Last scanned:
AI verdict failed due to an error.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-55200 | NONE0 | libssh2 1.11.1-3.ph5 fixed in 1.11.1-4.ph5 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-39822 | NONE0 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-55199 | NONE0 | libssh2 1.11.1-3.ph5 fixed in 1.11.1-5.ph5 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-32952 | NONE0 | github.com/Azure/go-ntlmssp v0.1.0 fixed in 0.1.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-35172 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-41888 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42505 | NONE0 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-11850 | NONE0 | krb5 1.20.2-13.ph5 fixed in 1.20.2-14.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-35206 | NONE0 | helm.sh/helm/v3 v3.18.5 fixed in 3.20.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-33540 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-24358 | NONE0 | github.com/gorilla/csrf v1.7.2 fixed in 1.7.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-47909 | NONE0 | github.com/gorilla/csrf v1.7.2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.52.0 No fix yet | — | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.55.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.37.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.81.1 fixed in 1.82.1 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.