Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The primary risk is CVE-2026-45570, a command injection in go-git's SSH transport, which could execute shell commands on the SSH server Gitea connects to when mirroring or migrating repositories. However, exploitation requires a non-default configuration: the SSH transport must be used with a repository path containing a single quote. Upgrading go-git to v5.19.1 or later fully mitigates this issue. Other exposed and post-exploit findings are low severity (max 2.92 post-exploit) and do not pose a significant practical risk.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-45570 | MEDIUM6.53 | github.com/go-git/go-git/v5 v5.19.0 fixed in 5.19.1 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-56132 | MEDIUM5.87 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56404 | MEDIUM5.87 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56407 | MEDIUM5.87 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33813 | MEDIUM5.52 | golang.org/x/image v0.40.0 fixed in 0.42.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-46599 | MEDIUM5.52 | golang.org/x/image v0.40.0 fixed in 0.41.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-46601 | MEDIUM5.52 | golang.org/x/image v0.40.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45571 | MEDIUM4.59 | github.com/go-git/go-git/v5 v5.19.0 fixed in 5.19.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56131 | LOW3.82 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45447 | LOW2.92 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-33630 | LOW2.7 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | — | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-2100 | LOW2.7 | p11-kit 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-32952 | LOW2.7 | github.com/Azure/go-ntlmssp v0.1.0 fixed in 0.1.1 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-7009 | LOW2.7 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-7009 | LOW2.7 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-5773 | LOW2.29 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW2.29 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5773 | LOW2.29 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW2.29 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW2.26 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW2.26 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42764 | LOW2.12 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42764 | LOW2.12 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5545 | LOW1.99 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW1.99 | curl 8.19.0-r0 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW1.99 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW1.99 | libcurl 8.19.0-r0 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW1.81 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW1.81 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW1.81 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-56408 | NONE0 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat 2.8.1-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56750 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58443 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-54481 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55987 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56654 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56755 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57894 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58314 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58436 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58437 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-42931 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-50105 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55982 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56443 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56657 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57886 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57897 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58425 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58428 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58429 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58432 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58435 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58441 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58442 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58444 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58507 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58510 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59763 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59765 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59766 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-23603 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55984 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58434 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58445 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58511 | NONE0 | code.gitea.io/gitea v1.26.4+dirty fixed in 1.27.0 | — | Not Applicable |
| GHSA-w5pp-99ch-qj29 | NONE0 | github.com/go-git/go-git/v5 v5.19.0 fixed in 5.19.1 | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.52.0 No fix yet | — | Not Applicable |
| CVE-2026-46602 | NONE0 | golang.org/x/image v0.40.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-46604 | NONE0 | golang.org/x/image v0.40.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42500 | NONE0 | golang.org/x/image v0.40.0 fixed in 0.41.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.55.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.37.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.79.3 fixed in 1.82.1 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.