Vulnerability Reportgitlab/gitlab-runner:alpine-v18.9.0

gitlab/gitlab-runner:alpine-v18.9.0
digestsha256:c008d2fd497ba413079a9302ce6068a1f5c66fb20fca5e444dec4cd5a0376a98

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The dominant practical danger is availability: CVE-2026-34183 lets a remote peer exhaust the QUIC stack's heap with PATH_CHALLENGE floods, and CVE-2026-63072 can corrupt the heap on a crafted CMS message, so an attacker could crash or destabilize any runner workload that terminates TLS or processes attacker-supplied cryptographic input. Note that CVE-2026-63076 only applies if CMP password-based protection is enabled, and CVE-2026-54874 requires an active DTLS endpoint — the runner uses neither, and disabling CMP entirely would fully eliminate CVE-2026-63076. All 104 post-exploit findings are low severity (max 3.82), so the residual risk comes almost entirely from the 217 exposed-surface issues in the pinned OpenSSL and Go dependency set. Rebuilding on a newer OpenSSL 3.5.8 base, as the advisory recommends, clears the highest-severity crypto denial-of-service issues while keeping the digest-pinned trust benefits.

Vulnerabilities

Vulnerability Log

321 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-34183HIGH7.5
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-63072HIGH7.5
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-63076HIGH7.5
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-54874HIGH7.5
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183HIGH7.5
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-63072HIGH7.5
libssl3
3.5.5-r0
fixed in 3.5.8-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-63076HIGH7.5
libssl3
3.5.5-r0
fixed in 3.5.8-r0
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-54874HIGH7.5
libssl3
3.5.5-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-39828HIGH7.48
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56865HIGH7.48
golang.org/x/mod
v0.31.0
fixed in 0.40.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34182HIGH7.4
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-34182HIGH7.4
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-39832HIGH7.39
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM6.97
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM6.97
stdlib
v1.24.11
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM6.97
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM6.97
stdlib
v1.25.7
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libssl3
3.5.5-r0
fixed in 3.5.6-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33997MEDIUM6.88
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39831MEDIUM6.88
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25681MEDIUM6.88
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27136MEDIUM6.88
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56858MEDIUM6.88
stdlib
v1.24.11
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44973MEDIUM6.88
github.com/go-git/go-billy/v5
v5.7.0
fixed in 5.9.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56864MEDIUM6.88
golang.org/x/mod
v0.31.0
fixed in 0.40.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-25681MEDIUM6.88
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27136MEDIUM6.88
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56858MEDIUM6.88
stdlib
v1.25.7
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68121MEDIUM6.8
stdlib
v1.24.11
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-15558MEDIUM6.8
github.com/docker/cli
v28.5.2+incompatible
fixed in 29.2.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-76957MEDIUM6.63
libexpat
2.7.4-r0
fixed in 2.8.4-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40200MEDIUM6.63
musl
1.2.5-r21
fixed in 1.2.5-r23
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40200MEDIUM6.63
musl-utils
1.2.5-r21
fixed in 1.2.5-r23
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22184MEDIUM6.63
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM6.63
stdlib
v1.24.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM6.63
stdlib
v1.25.7
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33630MEDIUM6.38
c-ares
1.34.6-r0
fixed in 1.34.8-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-14456MEDIUM6.38
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-28390MEDIUM6.38
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-63074MEDIUM6.38
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-63075MEDIUM6.38
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-45186MEDIUM6.38
libexpat
2.7.4-r0
fixed in 2.8.1-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-66046MEDIUM6.38
libexpat
2.7.4-r0
fixed in 2.8.4-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-76641MEDIUM6.38
libexpat
2.7.4-r0
fixed in 2.8.4-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-76956MEDIUM6.38
libexpat
2.7.4-r0
fixed in 2.8.4-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-93990MEDIUM6.38
libexpat
2.7.4-r0
fixed in 2.8.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-14456MEDIUM6.38
libssl3
3.5.5-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-28390MEDIUM6.38
libssl3
3.5.5-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-63074MEDIUM6.38
libssl3
3.5.5-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-63075MEDIUM6.38
libssl3
3.5.5-r0
fixed in 3.5.8-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
nghttp2-libs
1.68.0-r0
fixed in 1.68.1
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-41567MEDIUM6.38
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.47.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-46600MEDIUM6.38
golang.org/x/net
v0.47.0
fixed in 0.56.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56852MEDIUM6.38
golang.org/x/text
v0.32.0
fixed in 0.39.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-84445MEDIUM6.38
google.golang.org/grpc
v1.67.0
fixed in 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33818MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56853MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56859MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56860MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56862MEDIUM6.38
