Last scanned:
This image is safe for production use. The scan did surface low-severity items (3 exposed and 19 post-exploit-only), but their maximum severities of 3.15 and 2.78 fall well below the thresholds that would raise concern, and no high-impact findings were reported. The image is a widely used community file browser with strong reputation and is pinned by digest, so the artifact you deploy is immutable and reproducible. Keep the database and configuration paths mounted with least privilege, since the container serves file-access functionality by design.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-75803 | LOW3.15 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-75803 | LOW3.15 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13221 | LOW2.78 | perl 5.42.2-r0 fixed in 5.42.2-r1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-18798 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63072 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63076 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-14457 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-54874 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-18798 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63072 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63076 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-14457 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-54874 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-14456 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-63074 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-63075 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-14456 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-63074 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-63075 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-63073 | LOW2.12 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63073 | LOW2.12 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.56.0 No fix yet | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.