Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The dominant practical danger is availability: CVE-2026-34183 lets a remote peer exhaust the QUIC stack's heap with PATH_CHALLENGE floods, and CVE-2026-63072 can corrupt the heap on a crafted CMS message, so an attacker could crash or destabilize any runner workload that terminates TLS or processes attacker-supplied cryptographic input. Note that CVE-2026-63076 only applies if CMP password-based protection is enabled, and CVE-2026-54874 requires an active DTLS endpoint — the runner uses neither, and disabling CMP entirely would fully eliminate CVE-2026-63076. All 104 post-exploit findings are low severity (max 3.82), so the residual risk comes almost entirely from the 217 exposed-surface issues in the pinned OpenSSL and Go dependency set. Rebuilding on a newer OpenSSL 3.5.8 base, as the advisory recommends, clears the highest-severity crypto denial-of-service issues while keeping the digest-pinned trust benefits.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-34183 | HIGH7.5 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63072 | HIGH7.5 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63076 | HIGH7.5 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54874 | HIGH7.5 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34183 | HIGH7.5 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63072 | HIGH7.5 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63076 | HIGH7.5 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54874 | HIGH7.5 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-39828 | HIGH7.48 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-56865 | HIGH7.48 | golang.org/x/mod v0.31.0 fixed in 0.40.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | HIGH7.4 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34182 | HIGH7.4 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-39832 | HIGH7.39 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM6.97 | golang.org/x/net v0.47.0 fixed in 0.55.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM6.97 | stdlib v1.24.11 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM6.97 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM6.97 | stdlib v1.25.7 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libcrypto3 3.5.5-r0 fixed in 3.5.6-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl3 3.5.5-r0 fixed in 3.5.6-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-33997 | MEDIUM6.88 | github.com/docker/docker v28.5.2+incompatible fixed in 29.3.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39831 | MEDIUM6.88 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25681 | MEDIUM6.88 | golang.org/x/net v0.47.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27136 | MEDIUM6.88 | golang.org/x/net v0.47.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56858 | MEDIUM6.88 | stdlib v1.24.11 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-44973 | MEDIUM6.88 | github.com/go-git/go-billy/v5 v5.7.0 fixed in 5.9.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-56864 | MEDIUM6.88 | golang.org/x/mod v0.31.0 fixed in 0.40.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-25681 | MEDIUM6.88 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27136 | MEDIUM6.88 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56858 | MEDIUM6.88 | stdlib v1.25.7 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68121 | MEDIUM6.8 | stdlib v1.24.11 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.9% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-15558 | MEDIUM6.8 | github.com/docker/cli v28.5.2+incompatible fixed in 29.2.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-76957 | MEDIUM6.63 | libexpat 2.7.4-r0 fixed in 2.8.4-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl 1.2.5-r21 fixed in 1.2.5-r23 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl-utils 1.2.5-r21 fixed in 1.2.5-r23 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22184 | MEDIUM6.63 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39822 | MEDIUM6.63 | stdlib v1.24.11 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39822 | MEDIUM6.63 | stdlib v1.25.7 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-33630 | MEDIUM6.38 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-14456 | MEDIUM6.38 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-28390 | MEDIUM6.38 | libcrypto3 3.5.5-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-63074 | MEDIUM6.38 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | MEDIUM6.38 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-45186 | MEDIUM6.38 | libexpat 2.7.4-r0 fixed in 2.8.1-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-66046 | MEDIUM6.38 | libexpat 2.7.4-r0 fixed in 2.8.4-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-76641 | MEDIUM6.38 | libexpat 2.7.4-r0 fixed in 2.8.4-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-76956 | MEDIUM6.38 | libexpat 2.7.4-r0 fixed in 2.8.4-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-93990 | MEDIUM6.38 | libexpat 2.7.4-r0 fixed in 2.8.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-14456 | MEDIUM6.38 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-28390 | MEDIUM6.38 | libssl3 3.5.5-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-63074 | MEDIUM6.38 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | MEDIUM6.38 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | nghttp2-libs 1.68.0-r0 fixed in 1.68.1 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-41567 | MEDIUM6.38 | github.com/docker/docker v28.5.2+incompatible No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39829 | MEDIUM6.38 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39830 | MEDIUM6.38 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39835 | MEDIUM6.38 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-46597 | MEDIUM6.38 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | golang.org/x/net v0.47.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-46600 | MEDIUM6.38 | golang.org/x/net v0.47.0 fixed in 0.56.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56852 | MEDIUM6.38 | golang.org/x/text v0.32.0 fixed in 0.39.