Vulnerability Reportgitea/gitea:1.21.8-rootless

gitea/gitea:1.21.8-rootless
digestsha256:e7ee0467985fd81cf7f99bad25cbf70eb28ee378cf046cc3a41eb23f2f2d43e8

Executive Summary

Last scanned:

Threat Score
100/100DANGEROUS
Reputation
RELIABLE

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit a stored XSS vulnerability (CVE-2024-6886) to hijack an administrator session and take over the Gitea instance, or leverage the HTTP/2 CONTINUATION-frame flaw (CVE-2023-45288) to remotely crash the service via denial of service. Disabling HTTP/2 on the Gitea listener would fully eliminate the DoS vector.

Vulnerabilities

Vulnerability Log

275 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2024-6886CRITICAL10
code.gitea.io/gitea
1.21.8
fixed in 1.22.1
33.0%
High Exploitation Risk
Directly ExposedContext importance: HIGH
CVE-2023-45288CRITICAL9.75
golang.org/x/net
v0.20.0
fixed in 0.23.0
92.0%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2023-45288CRITICAL9.75
stdlib
v1.21.8
fixed in 1.21.9, 1.22.2
92.0%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2024-24790HIGH7.84
stdlib
v1.21.8
fixed in 1.21.11, 1.22.4
2.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-6119HIGH7.8
libcrypto3
3.1.4-r5
fixed in 3.1.7-r0
66.6%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2024-6119HIGH7.8
libssl3
3.1.4-r5
fixed in 3.1.7-r0
66.6%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2025-27113HIGH7.5
libxml2
2.11.7-r0
fixed in 2.11.8-r2
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-32952HIGH7.5
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-61726HIGH7.5
stdlib
v1.21.8
fixed in 1.24.12, 1.25.6
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-39828HIGH7.48
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39832HIGH7.39
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM6.97
golang.org/x/net
v0.20.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-44973MEDIUM6.88
github.com/go-git/go-billy/v5
v5.5.0
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-3445MEDIUM6.88
github.com/mholt/archiver/v3
v3.5.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39831MEDIUM6.88
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-25681MEDIUM6.88
golang.org/x/net
v0.20.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27136MEDIUM6.88
golang.org/x/net
v0.20.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-0406MEDIUM6.63
github.com/mholt/archiver/v3
v3.5.1
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM6.63
stdlib
v1.21.8
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-45337MEDIUM6.56
golang.org/x/crypto
v0.18.0
fixed in 0.31.0
3.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-24928MEDIUM6.54
libxml2
2.11.7-r0
fixed in 2.11.8-r1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45570MEDIUM6.53
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.19.1
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-32414MEDIUM6.38
libxml2
2.11.7-r0
fixed in 2.11.8-r3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-32415MEDIUM6.38
libxml2
2.11.7-r0
fixed in 2.11.8-r3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-31115MEDIUM6.38
xz-libs
5.4.3-r0
fixed in 5.4.3-r1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-20736MEDIUM6.38
code.gitea.io/gitea
1.21.8
fixed in 1.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44740MEDIUM6.38
github.com/go-git/go-billy/v5
v5.5.0
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-21614MEDIUM6.38
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.13.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-45022MEDIUM6.38
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.19.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt/v4
v4.5.0
fixed in 4.5.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt/v5
v5.0.0
fixed in 5.2.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-22869MEDIUM6.38
golang.org/x/crypto
v0.18.0
fixed in 0.35.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-47913MEDIUM6.38
golang.org/x/crypto
v0.18.0
fixed in 0.43.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-45338MEDIUM6.38
golang.org/x/net
v0.20.0
fixed in 0.33.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.20.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-22868MEDIUM6.38
golang.org/x/oauth2
v0.13.0
fixed in 0.27.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM6.38
stdlib
v1.21.8
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.8, 1.26.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.21.8
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.21.8
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-41506MEDIUM6.29
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-26519MEDIUM5.95
musl
1.2.4-r2
fixed in 1.2.4-r3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47907MEDIUM5.95
stdlib
v1.21.8
fixed in 1.23.12, 1.24.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-5535MEDIUM5.9
libcrypto3
3.1.4-r5
fixed in 3.1.6-r0
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-50602MEDIUM5.9
libexpat
2.6.0-r0
fixed in 2.6.4-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-5535MEDIUM5.9
libssl3
3.1.4-r5
fixed in 3.1.6-r0
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-24791MEDIUM5.9
stdlib
v1.21.8
fixed in 1.21.12, 1.22.5
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2024-34158MEDIUM5.9
stdlib
v1.21.8
fixed in 1.22.7, 1.23.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-4673MEDIUM5.78
stdlib
v1.21.8
fixed in 1.23.10, 1.24.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-4741MEDIUM5.6
