6
libssl3
3.1.3-r0
fixed in 3.1.6-r0
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2025-11579MEDIUM5.52
github.com/nwaples/rardecode
v1.1.3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2023-29407MEDIUM5.52
golang.org/x/image
v0.7.0
fixed in 0.10.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-29408MEDIUM5.52
golang.org/x/image
v0.7.0
fixed in 0.10.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33809MEDIUM5.52
golang.org/x/image
v0.7.0
fixed in 0.38.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33813MEDIUM5.52
golang.org/x/image
v0.7.0
fixed in 0.42.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46599MEDIUM5.52
golang.org/x/image
v0.7.0
fixed in 0.41.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46601MEDIUM5.52
golang.org/x/image
v0.7.0
fixed in 0.43.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22872MEDIUM5.52
golang.org/x/net
v0.13.0
fixed in 0.38.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.13.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-24785MEDIUM5.52
stdlib
v1.20.11
fixed in 1.21.8, 1.22.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-47906MEDIUM5.52
stdlib
v1.20.11
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.20.11
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.20.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-0727MEDIUM5.5
libcrypto3
3.1.3-r0
fixed in 3.1.4-r5
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-0727MEDIUM5.5
libssl3
3.1.3-r0
fixed in 3.1.4-r5
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-34459MEDIUM5.5
libxml2
2.11.6-r0
fixed in 2.11.8-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.20.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-24784MEDIUM5.4
stdlib
v1.20.11
fixed in 1.21.8, 1.22.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
libcrypto3
3.1.3-r0
fixed in 3.1.4-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2024-4603MEDIUM5.3
libcrypto3
3.1.3-r0
fixed in 3.1.5-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
libssl3
3.1.3-r0
fixed in 3.1.4-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2024-4603MEDIUM5.3
libssl3
3.1.3-r0
fixed in 3.1.5-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-12133MEDIUM5.3
libtasn1
4.19.0-r1
fixed in 4.20.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-39326MEDIUM5.3
stdlib
v1.20.11
fixed in 1.20.12, 1.21.5
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2023-45289MEDIUM5.3
stdlib
v1.20.11
fixed in 1.21.8, 1.22.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-45290MEDIUM5.3
stdlib
v1.20.11
fixed in 1.21.8, 1.22.1
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-33812MEDIUM5.18
golang.org/x/image
v0.7.0
fixed in 0.39.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.13.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.20.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68121MEDIUM5.1
stdlib
v1.20.11
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-24783MEDIUM5.02
stdlib
v1.20.11
fixed in 1.21.8, 1.22.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-34155MEDIUM5.02
stdlib
v1.20.11
fixed in 1.22.7, 1.23.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-45336MEDIUM5.02
stdlib
v1.20.11
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-32002MEDIUM4.97
git
2.40.1-r0
fixed in 2.40.3-r0
25.3%
High Exploitation Risk
Post-ExploitContext importance: MEDIUM
CVE-2024-2511MEDIUM4.81
libcrypto3
3.1.3-r0
fixed in 3.1.4-r6
54.0%
Actively Exploited
Directly Exposed
CVE-2024-2511MEDIUM4.81
libssl3
3.1.3-r0
fixed in 3.1.4-r6
54.0%
Actively Exploited
Directly Exposed
CVE-2023-49569MEDIUM4.7
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.11.0
1.5%
Low-Moderate Risk
Post-ExploitContext importance: MEDIUM
CVE-2023-52426MEDIUM4.67
libexpat
2.5.0-r1
fixed in 2.6.0-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2022-31022MEDIUM4.67
github.com/blevesearch/bleve/v2
v2.3.7
fixed in 2.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-6104MEDIUM4.67
github.com/hashicorp/go-retryablehttp
v0.7.2
fixed in 0.7.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-24789MEDIUM4.67
stdlib
v1.20.11
fixed in 1.21.11, 1.22.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.20.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68942MEDIUM4.59
code.gitea.io/gitea
1.20.6
fixed in 1.22.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45571MEDIUM4.59
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.19.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.13.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-22871MEDIUM4.59
stdlib
v1.20.11
fixed in 1.23.8, 1.24.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.20.11
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.20.11
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.20.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-28834MEDIUM4.5
gnutls
3.8.0-r2
fixed in 3.8.4-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-68939MEDIUM4.5
code.gitea.io/gitea
1.20.6
fixed in 1.23.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68938MEDIUM4.5
code.gitea.io/gitea
1.20.6
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68941MEDIUM4.5
code.gitea.io/gitea
1.20.6
fixed in 1.22.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68943MEDIUM4.5
code.gitea.io/gitea
1.20.6
fixed in 1.21.8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68944MEDIUM4.5
code.gitea.io/gitea
1.20.6
fixed in 1.22.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68945MEDIUM4.5
code.gitea.io/gitea
1.20.6
fixed in 1.21.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-69413MEDIUM4.5
code.gitea.io/gitea
1.20.6
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68940MEDIUM4.5
code.gitea.io/gitea
1.20.6
fixed in 1.22.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58058MEDIUM4.5
github.com/ulikunitz/xz
v0.5.11
fixed in 0.5.15
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.11.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.11.0
fixed in 0.45.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.11.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.13.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.13.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22866MEDIUM4.5
stdlib
v1.20.11