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-84445 | MEDIUM6.38 | google.golang.org/grpc v1.67.0 fixed in 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-25679 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.8, 1.26.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27145 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.9, 1.26.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-32281 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.9, 1.26.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-33811 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.10, 1.26.3 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-33818 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39820 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.10, 1.26.3 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-39836 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42499 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42504 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56853 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56859 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56860 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-56862 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61728 | MEDIUM6.38 | stdlib v1.24.11 fixed in 1.24.12, 1.25.6 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-32285 | MEDIUM6.38 | github.com/buger/jsonparser v1.1.1 fixed in 1.1.2 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-44740 | MEDIUM6.38 | github.com/go-git/go-billy/v5 v5.7.0 fixed in 5.9.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-45022 | MEDIUM6.38 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.19.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34986 | MEDIUM6.38 | github.com/go-jose/go-jose/v4 v4.1.3 fixed in 4.1.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-29181 | MEDIUM6.38 | go.opentelemetry.io/otel v1.39.0 fixed in 1.41.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | golang.org/x/net v0.48.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-46600 | MEDIUM6.38 | golang.org/x/net v0.48.0 fixed in 0.56.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-84445 | MEDIUM6.38 | google.golang.org/grpc v1.78.0 fixed in 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-25679 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.8, 1.26.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27145 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.9, 1.26.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-32281 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.9, 1.26.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-33811 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.10, 1.26.3 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-33818 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39820 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.10, 1.26.3 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-39836 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42499 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42504 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56853 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56859 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56860 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-56862 | MEDIUM6.38 | stdlib v1.25.7 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42508 | MEDIUM6.29 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-41506 | MEDIUM6.29 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.18.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42306 | MEDIUM6.12 | github.com/docker/docker v28.5.2+incompatible No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-46595 | MEDIUM6.03 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-71556 | MEDIUM6.03 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.19.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-14457 | MEDIUM6 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-14457 | MEDIUM6 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-24051 | MEDIUM5.95 | go.opentelemetry.io/otel/sdk v1.39.0 fixed in 1.40.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39883 | MEDIUM5.95 | go.opentelemetry.io/otel/sdk v1.39.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.5.5-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63073 | MEDIUM5.9 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.5.5-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63073 | MEDIUM5.9 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-56132 | MEDIUM5.87 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56404 | MEDIUM5.87 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56407 | MEDIUM5.87 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56854 | MEDIUM5.78 | golang.org/x/crypto v0.46.0 fixed in 0.55.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | libcrypto3 3.5.5-r0 fixed in 3.5.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | libssl3 3.5.5-r0 fixed in 3.5.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39827 | MEDIUM5.52 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39834 | MEDIUM5.52 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-25680 | MEDIUM5.52 | golang.org/x/net v0.47.0 fixed in 0.55.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39825 | MEDIUM5.52 | stdlib v1.24.11 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-35469 | MEDIUM5.52 | github.com/moby/spdystream v0.5.0 fixed in 0.5.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-25680 | MEDIUM5.52 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39825 | MEDIUM5.52 | stdlib v1.25.7 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-26625 | MEDIUM5.5 | git-lfs 3.7.0-r5 fixed in 3.7.1-r0 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.24.11 fixed in 1.25.9, 1.26.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.25.7 fixed in 1.25.9, 1.26.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-71557 | MEDIUM5.35 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.19.