Vulnerability Reporthaproxy:latest

haproxy:latesthaproxy:trixiehaproxy:lts-trixiehaproxy:ltshaproxy:3.4.0-trixiehaproxy:3.4.0haproxy:3.4-trixiehaproxy:3.4
DIGESTsha256:d27a4aac59a6a4f4f2a0a43c93599bdc573aa2cda2cfc297fa9f29cc5219dfdc

Executive Summary

NEEDS_ATTENTION

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The image contains 4 exposed vulnerabilities with severities ranging from 6.0 to 6.66, primarily impacting glibc. Notably, CVE-2019-1010022 (severity 6.66) could bypass stack guard protection, although upstream deems it a non-security bug, and CVE-2018-20796 (severity 6.0) could cause a denial of service if HAProxy processes maliciously crafted regular expressions. While there are 60 post-exploit vulnerabilities, their maximum severity is low at 4.68, and they generally require prior local access to exploit. The image benefits from being an official Docker Hub image and is pinned by digest, indicating a strong baseline of trust.

Threat Score
27/100
NEEDS_ATTENTION
Reputation
TRUSTED
Docker Official
BaseImage/
haproxy:latest
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

149 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2019-1010022MEDIUM6.66
libc-bin
2.41-12+deb13u3
No fix yet
0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2019-1010022MEDIUM6.66
libc6
2.41-12+deb13u3
No fix yet
0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2018-20796MEDIUM6
libc-bin
2.41-12+deb13u3
No fix yet
1.5%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2018-20796MEDIUM6
libc6
2.41-12+deb13u3
No fix yet
1.5%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-14104MEDIUM5.18
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42250MEDIUM5
libbz2-1.0
1.0.8-6
No fix yet
Directly Exposed
CVE-2026-48962MEDIUM4.68
perl-base
5.40.1-6
No fix yet
Post-Exploit
CVE-2022-0563MEDIUM4.67
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg+really1.3.1-1+b1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc6
2.41-12+deb13u3
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.8.1-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libsystemd0
257.13-1~deb13u1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libsystemd0
257.13-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libsystemd0
257.13-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libudev1
257.13-1~deb13u1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libudev1
257.13-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libudev1
257.13-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc-bin
2.41-12+deb13u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc-bin
2.41-12+deb13u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.41-12+deb13u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.41-12+deb13u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69720LOW3.98
ncurses-bin
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2019-9192LOW3.83
libc-bin
2.41-12+deb13u3
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2019-9192LOW3.83
libc6
2.41-12+deb13u3
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2011-3374LOW3.7
libapt-pkg7.0
3.0.3
No fix yet
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2021-45346LOW3.65
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2005-2541LOW3.6
tar
1.35+dfsg-3.1
No fix yet
3.8%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010024LOW3.6
libc-bin
2.41-12+deb13u3
No fix yet
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2019-1010025LOW3.6
libc-bin
2.41-12+deb13u3
No fix yet
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2019-1010024LOW3.6
libc6
2.41-12+deb13u3
No fix yet
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-8376LOW3.53
perl-base
5.40.1-6
No fix yet
Post-Exploit
CVE-2010-4756LOW3.4
libc-bin
2.41-12+deb13u3
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2010-4756LOW3.4
libc6
2.41-12+deb13u3
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42496LOW3.28
perl-base
5.40.1-6
No fix yet
Post-Exploit
CVE-2025-14104LOW3.11
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.8
tar
1.35+dfsg-3.1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-70873LOW2.8
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libsystemd0
257.13-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libsystemd0
257.13-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libudev1
257.13-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
257.13-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42497LOW2.7
perl-base
5.40.1-6
No fix yet
Post-Exploit
CVE-2026-9538LOW2.7
perl-base
5.40.1-6
No fix yet
Post-Exploit
CVE-2026-3184LOW2.7
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc-bin
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc6
2.41-12+deb13u3
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2007-5686LOW2.5
passwd
1:4.17.4-2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2017-18018LOW2.4
coreutils
9.7-3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils
9.7-3
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW2.22
apt
3.0.3
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW2.16
passwd
1:4.17.4-2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-6238LOW1.99
libc-bin
2.41-12+deb13u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.41-12+deb13u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc-bin
2.41-12+deb13u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.41-12+deb13u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-6141LOW1.68
ncurses-bin
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2011-4116LOW1.68
perl-base
5.40.1-6
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69720NONE0
libtinfo6
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-69720NONE0
ncurses-base
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-14104NONE0
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-14104NONE0
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2022-0563NONE0
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2022-0563NONE0
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-3184NONE0
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-3184NONE0
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2007-5686NONE0
login.defs
1:4.17.4-2
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27456NONE0
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-27456NONE0
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2024-56433NONE0
login.defs
1:4.17.4-2
No fix yet
4.5%
Low-Moderate Risk
Not Applicable
CVE-2025-6141NONE0
libtinfo6
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
ncurses-base
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
TEMP-0841856-B18BAFNONE0
bash
5.2.37-2+b9
No fix yet
Not Applicable
CVE-2026-34180NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34181NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34182NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34183NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42764NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42766NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42767NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42768NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42769NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42770NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45445NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45446NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45447NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-7383NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-9076NONE0
libssl3t64
3.5.6-1~deb13u1
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
login.defs
1:4.17.4-2
No fix yet
Not Applicable
CVE-2026-34180NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34181NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34182NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34183NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42764NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42766NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42767NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42768NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42769NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42770NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45445NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45446NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45447NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-7383NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-9076NONE0
openssl
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34180NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34181NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34182NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-34183NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42764NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42766NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42767NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42768NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42769NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-42770NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45445NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45446NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-45447NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-7383NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
CVE-2026-9076NONE0
openssl-provider-legacy
3.5.6-1~deb13u1
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
passwd
1:4.17.4-2
No fix yet
Not Applicable
CVE-2026-48959NONE0
perl-base
5.40.1-6
No fix yet
Not Applicable
CVE-2025-15649NONE0
perl-base
5.40.1-6
No fix yet
Not Applicable
CVE-2026-7010NONE0
perl-base
5.40.1-6
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-48961NONE0
perl-base
5.40.1-6
No fix yet
Not Applicable
TEMP-0517018-A83CE6NONE0
sysvinit-utils
3.14-4
No fix yet
Not Applicable
TEMP-0290435-0B57B5NONE0
tar
1.35+dfsg-3.1
No fix yet
Not Applicable