stdlib
v1.24.11
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-32285MEDIUM6.38
github.com/buger/jsonparser
v1.1.1
fixed in 1.1.2
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-44740MEDIUM6.38
github.com/go-git/go-billy/v5
v5.7.0
fixed in 5.9.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-45022MEDIUM6.38
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.19.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34986MEDIUM6.38
github.com/go-jose/go-jose/v4
v4.1.3
fixed in 4.1.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-29181MEDIUM6.38
go.opentelemetry.io/otel
v1.39.0
fixed in 1.41.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.48.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-46600MEDIUM6.38
golang.org/x/net
v0.48.0
fixed in 0.56.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-84445MEDIUM6.38
google.golang.org/grpc
v1.78.0
fixed in 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.8, 1.26.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33818MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56853MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56859MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56860MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56862MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-41506MEDIUM6.29
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42306MEDIUM6.12
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-71556MEDIUM6.03
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.19.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-14457MEDIUM6
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-14457MEDIUM6
libssl3
3.5.5-r0
fixed in 3.5.8-r0
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-24051MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.39.0
fixed in 1.40.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.39.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.9
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-63073MEDIUM5.9
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libssl3
3.5.5-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-63073MEDIUM5.9
libssl3
3.5.5-r0
fixed in 3.5.8-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-56132MEDIUM5.87
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56404MEDIUM5.87
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56854MEDIUM5.78
golang.org/x/crypto
v0.46.0
fixed in 0.55.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
libssl3
3.5.5-r0
fixed in 3.5.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-35469MEDIUM5.52
github.com/moby/spdystream
v0.5.0
fixed in 0.5.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-26625MEDIUM5.5
git-lfs
3.7.0-r5
fixed in 3.7.1-r0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32282MEDIUM5.44
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-71557MEDIUM5.35
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.19.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM5.3
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-42766MEDIUM5.3
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-50219MEDIUM5.02
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-34180MEDIUM5
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
libexpat
2.7.4-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
libexpat
2.7.4-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
libexpat
2.7.4-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r21
fixed in 1.2.5-r22
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl-utils
1.2.5-r21
fixed in 1.2.5-r22
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.24.11
fixed in 1.25.9, 1.26.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.24.11
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45571MEDIUM4.59
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.19.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.25.7
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56855MEDIUM4.5
golang.org/x/crypto
v0.46.0
fixed in 0.56.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-78662MEDIUM4.5
golang.org/x/crypto
v0.46.0
fixed in 0.56.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.24.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.24.11
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.25.7
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.25.7
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34165MEDIUM4.25
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.17.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-12064LOW3.82
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
curl
8.17.0-r1
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
curl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
curl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
curl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
curl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW3.82
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW3.82
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-56131LOW3.82
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-9547LOW3.77
curl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
curl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-25934LOW3.65
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.16.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-1965LOW3.47
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
curl
8.17.0-r1
fixed in 8.18.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
libcurl
8.17.0-r1
fixed in 8.18.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
curl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-19931LOW3.31
curl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
curl
8.17.0-r1
fixed in 8.19.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
curl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl
8.17.0-r1
fixed in 8.18.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-19931LOW3.31
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl
