Vulnerability Reportgitea/gitea:1.21.1-rootless

gitea/gitea:1.21.1-rootless
digestsha256:00486bc884e745209e8246b3d070761310d0e4334e4cacea52b3ce8b7c2a065a

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The stored XSS (CVE-2024-6886) could allow session hijacking or admin account takeover, while the SSH Terrapin flaw (CVE-2023-48795) could downgrade SSH integrity protections when clients connect through a network attacker. Although 64 post-exploit findings exist, their maximum severity is only 3.98, so the immediate risk is concentrated in the exposed surface. Note that the HTTP/2 DoS only applies when HTTP/2 is exposed; disabling HTTP/2 would fully eliminate that risk.

Vulnerabilities

Vulnerability Log

309 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2024-6886CRITICAL10
code.gitea.io/gitea
1.21.1
fixed in 1.22.1
33.0%
High Exploitation Risk
Directly ExposedContext importance: HIGH
CVE-2024-24790HIGH7.84
stdlib
v1.21.4
fixed in 1.21.11, 1.22.4
2.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2023-45288HIGH7.8
golang.org/x/net
v0.17.0
fixed in 0.23.0
92.0%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2023-45288HIGH7.8
stdlib
v1.21.4
fixed in 1.21.9, 1.22.2
92.0%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2023-48795HIGH7.67
golang.org/x/crypto
v0.14.0
fixed in 0.17.0
93.3%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2024-0553HIGH7.5
gnutls
3.8.0-r2
fixed in 3.8.3-r0
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-0567HIGH7.5
gnutls
3.8.0-r2
fixed in 3.8.3-r0
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2024-28757HIGH7.5
libexpat
2.5.0-r1
fixed in 2.6.2-r0
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-45490HIGH7.5
libexpat
2.5.0-r1
fixed in 2.6.3-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2024-8176HIGH7.5
libexpat
2.5.0-r1
fixed in 2.7.0-r0
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-5363HIGH7.5
libssl3
3.1.3-r0
fixed in 3.1.4-r0
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-25062HIGH7.5
libxml2
2.11.6-r0
fixed in 2.11.7-r0
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2025-27113HIGH7.5
libxml2
2.11.6-r0
fixed in 2.11.8-r2
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-32952HIGH7.5
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-34156HIGH7.5
stdlib
v1.21.4
fixed in 1.22.7, 1.23.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-61726HIGH7.5
stdlib
v1.21.4
fixed in 1.24.12, 1.25.6
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-39828HIGH7.48
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39832HIGH7.39
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2023-7104HIGH7.3
sqlite-libs
3.41.2-r2
fixed in 3.41.2-r3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-39821MEDIUM6.97
golang.org/x/net
v0.17.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-44973MEDIUM6.88
github.com/go-git/go-billy/v5
v5.5.0
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-3445MEDIUM6.88
github.com/mholt/archiver/v3
v3.5.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39831MEDIUM6.88
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-25681MEDIUM6.88
golang.org/x/net
v0.17.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27136MEDIUM6.88
golang.org/x/net
v0.17.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68121MEDIUM6.8
stdlib
v1.21.4
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2024-0406MEDIUM6.63
github.com/mholt/archiver/v3
v3.5.1
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM6.63
stdlib
v1.21.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-45337MEDIUM6.56
golang.org/x/crypto
v0.14.0
fixed in 0.31.0
3.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-24928MEDIUM6.54
libxml2
2.11.6-r0
fixed in 2.11.8-r1
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-6129MEDIUM6.5
libcrypto3
3.1.3-r0
fixed in 3.1.4-r3
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-6129MEDIUM6.5
libssl3
3.1.3-r0
fixed in 3.1.4-r3
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-32414MEDIUM6.38
libxml2
2.11.6-r0
fixed in 2.11.8-r3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-32415MEDIUM6.38
libxml2
2.11.6-r0
fixed in 2.11.8-r3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-31115MEDIUM6.38
xz-libs
5.4.3-r0
fixed in 5.4.3-r1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-20736MEDIUM6.38
code.gitea.io/gitea
1.21.1
fixed in 1.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44740MEDIUM6.38
github.com/go-git/go-billy/v5
v5.5.0
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-49568MEDIUM6.38
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.11.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-21614MEDIUM6.38
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.13.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-45022MEDIUM6.38
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.19.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt/v4
v4.5.0
fixed in 4.5.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt/v5
v5.0.0
fixed in 5.2.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-22869MEDIUM6.38
golang.org/x/crypto
v0.14.0