libcrypto3
3.1.4-r5
fixed in 3.1.6-r0
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2024-4741MEDIUM5.6
libssl3
3.1.4-r5
fixed in 3.1.6-r0
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2025-11579MEDIUM5.52
github.com/nwaples/rardecode
v1.1.3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33809MEDIUM5.52
golang.org/x/image
v0.13.0
fixed in 0.38.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33813MEDIUM5.52
golang.org/x/image
v0.13.0
fixed in 0.42.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46599MEDIUM5.52
golang.org/x/image
v0.13.0
fixed in 0.41.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46601MEDIUM5.52
golang.org/x/image
v0.13.0
fixed in 0.43.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22872MEDIUM5.52
golang.org/x/net
v0.20.0
fixed in 0.38.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.20.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47906MEDIUM5.52
stdlib
v1.21.8
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.21.8
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.21.8
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-34459MEDIUM5.5
libxml2
2.11.7-r0
fixed in 2.11.8-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.21.8
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-4603MEDIUM5.3
libcrypto3
3.1.4-r5
fixed in 3.1.5-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-4603MEDIUM5.3
libssl3
3.1.4-r5
fixed in 3.1.5-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-12133MEDIUM5.3
libtasn1
4.19.0-r1
fixed in 4.20.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-33812MEDIUM5.18
golang.org/x/image
v0.13.0
fixed in 0.39.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.20.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.21.8
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68121MEDIUM5.1
stdlib
v1.21.8
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-34155MEDIUM5.02
stdlib
v1.21.8
fixed in 1.22.7, 1.23.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-45336MEDIUM5.02
stdlib
v1.21.8
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-2511MEDIUM4.81
libcrypto3
3.1.4-r5
fixed in 3.1.4-r6
54.0%
Actively Exploited
Directly Exposed
CVE-2024-2511MEDIUM4.81
libssl3
3.1.4-r5
fixed in 3.1.4-r6
54.0%
Actively Exploited
Directly Exposed
CVE-2022-31022MEDIUM4.67
github.com/blevesearch/bleve/v2
v2.3.10
fixed in 2.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-6104MEDIUM4.67
github.com/hashicorp/go-retryablehttp
v0.7.4
fixed in 0.7.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-24789MEDIUM4.67
stdlib
v1.21.8
fixed in 1.21.11, 1.22.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.21.8
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68942MEDIUM4.59
code.gitea.io/gitea
1.21.8
fixed in 1.22.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45571MEDIUM4.59
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.19.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.20.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-22871MEDIUM4.59
stdlib
v1.21.8
fixed in 1.23.8, 1.24.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.21.8
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.21.8
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.21.8
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-28834MEDIUM4.5
gnutls
3.8.3-r0
fixed in 3.8.4-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-68939MEDIUM4.5
code.gitea.io/gitea
1.21.8
fixed in 1.23.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68938MEDIUM4.5
code.gitea.io/gitea
1.21.8
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68941MEDIUM4.5
code.gitea.io/gitea
1.21.8
fixed in 1.22.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68944MEDIUM4.5
code.gitea.io/gitea
1.21.8
fixed in 1.22.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-69413MEDIUM4.5
code.gitea.io/gitea
1.21.8
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68940MEDIUM4.5
code.gitea.io/gitea
1.21.8
fixed in 1.22.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58058MEDIUM4.5
github.com/ulikunitz/xz
v0.5.11
fixed in 0.5.15
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.18.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.18.0
fixed in 0.45.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.18.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.20.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.20.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22866MEDIUM4.5
stdlib
v1.21.8
fixed in 1.22.12, 1.23.6, 1.24.0-rc.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22873MEDIUM4.5
stdlib
v1.21.8
fixed in 1.23.9, 1.24.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.21.8
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.21.8
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.21.8
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-28835MEDIUM4.25
gnutls
3.8.3-r0
fixed in 3.8.4-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34165MEDIUM4.25
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.17.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-1386MEDIUM4.17
github.com/ClickHouse/ch-go
v0.58.2
fixed in 0.65.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libcrypto3
3.1.4-r5
fixed in 3.1.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libssl3
3.1.4-r5
fixed in 3.1.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-32465LOW3.98
git
2.40.1-r0
fixed in 2.40.3-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2024-9681LOW3.9
libcurl
