Vulnerability Reporthttpd:latest

DIGESTsha256:89a0b59e6d7285f00fc8df952a1579c31eb035cbdccb96690051e8bb6432cbea

Executive Summary

CAUTION

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. Despite being an Official Docker Hub Image with a trusted verdict, it exposes 14 vulnerabilities with severity 6.0 or higher, with the highest at 6.7, including potential local privilege escalation (CVE-2026-4878) and denial of service (CVE-2026-29111). Many of these higher-severity vulnerabilities require local access to the container for exploitation, reducing the direct network attack surface for the httpd service. Additionally, some systemd-related vulnerabilities, such as CVE-2026-40226 concerning `nspawn` or those explicitly requiring `systemd` to be PID 1, may have reduced relevance in a standard `httpd-foreground` container setup.

Threat Score
50/100
CAUTION
Reputation
TRUSTED
Docker Official
BaseImage/
httpd:latest
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

158 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-4878MEDIUM6.7
libcap2
1:2.75-10+b8
No fix yet
Directly Exposed
CVE-2026-25210MEDIUM6.63
libexpat1
2.7.1-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-29111MEDIUM6.63
libsystemd0
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-29111MEDIUM6.63
libudev1
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40225MEDIUM6.4
libsystemd0
257.9-1~deb13u1
No fix yet
Directly Exposed
CVE-2026-40226MEDIUM6.4
libsystemd0
257.9-1~deb13u1
No fix yet
Directly Exposed
CVE-2026-40225MEDIUM6.4
libudev1
257.9-1~deb13u1
No fix yet
Directly Exposed
CVE-2026-40226MEDIUM6.4
libudev1
257.9-1~deb13u1
No fix yet
Directly Exposed
CVE-2019-9192MEDIUM6.38
libc-bin
2.41-12+deb13u2
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2019-9192MEDIUM6.38
libc6
2.41-12+deb13u2
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2020-36325MEDIUM6.38
libjansson4
2.14-2+b3
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2-14
1.64.0-1.1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2018-20796MEDIUM6
libc-bin
2.41-12+deb13u2
No fix yet
1.5%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2018-20796MEDIUM6
libc6
2.41-12+deb13u2
No fix yet
1.5%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-13034MEDIUM5.78
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14819MEDIUM5.78
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-1965MEDIUM5.78
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22185MEDIUM5.78
libldap-common
2.6.10+dfsg-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22185MEDIUM5.78
libldap2
2.6.10+dfsg-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4105MEDIUM5.7
libsystemd0
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4105MEDIUM5.7
libudev1
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libc-bin
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libc6
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14524MEDIUM5.52
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3784MEDIUM5.52
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3805MEDIUM5.35
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-1757MEDIUM5.27
libxml2
2.12.7+dfsg+really2.9.14-2.1+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-10966MEDIUM5.02
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-26458MEDIUM5.02
libgssapi-krb5-2
1.21.3-5
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-26461MEDIUM5.02
libgssapi-krb5-2
1.21.3-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-26458MEDIUM5.02
libk5crypto3
1.21.3-5
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-26461MEDIUM5.02
libk5crypto3
1.21.3-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-26458MEDIUM5.02
libkrb5-3
1.21.3-5
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-26461MEDIUM5.02
libkrb5-3
1.21.3-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-26458MEDIUM5.02
libkrb5support0
1.21.3-5
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-26461MEDIUM5.02
libkrb5support0
1.21.3-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.02
libtasn1-6
4.20.0-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-0990MEDIUM5.02
libxml2
2.12.7+dfsg+really2.9.14-2.1+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3783MEDIUM4.84
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-66382MEDIUM4.67
libexpat1
2.7.1-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
libexpat1
2.7.1-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
libexpat1
2.7.1-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
libexpat1
2.7.1-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg+really1.3.1-1+b1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2015-3276MEDIUM4.5
libldap-common
2.6.10+dfsg-1
No fix yet
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2017-17740MEDIUM4.5
libldap-common
2.6.10+dfsg-1
No fix yet
6.2%
Low-Moderate Risk
Directly Exposed
CVE-2015-3276MEDIUM4.5
libldap2
2.6.10+dfsg-1
No fix yet
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2017-17740MEDIUM4.5
libldap2
2.6.10+dfsg-1
No fix yet
6.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-bin
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM4.5
libc-bin
2.41-12+deb13u2
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc-bin
2.41-12+deb13u2
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM4.5
libc6
2.41-12+deb13u2
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc6
2.41-12+deb13u2
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-59375MEDIUM4.5
libexpat1
2.7.1-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.8.1-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libsystemd0
257.9-1~deb13u1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libsystemd0
257.9-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libsystemd0
257.9-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libudev1
257.9-1~deb13u1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libudev1
257.9-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libudev1
257.9-1~deb13u1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2011-3389MEDIUM4.3