fixed in 0.35.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-47913MEDIUM6.38
golang.org/x/crypto
v0.14.0
fixed in 0.43.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-45338MEDIUM6.38
golang.org/x/net
v0.17.0
fixed in 0.33.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.17.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-22868MEDIUM6.38
golang.org/x/oauth2
v0.13.0
fixed in 0.27.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM6.38
stdlib
v1.21.4
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.8, 1.26.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.21.4
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.21.4
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-41506MEDIUM6.29
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-26519MEDIUM5.95
musl
1.2.4-r1
fixed in 1.2.4-r3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-26519MEDIUM5.95
musl-utils
1.2.4-r1
fixed in 1.2.4-r3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47907MEDIUM5.95
stdlib
v1.21.4
fixed in 1.23.12, 1.24.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-5981MEDIUM5.9
gnutls
3.8.0-r2
fixed in 3.8.3-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-6237MEDIUM5.9
libcrypto3
3.1.3-r0
fixed in 3.1.4-r4
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-5535MEDIUM5.9
libcrypto3
3.1.3-r0
fixed in 3.1.6-r0
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-50602MEDIUM5.9
libexpat
2.5.0-r1
fixed in 2.6.4-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-6237MEDIUM5.9
libssl3
3.1.3-r0
fixed in 3.1.4-r4
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-5535MEDIUM5.9
libssl3
3.1.3-r0
fixed in 3.1.6-r0
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-24786MEDIUM5.9
google.golang.org/protobuf
v1.31.0
fixed in 1.33.0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-24791MEDIUM5.9
stdlib
v1.21.4
fixed in 1.21.12, 1.22.5
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2024-34158MEDIUM5.9
stdlib
v1.21.4
fixed in 1.22.7, 1.23.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-4673MEDIUM5.78
stdlib
v1.21.4
fixed in 1.23.10, 1.24.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-4741MEDIUM5.6
libcrypto3
3.1.3-r0
fixed in 3.1.6-r0
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2024-4741MEDIUM5.6
libssl3
3.1.3-r0
fixed in 3.1.6-r0
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2025-11579MEDIUM5.52
github.com/nwaples/rardecode
v1.1.3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33809MEDIUM5.52
golang.org/x/image
v0.13.0
fixed in 0.38.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33813MEDIUM5.52
golang.org/x/image
v0.13.0
fixed in 0.42.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46599MEDIUM5.52
golang.org/x/image
v0.13.0
fixed in 0.41.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46601MEDIUM5.52
golang.org/x/image
v0.13.0
fixed in 0.43.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22872MEDIUM5.52
golang.org/x/net
v0.17.0
fixed in 0.38.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.17.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-24785MEDIUM5.52
stdlib
v1.21.4
fixed in 1.21.8, 1.22.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-47906MEDIUM5.52
stdlib
v1.21.4
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.21.4
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.21.4
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-0727MEDIUM5.5
libcrypto3
3.1.3-r0
fixed in 3.1.4-r5
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-0727MEDIUM5.5
libssl3
3.1.3-r0
fixed in 3.1.4-r5
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-34459MEDIUM5.5
libxml2
2.11.6-r0
fixed in 2.11.8-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.21.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-24784MEDIUM5.4
stdlib
v1.21.4
fixed in 1.21.8, 1.22.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
libcrypto3
3.1.3-r0
fixed in 3.1.4-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2024-4603MEDIUM5.3
libcrypto3
3.1.3-r0
fixed in 3.1.5-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
libssl3
3.1.3-r0
fixed in 3.1.4-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2024-4603MEDIUM5.3
libssl3
3.1.3-r0
fixed in 3.1.5-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-12133MEDIUM5.3
libtasn1
4.19.0-r1
fixed in 4.20.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-39326MEDIUM5.3
stdlib
v1.21.4
fixed in 1.20.12, 1.21.5
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2023-45289MEDIUM5.3
stdlib
v1.21.4
fixed in 1.21.8, 1.22.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-45290MEDIUM5.3
stdlib
v1.21.4
fixed in 1.21.8, 1.22.1
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-33812MEDIUM5.18
golang.org/x/image
v0.13.0
fixed in 0.39.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.17.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.21.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-24783MEDIUM5.02
stdlib
v1.21.4
fixed in 1.21.8, 1.22.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-34155MEDIUM5.02
stdlib
v1.21.4
fixed in 1.22.7, 1.23.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-45336MEDIUM5.02