8.17.0-r1
fixed in 8.18.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-41568LOW3.31
github.com/docker/docker
v28.5.2+incompatible
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33186LOW3.28
google.golang.org/grpc
v1.67.0
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-33186LOW3.28
google.golang.org/grpc
v1.78.0
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-3805LOW3.21
curl
8.17.0-r1
fixed in 8.19.0-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
libcurl
8.17.0-r1
fixed in 8.19.0-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW3.15
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-75803LOW3.15
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41080LOW3.15
libexpat
2.7.4-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-75803LOW3.15
libssl3
3.5.5-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31789LOW3
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.5.5-r0
fixed in 3.5.6-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-1229LOW3
github.com/cloudflare/circl
v1.6.2
fixed in 1.6.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45570LOW2.94
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.19.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.92
curl
8.17.0-r1
fixed in 8.22.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
4.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-8925LOW2.92
libcurl
8.17.0-r1
fixed in 8.22.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.5.5-r0
fixed in 3.5.7-r0
4.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-3783LOW2.91
curl
8.17.0-r1
fixed in 8.19.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3783LOW2.91
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-81870LOW2.8
go.opentelemetry.io/otel/sdk
v1.39.0
fixed in 1.45.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45445LOW2.78
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.7
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libcrypto3
3.5.5-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-28388LOW2.7
libssl3
3.5.5-r0
fixed in 3.5.6-r0
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libssl3
3.5.5-r0
fixed in 3.5.6-r0
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libssl3
3.5.5-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2025-61726LOW2.7
stdlib
v1.24.11
fixed in 1.24.12, 1.25.6
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.1.0
fixed in 0.1.1
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8286LOW2.48
curl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8458LOW2.48
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8286LOW2.48
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8458LOW2.48
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
curl
8.17.0-r1
fixed in 8.18.0-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-82208LOW2.45
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl
8.17.0-r1
fixed in 8.18.0-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-82208LOW2.45
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
curl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33762LOW2.38
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.17.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-11352LOW2.29
curl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW2.29
curl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11352LOW2.29
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.24.11
fixed in 1.25.8, 1.26.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27139LOW2.12
stdlib
v1.25.7
fixed in 1.25.8, 1.26.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-13608LOW1.89
curl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-18924LOW1.89
curl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-80230LOW1.89
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-80231LOW1.89
curl
8.17.0-r1
fixed in 8.22.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-80255LOW1.89
curl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-13608LOW1.89
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-18924LOW1.89
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-80230LOW1.89
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-80231LOW1.89
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-80255LOW1.89
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-82209LOW1.58
curl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-82209LOW1.58
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-80229NONE0
curl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-80256NONE0
curl
8.17.0-r1
fixed in 8.22.0-r0
—
Not Applicable
CVE-2026-80229NONE0
libcurl
8.17.0-r1
fixed in 8.22.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-80256NONE0
libcurl
8.17.0-r1
fixed in 8.22.0-r0
—
Not Applicable
CVE-2026-56408NONE0
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat
2.7.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.46.0
No fix yet
—
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.39.0
fixed in 0.44.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-84304NONE0
google.golang.org/grpc
v1.67.0
fixed in 1.83.1
0.6%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.67.0
fixed in 1.82.1
—
Not Applicable
CVE-2026-84303NONE0
google.golang.org/grpc
v1.67.0
fixed in 1.83.1
0.3%
Theoretical Threat
Not Applicable
GHSA-xmrv-pmrh-hhx2NONE0
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
v1.7.4
fixed in 1.7.8
—
Not Applicable
GHSA-xmrv-pmrh-hhx2NONE0
github.com/aws/aws-sdk-go-v2/service/s3
v1.95.0
fixed in 1.97.3
—
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.16.4
fixed in 5.19.1
—
Not Applicable
GHSA-pmwq-pjrm-6p5rNONE0
github.com/in-toto/in-toto-golang
v0.9.0
fixed in 0.11.0
—
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.40.0
fixed in 0.44.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-84304NONE0
google.golang.org/grpc
v1.78.0
fixed in 1.83.1
0.6%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.78.0
fixed in 1.82.1
—
Not Applicable
CVE-2026-84303NONE0
google.golang.org/grpc
v1.78.0
fixed in 1.83.1
0.3%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.