fixed in 1.22.12, 1.23.6, 1.24.0-rc.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22873MEDIUM4.5
stdlib
v1.20.11
fixed in 1.23.9, 1.24.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.20.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.20.11
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.20.11
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-28835MEDIUM4.25
gnutls
3.8.0-r2
fixed in 3.8.4-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34165MEDIUM4.25
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.17.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-1386MEDIUM4.17
github.com/ClickHouse/ch-go
v0.55.0
fixed in 0.65.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libcrypto3
3.1.3-r0
fixed in 3.1.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libssl3
3.1.3-r0
fixed in 3.1.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-32465LOW3.98
git
2.40.1-r0
fixed in 2.40.3-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2024-9681LOW3.9
curl
8.4.0-r0
fixed in 8.11.0-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-46218LOW3.9
libcurl
8.4.0-r0
fixed in 8.5.0-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-9681LOW3.9
libcurl
8.4.0-r0
fixed in 8.11.0-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-22870LOW3.74
golang.org/x/net
v0.13.0
fixed in 0.36.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
stdlib
v1.20.11
fixed in 1.23.7, 1.24.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-9143LOW3.7
libcrypto3
3.1.3-r0
fixed in 3.1.7-r1
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2024-9143LOW3.7
libssl3
3.1.3-r0
fixed in 3.1.7-r1
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-25934LOW3.65
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.16.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-32021LOW3.62
git
2.40.1-r0
fixed in 2.40.3-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2025-6965LOW3.61
sqlite-libs
3.41.2-r2
fixed in 3.41.2-r4
74.4%
Actively Exploited
Post-Exploit
CVE-2024-45341LOW3.57
stdlib
v1.20.11
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-11053LOW3.54
curl
8.4.0-r0
fixed in 8.11.1-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-11053LOW3.54
libcurl
8.4.0-r0
fixed in 8.11.1-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-45491LOW3.53
libexpat
2.5.0-r1
fixed in 2.6.3-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-45492LOW3.53
libexpat
2.5.0-r1
fixed in 2.6.3-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-56171LOW3.53
libxml2
2.11.6-r0
fixed in 2.11.8-r1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-6119LOW3.51
libcrypto3
3.1.3-r0
fixed in 3.1.7-r0
66.6%
Actively Exploited
Post-Exploit
CVE-2024-6119LOW3.51
libssl3
3.1.3-r0
fixed in 3.1.7-r0
66.6%
Actively Exploited
Post-Exploit
CVE-2024-8096LOW3.31
curl
8.4.0-r0
fixed in 8.10.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-8096LOW3.31
libcurl
8.4.0-r0
fixed in 8.10.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-33186LOW3.28
google.golang.org/grpc
v1.53.0
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2024-2379LOW3.24
curl
8.4.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-2379LOW3.24
libcurl
8.4.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
curl
8.4.0-r0
fixed in 8.5.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-0853LOW3.18
curl
8.4.0-r0
fixed in 8.6.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-2466LOW3.18
curl
8.4.0-r0
fixed in 8.7.1-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
curl
8.4.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
libcurl
8.4.0-r0
fixed in 8.5.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-0853LOW3.18
libcurl
8.4.0-r0
fixed in 8.6.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-2466LOW3.18
libcurl
8.4.0-r0
fixed in 8.7.1-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
libcurl
8.4.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2025-8556LOW3.15
github.com/cloudflare/circl
v1.3.3
fixed in 1.6.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-2398LOW3.1
curl
8.4.0-r0
fixed in 8.7.1-r0
36.1%
High Exploitation Risk
Post-Exploit
CVE-2024-2398LOW3.1
libcurl
8.4.0-r0
fixed in 8.7.1-r0
36.1%
High Exploitation Risk
Post-Exploit
CVE-2026-1229LOW3
github.com/cloudflare/circl
v1.3.3
fixed in 1.6.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-0798LOW2.98
code.gitea.io/gitea
1.20.6
fixed in 1.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45570LOW2.94
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.19.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-21613LOW2.92
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.13.0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-32004LOW2.81
git
2.40.1-r0
fixed in 2.40.3-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-42363LOW2.8
busybox
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
busybox
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
busybox
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
busybox
1.36.1-r2
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42363LOW2.8
busybox-binsh
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
busybox-binsh
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
busybox-binsh
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
busybox-binsh
1.36.1-r2
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42363LOW2.8
ssl_client
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
ssl_client
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
ssl_client
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
ssl_client
1.36.1-r2
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-6197LOW2.7
curl
8.4.0-r0
fixed in 8.9.0-r0
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-52006LOW2.7
git
2.40.1-r0
fixed in 2.40.4-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-6197LOW2.7
libcurl
8.4.0-r0
fixed in 8.9.0-r0
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-52425LOW2.7
libexpat
2.5.0-r1
fixed in 2.6.0-r0
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2024-7264LOW2.69
curl
8.4.0-r0
fixed in 8.9.1-r0
17.3%
High Exploitation Risk
Post-Exploit
CVE-2024-7264LOW2.69
libcurl
8.4.0-r0
fixed in 8.9.1-r0
17.3%
High Exploitation Risk
Post-Exploit
CVE-2024-51744LOW2.63