8.5.0-r0
fixed in 8.11.0-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-22870LOW3.74
golang.org/x/net
v0.20.0
fixed in 0.36.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
stdlib
v1.21.8
fixed in 1.23.7, 1.24.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-32002LOW3.73
git
2.40.1-r0
fixed in 2.40.3-r0
25.3%
High Exploitation Risk
Post-Exploit
CVE-2024-9143LOW3.7
libcrypto3
3.1.4-r5
fixed in 3.1.7-r1
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2024-9143LOW3.7
libssl3
3.1.4-r5
fixed in 3.1.7-r1
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-25934LOW3.65
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.16.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-32021LOW3.62
git
2.40.1-r0
fixed in 2.40.3-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2025-6965LOW3.61
sqlite-libs
3.41.2-r3
fixed in 3.41.2-r4
74.4%
Actively Exploited
Post-Exploit
CVE-2025-26519LOW3.57
musl-utils
1.2.4-r2
fixed in 1.2.4-r3
0.3%
Theoretical Threat
Post-Exploit
CVE-2024-45341LOW3.57
stdlib
v1.21.8
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-11053LOW3.54
curl
8.5.0-r0
fixed in 8.11.1-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-11053LOW3.54
libcurl
8.5.0-r0
fixed in 8.11.1-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-45491LOW3.53
libexpat
2.6.0-r0
fixed in 2.6.3-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-45492LOW3.53
libexpat
2.6.0-r0
fixed in 2.6.3-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-56171LOW3.53
libxml2
2.11.7-r0
fixed in 2.11.8-r1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-8096LOW3.31
curl
8.5.0-r0
fixed in 8.10.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-8096LOW3.31
libcurl
8.5.0-r0
fixed in 8.10.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-33186LOW3.28
google.golang.org/grpc
v1.58.3
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2024-2379LOW3.24
curl
8.5.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-2379LOW3.24
libcurl
8.5.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-0853LOW3.18
curl
8.5.0-r0
fixed in 8.6.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-2466LOW3.18
curl
8.5.0-r0
fixed in 8.7.1-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
curl
8.5.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-0853LOW3.18
libcurl
8.5.0-r0
fixed in 8.6.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-2466LOW3.18
libcurl
8.5.0-r0
fixed in 8.7.1-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
libcurl
8.5.0-r0
fixed in 8.7.1-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2025-8556LOW3.15
github.com/cloudflare/circl
v1.3.7
fixed in 1.6.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-2398LOW3.1
curl
8.5.0-r0
fixed in 8.7.1-r0
36.1%
High Exploitation Risk
Post-Exploit
CVE-2024-2398LOW3.1
libcurl
8.5.0-r0
fixed in 8.7.1-r0
36.1%
High Exploitation Risk
Post-Exploit
CVE-2026-1229LOW3
github.com/cloudflare/circl
v1.3.7
fixed in 1.6.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-0798LOW2.98
code.gitea.io/gitea
1.21.8
fixed in 1.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-21613LOW2.92
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.13.0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-32004LOW2.81
git
2.40.1-r0
fixed in 2.40.3-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-42363LOW2.8
busybox
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
busybox
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
busybox
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
busybox
1.36.1-r5
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42363LOW2.8
busybox-binsh
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
busybox-binsh
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
busybox-binsh
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
busybox-binsh
1.36.1-r5
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42363LOW2.8
ssl_client
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
ssl_client
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
ssl_client
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
ssl_client
1.36.1-r5
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-6197LOW2.7
curl
8.5.0-r0
fixed in 8.9.0-r0
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-52006LOW2.7
git
2.40.1-r0
fixed in 2.40.4-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-6197LOW2.7
libcurl
8.5.0-r0
fixed in 8.9.0-r0
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-28757LOW2.7
libexpat
2.6.0-r0
fixed in 2.6.2-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-45490LOW2.7
libexpat
2.6.0-r0
fixed in 2.6.3-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-8176LOW2.7
libexpat
2.6.0-r0
fixed in 2.7.0-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2024-34156LOW2.7
stdlib
v1.21.8
fixed in 1.22.7, 1.23.1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-7264LOW2.69
curl
8.5.0-r0
fixed in 8.9.1-r0
17.3%
High Exploitation Risk
Post-Exploit
CVE-2024-7264LOW2.69
libcurl
8.5.0-r0
fixed in 8.9.1-r0
17.3%
High Exploitation Risk
Post-Exploit
CVE-2024-51744LOW2.63
github.com/golang-jwt/jwt/v4
v4.5.0
fixed in 4.5.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-50349LOW2.4
git
2.40.1-r0
fixed in 2.40.4-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-0665LOW2.4
curl
8.5.0-r0
fixed in 8.12.0-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-0725LOW2.4
curl
8.5.0-r0
fixed in 8.12.0-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-0665LOW2.4
libcurl
8.5.0-r0
