Vulnerability Reporthexpm/elixir:1.19.5-erlang-28.5-debian-trixie-20260505

hexpm/elixir:1.19.5-erlang-28.5-debian-trixie-20260505
DIGESTsha256:7c5a50e1dc2abd3ff5a8ff7e8178e01581f0341f3ed80774740178e25c144466

Executive Summary

CAUTION

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. Exploitation of vulnerabilities like CVE-2026-29111 could lead to arbitrary code execution or Denial of Service from an unprivileged process, while CVE-2018-20796 poses a remote Denial of Service risk via malicious regular expression processing. The image's startup command is "bash", which may increase the relevance of vulnerabilities in command-line utilities. Note that CVE-2019-1010022 is considered a non-security bug by its upstream project and requires a pre-existing stack buffer overflow. The unknown Linux distribution might also present challenges for proactive security updates.

Threat Score
50/100
CAUTION
Reputation
RELIABLE
hexpm
BaseImage/
hexpm/elixir:1.19.5-erlang-28.5-debian-trixie-20260505
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

111 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2019-1010022MEDIUM6.66
libc-bin
2.41-12+deb13u2
No fix yet
0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2019-1010022MEDIUM6.66
libc6
2.41-12+deb13u2
No fix yet
0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-29111MEDIUM6.63
libsystemd0
257.9-1~deb13u1
fixed in 257.13-1~deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69720MEDIUM6.63
libtinfo6
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-29111MEDIUM6.63
libudev1
257.9-1~deb13u1
fixed in 257.13-1~deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69720MEDIUM6.63
ncurses-base
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2018-20796MEDIUM6
libc-bin
2.41-12+deb13u2
No fix yet
1.5%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2018-20796MEDIUM6
libc6
2.41-12+deb13u2
No fix yet
1.5%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-4878MEDIUM5.95
libcap2
1:2.75-10+b8
fixed in 1:2.75-10+deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4105MEDIUM5.7
libsystemd0
257.9-1~deb13u1
fixed in 257.13-1~deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4105MEDIUM5.7
libudev1
257.9-1~deb13u1
fixed in 257.13-1~deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40225MEDIUM5.44
libsystemd0
257.9-1~deb13u1
fixed in 257.13-1~deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libsystemd0
257.9-1~deb13u1
fixed in 257.13-1~deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40225MEDIUM5.44
libudev1
257.9-1~deb13u1
fixed in 257.13-1~deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libudev1
257.9-1~deb13u1
fixed in 257.13-1~deb13u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-1013MEDIUM5.3
libodbc2
2.3.12-2
No fix yet
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-14104MEDIUM5.18
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2019-9192MEDIUM5.1
libc-bin
2.41-12+deb13u2
No fix yet
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2019-9192MEDIUM5.1
libc6
2.41-12+deb13u2
No fix yet
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2022-0563MEDIUM4.67
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg+really1.3.1-1+b1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-bin
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
<0.1%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM4.5
libc-bin
2.41-12+deb13u2
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc-bin
2.41-12+deb13u2
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
<0.1%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM4.5
libc6
2.41-12+deb13u2
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc6
2.41-12+deb13u2
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.8.1-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libsystemd0
257.9-1~deb13u1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libsystemd0
257.9-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libsystemd0
257.9-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libudev1
257.9-1~deb13u1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libudev1
257.9-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libudev1
257.9-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM4.42
libc-bin
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4437MEDIUM4.42
libc6
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5450MEDIUM4.25
libc-bin
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc-bin
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69720LOW3.98
ncurses-bin
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW3.7
libapt-pkg7.0
3.0.3
No fix yet
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2021-45346LOW3.65
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2005-2541LOW3.6
tar
1.35+dfsg-3.1
No fix yet
3.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-4438LOW3.4
libc-bin
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
<0.1%
Theoretical Threat
Directly Exposed
CVE-2010-4756LOW3.4
libc-bin
2.41-12+deb13u2
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.41-12+deb13u2
fixed in 2.41-12+deb13u3
<0.1%
Theoretical Threat
Directly Exposed
CVE-2010-4756LOW3.4
libc6
2.41-12+deb13u2
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14104LOW3.11
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.8
tar
1.35+dfsg-3.1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-70873LOW2.8
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libsystemd0
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libsystemd0
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-6141LOW2.8
libtinfo6
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libudev1
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-6141LOW2.8
ncurses-base
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184LOW2.7
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc-bin
2.41-12+deb13u2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc6
2.41-12+deb13u2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2007-5686LOW2.5
passwd
1:4.17.4-2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2017-18018LOW2.4
coreutils
9.7-3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils
9.7-3
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW2.22
apt
3.0.3
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW2.16
passwd
1:4.17.4-2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-6238LOW1.99
libc-bin
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc-bin
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-6141LOW1.68
ncurses-bin
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2011-4116LOW1.68
perl-base
5.40.1-6
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2007-5686NONE0
login.defs
1:4.17.4-2
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2024-56433NONE0
login.defs
1:4.17.4-2
No fix yet
4.5%
Low-Moderate Risk
Not Applicable
TEMP-0841856-B18BAFNONE0
bash
5.2.37-2+b8
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
login.defs
1:4.17.4-2
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
passwd
1:4.17.4-2
No fix yet
Not Applicable
CVE-2026-5958NONE0
sed
4.9-2
fixed in 4.9-2+deb13u1
<0.1%
Theoretical Threat
Not Applicable
TEMP-0517018-A83CE6NONE0
sysvinit-utils
3.14-4
No fix yet
Not Applicable
TEMP-0290435-0B57B5NONE0
tar
1.35+dfsg-3.1
No fix yet
Not Applicable