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM5.3 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42766 | MEDIUM5.3 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42502 | MEDIUM5.18 | golang.org/x/net v0.47.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32289 | MEDIUM5.18 | stdlib v1.24.11 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42502 | MEDIUM5.18 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32289 | MEDIUM5.18 | stdlib v1.25.7 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.02 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.02 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-32776 | MEDIUM4.67 | libexpat 2.7.4-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32777 | MEDIUM4.67 | libexpat 2.7.4-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32778 | MEDIUM4.67 | libexpat 2.7.4-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r21 fixed in 1.2.5-r22 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl-utils 1.2.5-r21 fixed in 1.2.5-r22 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39833 | MEDIUM4.67 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.24.11 fixed in 1.25.9, 1.26.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.25.7 fixed in 1.25.9, 1.26.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42506 | MEDIUM4.59 | golang.org/x/net v0.47.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27142 | MEDIUM4.59 | stdlib v1.24.11 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | MEDIUM4.59 | stdlib v1.24.11 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.24.11 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45571 | MEDIUM4.59 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.19.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42506 | MEDIUM4.59 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27142 | MEDIUM4.59 | stdlib v1.25.7 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | MEDIUM4.59 | stdlib v1.25.7 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.25.7 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-46598 | MEDIUM4.5 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-56855 | MEDIUM4.5 | golang.org/x/crypto v0.46.0 fixed in 0.56.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-78662 | MEDIUM4.5 | golang.org/x/crypto v0.46.0 fixed in 0.56.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61730 | MEDIUM4.5 | stdlib v1.24.11 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.24.11 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | MEDIUM4.5 | stdlib v1.24.11 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.25.7 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | MEDIUM4.5 | stdlib v1.25.7 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34165 | MEDIUM4.25 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.17.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-12064 | LOW3.82 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5773 | LOW3.82 | curl 8.17.0-r1 fixed in 8.20.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW3.82 | curl 8.17.0-r1 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9079 | LOW3.82 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9546 | LOW3.82 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-11586 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5773 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.20.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9079 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9546 | LOW3.82 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-56131 | LOW3.82 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-9547 | LOW3.77 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-25934 | LOW3.65 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.16.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-1965 | LOW3.47 | curl 8.17.0-r1 fixed in 8.19.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-14819 | LOW3.47 | curl 8.17.0-r1 fixed in 8.18.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-1965 | LOW3.47 | libcurl 8.17.0-r1 fixed in 8.19.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-14819 | LOW3.47 | libcurl 8.17.0-r1 fixed in 8.18.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-11564 | LOW3.31 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW3.31 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-19931 | LOW3.31 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-3784 | LOW3.31 | curl 8.17.0-r1 fixed in 8.19.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | curl 8.17.0-r1 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW3.31 | curl 8.17.0-r1 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | curl 8.17.0-r1 fixed in 8.18.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-11564 | LOW3.31 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW3.31 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-19931 | LOW3.31 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-3784 | LOW3.31 | libcurl 8.17.0-r1 fixed in 8.19.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | libcurl 8.17.0-r1 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW3.31 | libcurl 8.17.0-r1 fixed in 8.20.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | libcurl 8.17.0-r1 fixed in 8.18.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-41568 | LOW3.31 | github.com/docker/docker v28.5.2+incompatible No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33186 | LOW3.28 | google.golang.org/grpc v1.67.0 fixed in 1.79.3 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-33186 | LOW3.28 | google.golang.org/grpc v1.78.0 fixed in 1.79.3 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3805 | LOW3.21 | curl 8.17.0-r1 fixed in 8.19.0-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-3805 | LOW3.21 | libcurl 8.17.0-r1 fixed in 8.19.0-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW3.15 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-75803 | LOW3.15 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-41080 | LOW3.15 | libexpat 2.7.4-r0 fixed in 2.8.1-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-75803 | LOW3.15 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | LOW3 | libcrypto3 3.5.5-r0 fixed in 3.5.6-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libssl3 3.5.5-r0 fixed in 3.5.6-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-1229 | LOW3 | github.com/cloudflare/circl v1.6.2 fixed in 1.6.