stdlib
v1.21.4
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-2511MEDIUM4.81
libcrypto3
3.1.3-r0
fixed in 3.1.4-r6
54.0%
Actively Exploited
Directly Exposed
CVE-2024-2511MEDIUM4.81
libssl3
3.1.3-r0
fixed in 3.1.4-r6
54.0%
Actively Exploited
Directly Exposed
CVE-2023-52426MEDIUM4.67
libexpat
2.5.0-r1
fixed in 2.6.0-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2022-31022MEDIUM4.67
github.com/blevesearch/bleve/v2
v2.3.10
fixed in 2.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-6104MEDIUM4.67
github.com/hashicorp/go-retryablehttp
v0.7.4
fixed in 0.7.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-24789MEDIUM4.67
stdlib
v1.21.4
fixed in 1.21.11, 1.22.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.21.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68942MEDIUM4.59
code.gitea.io/gitea
1.21.1
fixed in 1.22.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45571MEDIUM4.59
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.19.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.17.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-22871MEDIUM4.59
stdlib
v1.21.4
fixed in 1.23.8, 1.24.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.21.4
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.21.4
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.21.4
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-28834MEDIUM4.5
gnutls
3.8.0-r2
fixed in 3.8.4-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-68939MEDIUM4.5
code.gitea.io/gitea
1.21.1
fixed in 1.23.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68938MEDIUM4.5
code.gitea.io/gitea
1.21.1
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68941MEDIUM4.5
code.gitea.io/gitea
1.21.1
fixed in 1.22.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68943MEDIUM4.5
code.gitea.io/gitea
1.21.1
fixed in 1.21.8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68944MEDIUM4.5
code.gitea.io/gitea
1.21.1
fixed in 1.22.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68945MEDIUM4.5
code.gitea.io/gitea
1.21.1
fixed in 1.21.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-69413MEDIUM4.5
code.gitea.io/gitea
1.21.1
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68940MEDIUM4.5
code.gitea.io/gitea
1.21.1
fixed in 1.22.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58058MEDIUM4.5
github.com/ulikunitz/xz
v0.5.11
fixed in 0.5.15
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.14.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.14.0
fixed in 0.45.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.14.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.17.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.17.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22866MEDIUM4.5
stdlib
v1.21.4
fixed in 1.22.12, 1.23.6, 1.24.0-rc.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22873MEDIUM4.5
stdlib
v1.21.4
fixed in 1.23.9, 1.24.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.21.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.21.4
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.21.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-28835MEDIUM4.25
gnutls
3.8.0-r2
fixed in 3.8.4-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34165MEDIUM4.25
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.17.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-1386MEDIUM4.17
github.com/ClickHouse/ch-go
v0.58.2
fixed in 0.65.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libcrypto3
3.1.3-r0
fixed in 3.1.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libssl3
3.1.3-r0
fixed in 3.1.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-32465LOW3.98
git
2.40.1-r0
fixed in 2.40.3-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2024-9681LOW3.9
curl
8.4.0-r0
fixed in 8.11.0-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-46218LOW3.9
libcurl
8.4.0-r0
fixed in 8.5.0-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-9681LOW3.9
libcurl
8.4.0-r0
fixed in 8.11.0-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-22870LOW3.74
golang.org/x/net
v0.17.0
fixed in 0.36.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
stdlib
v1.21.4
fixed in 1.23.7, 1.24.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-32002LOW3.73
git
2.40.1-r0
fixed in 2.40.3-r0
25.3%
High Exploitation Risk
Post-Exploit
CVE-2024-9143LOW3.7
libcrypto3
3.1.3-r0
fixed in 3.1.7-r1
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2024-9143LOW3.7
libssl3
3.1.3-r0
fixed in 3.1.7-r1
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-25934LOW3.65
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.16.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-32021LOW3.62
git
2.40.1-r0
fixed in 2.40.3-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2025-6965LOW3.61
sqlite-libs
3.41.2-r2
fixed in 3.41.2-r4
74.4%
Actively Exploited
Post-Exploit
CVE-2024-45341LOW3.57
stdlib
v1.21.4
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-11053LOW3.54
curl
8.4.0-r0
fixed in 8.11.1-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-11053LOW3.54
libcurl
8.4.0-r0
