Last scanned:
This image is safe for production use. The sole post-exploit finding is low severity (3.0) and not part of the exposed attack surface, so it poses negligible practical risk. No CVE IDs were identified in the top findings, and the image is an official, digest-pinned HAProxy release. Overall, no remediation is required for production deployment.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-56123 | LOW3 | socat 1.8.1.1-r0 fixed in 1.8.1.2-r0 | 0.3% Theoretical Threat | Post-Exploit |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.