github.com/golang-jwt/jwt/v4
v4.5.0
fixed in 4.5.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-50349LOW2.4
git
2.40.1-r0
fixed in 2.40.4-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-0665LOW2.4
curl
8.4.0-r0
fixed in 8.12.0-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-0725LOW2.4
curl
8.4.0-r0
fixed in 8.12.0-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-0665LOW2.4
libcurl
8.4.0-r0
fixed in 8.12.0-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-0725LOW2.4
libcurl
8.4.0-r0
fixed in 8.12.0-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-33762LOW2.38
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.17.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-46218LOW2.34
curl
8.4.0-r0
fixed in 8.5.0-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-6874LOW2.19
curl
8.4.0-r0
fixed in 8.9.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2024-6874LOW2.19
libcurl
8.4.0-r0
fixed in 8.9.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.20.11
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-32020LOW1.68
git
2.40.1-r0
fixed in 2.40.3-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-26519NONE0
musl-utils
1.2.4-r1
fixed in 1.2.4-r3
0.3%
Theoretical Threat
Not Applicable
CVE-2025-0167NONE0
curl
8.4.0-r0
fixed in 8.12.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-0167NONE0
libcurl
8.4.0-r0
fixed in 8.12.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-20896NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.3
31.8%
High Exploitation Risk
Not Applicable
CVE-2026-22874NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-56750NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58443NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-20779NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-22555NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-24451NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-25038NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-26231NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27771NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.2
43.1%
High Exploitation Risk
Not Applicable
CVE-2026-27775NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28699NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.2
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28744NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54481NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-55987NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-56654NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-56755NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-57894NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58314NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58419NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58421NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58422NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58424NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58436NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58437NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-20706NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25714NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27761NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27783NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42931NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-50105NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-55982NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-56443NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-56657NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-57886NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-57897NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58418NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58425NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58428NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58429NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58432NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58435NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58441NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58442NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58444NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58507NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58510NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-59763NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-59765NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-59766NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
GHSA-3m6q-h5gj-7mrwNONE0
code.gitea.io/gitea
1.20.6
fixed in 1.25.0
Not Applicable
GHSA-rjvx-x5h2-6px5NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.26.0
Not Applicable
CVE-2026-23603NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-55984NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58434NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58445NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
CVE-2026-58511NONE0
code.gitea.io/gitea
1.20.6
fixed in 1.27.0
Not Applicable
GHSA-9763-4f94-gfchNONE0
github.com/cloudflare/circl
v1.3.3
fixed in 1.3.7
Not Applicable
GHSA-vrw8-fxc6-2r93NONE0
github.com/go-chi/chi/v5
v5.0.8
fixed in 5.2.2
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.6.1
fixed in 5.19.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.11.0
No fix yet
Not Applicable
CVE-2026-46602NONE0
golang.org/x/image
v0.7.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46604NONE0
golang.org/x/image
v0.7.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2024-24792NONE0
golang.org/x/image
v0.7.0
fixed in 0.18.0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-42500NONE0
golang.org/x/image
v0.7.0
fixed in 0.41.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.13.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.10.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.11.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.53.0
fixed in 1.82.1
Not Applicable
GHSA-m425-mq94-257gNONE0
google.golang.org/grpc
v1.53.0
fixed in 1.56.3, 1.57.1, 1.58.3
Not Applicable
CVE-2025-0913NONE0
stdlib
v1.20.11
fixed in 1.23.10, 1.24.4
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.