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-45570 | LOW2.94 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.19.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8925 | LOW2.92 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 4.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-8925 | LOW2.92 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 4.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3783 | LOW2.91 | curl 8.17.0-r1 fixed in 8.19.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-3783 | LOW2.91 | libcurl 8.17.0-r1 fixed in 8.19.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-81870 | LOW2.8 | go.opentelemetry.io/otel/sdk v1.39.0 fixed in 1.45.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45445 | LOW2.78 | libcrypto3 3.5.5-r0 fixed in 3.5.7-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libssl3 3.5.5-r0 fixed in 3.5.7-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libcrypto3 3.5.5-r0 fixed in 3.5.6-r0 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libcrypto3 3.5.5-r0 fixed in 3.5.6-r0 | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2026-18798 | LOW2.7 | libcrypto3 3.5.5-r0 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libssl3 3.5.5-r0 fixed in 3.5.6-r0 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libssl3 3.5.5-r0 fixed in 3.5.6-r0 | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2026-18798 | LOW2.7 | libssl3 3.5.5-r0 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2025-61726 | LOW2.7 | stdlib v1.24.11 fixed in 1.24.12, 1.25.6 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-32952 | LOW2.7 | github.com/Azure/go-ntlmssp v0.1.0 fixed in 0.1.1 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | curl 8.17.0-r1 fixed in 8.20.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | curl 8.17.0-r1 fixed in 8.20.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-7009 | LOW2.7 | curl 8.17.0-r1 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | curl 8.17.0-r1 fixed in 8.20.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | libcurl 8.17.0-r1 fixed in 8.20.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | libcurl 8.17.0-r1 fixed in 8.20.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-7009 | LOW2.7 | libcurl 8.17.0-r1 fixed in 8.20.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | libcurl 8.17.0-r1 fixed in 8.20.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8458 | LOW2.48 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8458 | LOW2.48 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | curl 8.17.0-r1 fixed in 8.18.0-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-82208 | LOW2.45 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | libcurl 8.17.0-r1 fixed in 8.18.0-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-82208 | LOW2.45 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-33762 | LOW2.38 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.17.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-11352 | LOW2.29 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-11586 | LOW2.29 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-11352 | LOW2.29 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-27139 | LOW2.12 | stdlib v1.24.11 fixed in 1.25.8, 1.26.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27139 | LOW2.12 | stdlib v1.25.7 fixed in 1.25.8, 1.26.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13608 | LOW1.89 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-18924 | LOW1.89 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-80230 | LOW1.89 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-80231 | LOW1.89 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-80255 | LOW1.89 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-13608 | LOW1.89 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-18924 | LOW1.89 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-80230 | LOW1.89 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-80231 | LOW1.89 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-80255 | LOW1.89 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-82209 | LOW1.58 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-82209 | LOW1.58 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-80229 | NONE0 | curl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-80256 | NONE0 | curl 8.17.0-r1 fixed in 8.22.0-r0 | — | Not Applicable |
| CVE-2026-80229 | NONE0 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-80256 | NONE0 | libcurl 8.17.0-r1 fixed in 8.22.0-r0 | — | Not Applicable |
| CVE-2026-56408 | NONE0 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat 2.7.4-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.46.0 No fix yet | — | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.39.0 fixed in 0.44.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-84304 | NONE0 | google.golang.org/grpc v1.67.0 fixed in 1.83.1 | 0.6% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.67.0 fixed in 1.82.1 | — | Not Applicable |
| CVE-2026-84303 | NONE0 | google.golang.org/grpc v1.67.0 fixed in 1.83.1 | 0.3% Theoretical Threat | Not Applicable |
| GHSA-xmrv-pmrh-hhx2 | NONE0 | github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.4 fixed in 1.7.8 | — | Not Applicable |
| GHSA-xmrv-pmrh-hhx2 | NONE0 | github.com/aws/aws-sdk-go-v2/service/s3 v1.95.0 fixed in 1.97.3 | — | Not Applicable |
| GHSA-w5pp-99ch-qj29 | NONE0 | github.com/go-git/go-git/v5 v5.16.4 fixed in 5.19.1 | — | Not Applicable |
| GHSA-pmwq-pjrm-6p5r | NONE0 | github.com/in-toto/in-toto-golang v0.9.0 fixed in 0.11.0 | — | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.40.0 fixed in 0.44.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-84304 | NONE0 | google.golang.org/grpc v1.78.0 fixed in 1.83.1 | 0.6% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.78.0 fixed in 1.82.1 | — | Not Applicable |
| CVE-2026-84303 | NONE0 | google.golang.org/grpc v1.78.0 fixed in 1.83.1 | 0.3% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.