fixed in 8.11.1-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-45491LOW3.53
libexpat
2.5.0-r1
fixed in 2.6.3-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-45492LOW3.53
libexpat
2.5.0-r1
fixed in 2.6.3-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-56171LOW3.53
libxml2
2.11.6-r0
fixed in 2.11.8-r1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2023-49569LOW3.53
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.11.0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-6119LOW3.51
libcrypto3
3.1.3-r0
fixed in 3.1.7-r0
66.6%
Actively Exploited
Post-Exploit
CVE-2024-6119LOW3.51
libssl3
3.1.3-r0
fixed in 3.1.7-r0
66.6%
Actively Exploited
Post-Exploit
CVE-2024-8096LOW3.31
curl
8.4.0-r0
fixed in 8.10.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-8096LOW3.31
libcurl
8.4.0-r0
fixed in 8.10.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-33186LOW3.28
google.golang.org/grpc
v1.58.3
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2024-2379LOW3.24
curl
8.4.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-2379LOW3.24
libcurl
8.4.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
curl
8.4.0-r0
fixed in 8.5.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-0853LOW3.18
curl
8.4.0-r0
fixed in 8.6.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-2466LOW3.18
curl
8.4.0-r0
fixed in 8.7.1-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
curl
8.4.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
libcurl
8.4.0-r0
fixed in 8.5.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-0853LOW3.18
libcurl
8.4.0-r0
fixed in 8.6.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-2466LOW3.18
libcurl
8.4.0-r0
fixed in 8.7.1-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
libcurl
8.4.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2025-8556LOW3.15
github.com/cloudflare/circl
v1.3.3
fixed in 1.6.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-2398LOW3.1
curl
8.4.0-r0
fixed in 8.7.1-r0
36.1%
High Exploitation Risk
Post-Exploit
CVE-2024-2398LOW3.1
libcurl
8.4.0-r0
fixed in 8.7.1-r0
36.1%
High Exploitation Risk
Post-Exploit
CVE-2026-1229LOW3
github.com/cloudflare/circl
v1.3.3
fixed in 1.6.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-0798LOW2.98
code.gitea.io/gitea
1.21.1
fixed in 1.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45570LOW2.94
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.19.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-21613LOW2.92
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.13.0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-32004LOW2.81
git
2.40.1-r0
fixed in 2.40.3-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-42363LOW2.8
busybox
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
busybox
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
busybox
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
busybox
1.36.1-r2
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42363LOW2.8
busybox-binsh
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
busybox-binsh
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
busybox-binsh
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
busybox-binsh
1.36.1-r2
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42363LOW2.8
ssl_client
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
ssl_client
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
ssl_client
1.36.1-r2
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
ssl_client
1.36.1-r2
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-6197LOW2.7
curl
8.4.0-r0
fixed in 8.9.0-r0
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-52006LOW2.7
git
2.40.1-r0
fixed in 2.40.4-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-5363LOW2.7
libcrypto3
3.1.3-r0
fixed in 3.1.4-r0
3.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-6197LOW2.7
libcurl
8.4.0-r0
fixed in 8.9.0-r0
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-52425LOW2.7
libexpat
2.5.0-r1
fixed in 2.6.0-r0
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2024-7264LOW2.69
curl
8.4.0-r0
fixed in 8.9.1-r0
17.3%
High Exploitation Risk
Post-Exploit
CVE-2024-7264LOW2.69
libcurl
8.4.0-r0
fixed in 8.9.1-r0
17.3%
High Exploitation Risk
Post-Exploit
CVE-2024-51744LOW2.63
github.com/golang-jwt/jwt/v4
v4.5.0
fixed in 4.5.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-50349LOW2.4
git
2.40.1-r0
fixed in 2.40.4-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-0665LOW2.4
curl
8.4.0-r0
fixed in 8.12.0-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-0725LOW2.4
curl
8.4.0-r0
fixed in 8.12.0-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-0665LOW2.4
libcurl
8.4.0-r0
fixed in 8.12.0-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-0725LOW2.4
libcurl
8.4.0-r0
fixed in 8.12.0-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-33762LOW2.38
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.17.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-46218LOW2.34
curl
8.4.0-r0
fixed in 8.5.0-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-6874LOW2.19
curl
8.4.0-r0
fixed in 8.9.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2024-6874LOW2.19