libgnutls30t64
3.8.9-3+deb13u2
No fix yet
3.8%
Low-Moderate Risk
Directly Exposed
CVE-2025-14017MEDIUM4.08
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-15224MEDIUM4
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2017-14159MEDIUM4
libldap-common
2.6.10+dfsg-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2017-14159MEDIUM4
libldap2
2.6.10+dfsg-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2011-3374LOW3.7
libapt-pkg7.0
3.0.3
No fix yet
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-41080LOW3.7
libexpat1
2.7.1-2
No fix yet
Directly Exposed
CVE-2021-45346LOW3.65
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2005-2541LOW3.6
tar
1.35+dfsg-3.1
No fix yet
3.3%
Low-Moderate Risk
Post-Exploit
CVE-2020-15719LOW3.57
libldap-common
2.6.10+dfsg-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2020-15719LOW3.57
libldap2
2.6.10+dfsg-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc-bin
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2010-4756LOW3.4
libc-bin
2.41-12+deb13u2
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.41-12+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2010-4756LOW3.4
libc6
2.41-12+deb13u2
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW3.3
libsystemd0
257.9-1~deb13u1
No fix yet
Directly Exposed
CVE-2026-40228LOW3.3
libudev1
257.9-1~deb13u1
No fix yet
Directly Exposed
CVE-2026-3184LOW3.15
libblkid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184LOW3.15
libmount1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184LOW3.15
libuuid1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-0989LOW3.15
libxml2
2.12.7+dfsg+really2.9.14-2.1+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104LOW3.11
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010022LOW3
libc-bin
2.41-12+deb13u2
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010022LOW3
libc6
2.41-12+deb13u2
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-70873LOW2.8
libsqlite3-0
3.46.1-7+deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libsystemd0
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libudev1
257.9-1~deb13u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-8732LOW2.8
libxml2
2.12.7+dfsg+really2.9.14-2.1+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2018-5709LOW2.7
libgssapi-krb5-2
1.21.3-5
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2018-5709LOW2.7
libk5crypto3
1.21.3-5
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2018-5709LOW2.7
libkrb5-3
1.21.3-5
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2018-5709LOW2.7
libkrb5support0
1.21.3-5
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010023LOW2.69
libc-bin
2.41-12+deb13u2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc6
2.41-12+deb13u2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.55
tar
1.35+dfsg-3.1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2007-5686LOW2.5
login.defs
1:4.17.4-2
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2007-5686LOW2.5
passwd
1:4.17.4-2
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
libcurl4t64
8.14.1-2+deb13u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-0992LOW2.46
libxml2
2.12.7+dfsg+really2.9.14-2.1+deb13u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456LOW2.4
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2017-18018LOW2.4
coreutils
9.7-3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils
9.7-3
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW2.22
apt
3.0.3
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW2.16
login.defs
1:4.17.4-2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW2.16
passwd
1:4.17.4-2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-24515LOW2.12
libexpat1
2.7.1-2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184LOW1.89
bsdutils
1:2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW1.89
login
1:4.16.0-2+really2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW1.89
mount
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW1.89
util-linux
2.41-5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2011-4116LOW1.68
perl-base
5.40.1-6
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69720NONE0
libtinfo6
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-69720NONE0
ncurses-base
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-69720NONE0
ncurses-bin
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-14104NONE0
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-14104NONE0
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2022-0563NONE0
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2022-0563NONE0
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-27456NONE0
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-27456NONE0
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-3184NONE0
liblastlog2-2
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-3184NONE0
libsmartcols1
2.41-5
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
libtinfo6
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
ncurses-base
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
ncurses-bin
6.5+20250216-2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
TEMP-0841856-B18BAFNONE0
bash
5.2.37-2+b8
No fix yet
Not Applicable
CVE-2026-5358NONE0
libc-bin
2.41-12+deb13u2
No fix yet
Not Applicable
CVE-2026-5450NONE0
libc-bin
2.41-12+deb13u2
No fix yet
Not Applicable
CVE-2026-5928NONE0
libc-bin
2.41-12+deb13u2
No fix yet
Not Applicable
CVE-2026-5358NONE0
libc6
2.41-12+deb13u2
No fix yet
Not Applicable
CVE-2026-5450NONE0
libc6
2.41-12+deb13u2
No fix yet
Not Applicable
CVE-2026-5928NONE0
libc6
2.41-12+deb13u2
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
login.defs
1:4.17.4-2
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
passwd
1:4.17.4-2
No fix yet
Not Applicable
CVE-2026-5958NONE0
sed
4.9-2
No fix yet
Not Applicable
TEMP-0517018-A83CE6NONE0
sysvinit-utils
3.14-4
No fix yet
Not Applicable
TEMP-0290435-0B57B5NONE0
tar
1.35+dfsg-3.1
No fix yet
Not Applicable