Last scanned:
This image is safe for production use. It contains 17 low-severity exposed vulnerabilities (max CVSS 5.5) and 6 low-severity post-exploit issues (max 2.48), which pose minimal risk in typical deployment scenarios. The image is from a trusted community publisher and is pinned by digest, ensuring immutability.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-54512 | MEDIUM5.5 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54513 | MEDIUM5.5 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-22747 | MEDIUM5.5 | org.springframework.security:spring-security-web 7.0.4 fixed in 7.0.5 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-22754 | MEDIUM5.1 | org.springframework.security:spring-security-config 7.0.4 fixed in 7.0.5 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg-3.1ubuntu2.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54518 | MEDIUM4.42 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4 | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-0636 | MEDIUM4.42 | org.bouncycastle:bcprov-jdk18on 1.81.1 fixed in 1.84 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-22753 | MEDIUM4.42 | org.springframework.security:spring-security-config 7.0.4 fixed in 7.0.5 | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54514 | LOW3.6 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54515 | LOW3.6 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54516 | LOW3.6 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4, 3.1.4 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54517 | LOW3.6 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-4438 | LOW3.4 | libc6 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-kqueue 4.2.12.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22751 | LOW3.26 | org.springframework.security:spring-security-core 7.0.4 fixed in 6.5.10, 7.0.5 | 0.1% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-22746 | LOW3.15 | org.springframework.security:spring-security-core 7.0.4 fixed in 6.5.10, 7.0.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-59250 | LOW2.48 | com.microsoft.sqlserver:mssql-jdbc 13.2.1 fixed in 10.2.4.jre11, 11.2.4.jre11, 12.2.1.jre11, 12.6.5.jre11, 12.8.2.jre11, 12.10.2.jre11, 13.2.1.jre11 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-42198 | LOW2.29 | org.postgresql:postgresql 42.7.10 fixed in 42.7.11 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-4437 | LOW1.99 | libc6 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc6 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc6 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-4046 | LOW1.62 | libc6 2.39-0ubuntu8.7 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.54.0 No fix yet | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.