fixed in 8.12.0-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-0725LOW2.4
libcurl
8.5.0-r0
fixed in 8.12.0-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-33762LOW2.38
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.17.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-9681LOW2.34
curl
8.5.0-r0
fixed in 8.11.0-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-6874LOW2.19
curl
8.5.0-r0
fixed in 8.9.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2024-6874LOW2.19
libcurl
8.5.0-r0
fixed in 8.9.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.21.8
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-32020LOW1.68
git
2.40.1-r0
fixed in 2.40.3-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-0167NONE0
curl
8.5.0-r0
fixed in 8.12.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-0167NONE0
libcurl
8.5.0-r0
fixed in 8.12.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-20896NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.3
31.8%
High Exploitation Risk
Not Applicable
CVE-2026-22874NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-56750NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58443NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-20779NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-22555NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-24451NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-25038NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-26231NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27771NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.2
43.1%
High Exploitation Risk
Not Applicable
CVE-2026-27775NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28699NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.2
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28744NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54481NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-55987NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-56654NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-56755NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-57894NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58314NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58419NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58421NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58422NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58424NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58436NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58437NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-20706NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25714NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27761NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27783NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42931NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-50105NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-55982NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-56443NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-56657NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-57886NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-57897NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58418NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58425NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58428NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58429NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58432NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58435NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58441NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58442NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58444NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58507NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58510NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-59763NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-59765NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-59766NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
GHSA-3m6q-h5gj-7mrwNONE0
code.gitea.io/gitea
1.21.8
fixed in 1.25.0
Not Applicable
GHSA-rjvx-x5h2-6px5NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.26.0
Not Applicable
CVE-2026-23603NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-55984NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58434NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58445NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
CVE-2026-58511NONE0
code.gitea.io/gitea
1.21.8
fixed in 1.27.0
Not Applicable
GHSA-vrw8-fxc6-2r93NONE0
github.com/go-chi/chi/v5
v5.0.10
fixed in 5.2.2
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.11.0
fixed in 5.19.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.18.0
No fix yet
Not Applicable
CVE-2026-46602NONE0
golang.org/x/image
v0.13.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46604NONE0
golang.org/x/image
v0.13.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2024-24792NONE0
golang.org/x/image
v0.13.0
fixed in 0.18.0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-42500NONE0
golang.org/x/image
v0.13.0
fixed in 0.41.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.20.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.16.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.14.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.58.3
fixed in 1.82.1
Not Applicable
CVE-2025-0913NONE0
stdlib
v1.21.8
fixed in 1.23.10, 1.24.4
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.