libcurl
8.4.0-r0
fixed in 8.9.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.21.4
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-32020LOW1.68
git
2.40.1-r0
fixed in 2.40.3-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-0167NONE0
curl
8.4.0-r0
fixed in 8.12.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-0167NONE0
libcurl
8.4.0-r0
fixed in 8.12.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-20896NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.3
31.8%
High Exploitation Risk
Not Applicable
CVE-2026-22874NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-56750NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58443NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-20779NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-22555NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-24451NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-25038NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-26231NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27771NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.2
43.1%
High Exploitation Risk
Not Applicable
CVE-2026-27775NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28699NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.2
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28744NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54481NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-55987NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-56654NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-56755NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-57894NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58314NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58419NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58421NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58422NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58424NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58436NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58437NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-20706NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25714NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27761NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27783NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42931NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-50105NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-55982NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-56443NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-56657NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-57886NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-57897NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58418NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58425NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58428NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58429NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58432NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58435NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58441NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58442NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58444NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58507NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58510NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-59763NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-59765NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-59766NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
GHSA-3m6q-h5gj-7mrwNONE0
code.gitea.io/gitea
1.21.1
fixed in 1.25.0
Not Applicable
GHSA-rjvx-x5h2-6px5NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.26.0
Not Applicable
CVE-2026-23603NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-55984NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58434NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58445NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
CVE-2026-58511NONE0
code.gitea.io/gitea
1.21.1
fixed in 1.27.0
Not Applicable
GHSA-9763-4f94-gfchNONE0
github.com/cloudflare/circl
v1.3.3
fixed in 1.3.7
Not Applicable
GHSA-vrw8-fxc6-2r93NONE0
github.com/go-chi/chi/v5
v5.0.10
fixed in 5.2.2
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.9.0
fixed in 5.19.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.14.0
No fix yet
Not Applicable
CVE-2026-46602NONE0
golang.org/x/image
v0.13.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46604NONE0
golang.org/x/image
v0.13.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2024-24792NONE0
golang.org/x/image
v0.13.0
fixed in 0.18.0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-42500NONE0
golang.org/x/image
v0.13.0
fixed in 0.41.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.17.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.13.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.13.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.58.3
fixed in 1.82.1
Not Applicable
CVE-2025-0913NONE0
stdlib
v1.21.4
fixed in 1.23.10, 1.24.4
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.