Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The Jenkins image exposes a substantial number of vulnerabilities (170 total, 21 rated >=6.0); the most notable are CVE-2026-39821 (privilege escalation via Punycode handling) and CVE-2026-54512 (Jackson databind deserialization leading to potential remote code execution). An attacker could potentially leverage these flaws to gain unauthorized access or execute arbitrary code with the privileges of the Jenkins process. However, none of the exposed findings reach the 7.0 severity threshold, and post-exploit-only issues remain low (max 4.64), keeping the overall risk at CAUTION rather than DANGEROUS. Disabling Jackson's polymorphic deserialization fully mitigates CVE-2026-54512, and note that this flaw only applies if that non-default feature is enabled.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-39821 | MEDIUM6.97 | golang.org/x/net v0.38.0 fixed in 0.55.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.20.1 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.20.1 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-39831 | MEDIUM6.88 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-25681 | MEDIUM6.88 | golang.org/x/net v0.38.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27136 | MEDIUM6.88 | golang.org/x/net v0.38.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-25210 | MEDIUM6.63 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-48962 | MEDIUM6.63 | libperl5.40 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45186 | MEDIUM6.38 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42497 | MEDIUM6.38 | libperl5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-9538 | MEDIUM6.38 | libperl5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-47913 | MEDIUM6.38 | golang.org/x/crypto v0.36.0 fixed in 0.43.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39829 | MEDIUM6.38 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39830 | MEDIUM6.38 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39835 | MEDIUM6.38 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-46597 | MEDIUM6.38 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | golang.org/x/net v0.38.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42508 | MEDIUM6.29 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54369 | MEDIUM6.03 | libacl1 2.3.2-2+b1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-46595 | MEDIUM6.03 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2015-3276 | MEDIUM6 | libldap2 2.6.10+dfsg-1 No fix yet | 5.3% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-26461 | MEDIUM5.9 | libgssapi-krb5-2 1.21.3-5+deb13u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libk5crypto3 1.21.3-5+deb13u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libkrb5-3 1.21.3-5+deb13u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libkrb5support0 1.21.3-5+deb13u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-56132 | MEDIUM5.87 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56404 | MEDIUM5.87 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56407 | MEDIUM5.87 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22185 | MEDIUM5.78 | libldap2 2.6.10+dfsg-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2011-3389 | MEDIUM5.59 | libgnutls30t64 3.8.9-3+deb13u4 No fix yet | 73.3% Actively Exploited | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-15649 | MEDIUM5.52 | libperl5.40 5.40.1-6 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.20.1 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39827 | MEDIUM5.52 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39834 | MEDIUM5.52 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25680 | MEDIUM5.52 | golang.org/x/net v0.38.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54370 | MEDIUM5.35 | libacl1 2.3.2-2+b1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54371 | MEDIUM5.35 | libattr1 1:2.5.2-3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc-bin 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc-bin 2.41-12+deb13u3 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-59375 | MEDIUM5.3 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.25.5-3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libblkid1 2.41-5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | liblastlog2-2 2.41-5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libmount1 2.41-5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libsmartcols1 2.41-5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libuuid1 2.41-5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42502 | MEDIUM5.18 | golang.org/x/net v0.38.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libgssapi-krb5-2 1.21.3-5+deb13u1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libk5crypto3 1.21.3-5+deb13u1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libkrb5-3 1.21.3-5+deb13u1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libkrb5support0 1.21.3-5+deb13u1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libblkid1 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-66382 | MEDIUM4.67 | libexpat1 2.7.1-2 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32776 | MEDIUM4.67 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32777 | MEDIUM4.67 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32778 | MEDIUM4.67 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | liblastlog2-2 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libmount1 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2021-4214 | MEDIUM4.67 | libpng16-16t64 1.6.48-1+deb13u5 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libsmartcols1 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libuuid1 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39833 | MEDIUM4.67 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42496 | MEDIUM4.64 | perl 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42496 | MEDIUM4.64 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42496 | MEDIUM4.64 | perl-modules-5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-58055 | MEDIUM4.59 | libnghttp2-14 1.64.0-1.1+deb13u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42506 | MEDIUM4.59 | golang.org/x/net v0.38.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2022-24975 | MEDIUM4.5 | git 1:2.47.3-0+deb13u1 No fix yet | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-13595 | MEDIUM4.5 | libblkid1 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libblkid1 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | liblastlog2-2 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | liblastlog2-2 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | liblzma5 5.8.1-1 fixed in 5.8.1-1+deb13u1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libmount1 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libmount1 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-12087 | MEDIUM4.5 | libperl5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-3713 | MEDIUM4.5 | libpng16-16t64 1.6.48-1+deb13u5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libsmartcols1 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libsmartcols1 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libudev1 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libudev1 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libudev1 257.13-1~deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libuuid1 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libuuid1 2.41-5 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.20.1 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.20.1 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-47914 | MEDIUM4.5 | golang.org/x/crypto v0.36.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58181 | MEDIUM4.5 | golang.org/x/crypto v0.36.0 fixed in 0.45.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-46598 | MEDIUM4.5 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-47911 | MEDIUM4.5 | golang.org/x/net v0.38.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58190 | MEDIUM4.5 | golang.org/x/net v0.38.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-52005 | MEDIUM4.49 | git 1:2.47.3-0+deb13u1 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2021-45346 | MEDIUM4.3 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-57432 | MEDIUM4.28 | perl 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-57432 | MEDIUM4.28 | perl-base 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-57432 | MEDIUM4.28 | perl-modules-5.40 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42250 | MEDIUM4.25 | libbz2-1.0 1.0.8-6 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.41-12+deb13u3 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.41-12+deb13u3 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libgssapi-krb5-2 1.21.3-5+deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libk5crypto3 1.21.3-5+deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5-3 1.21.3-5+deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5support0 1.21.3-5+deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-48959 | MEDIUM4.25 | libperl5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48961 | MEDIUM4.25 | libperl5.40 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2020-15719 | MEDIUM4.2 | libldap2 2.6.10+dfsg-1 No fix yet | 2.5% Low-Moderate Risk | Directly Exposed |
| CVE-2026-8286 | MEDIUM4.13 | curl 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | curl 8.14.1-2+deb13u4 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | MEDIUM4.13 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | MEDIUM4.13 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | liblastlog2-2 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2017-14159 | MEDIUM4 | libldap2 2.6.10+dfsg-1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.41-5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc-bin 2.41-12+deb13u3 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc6 2.41-12+deb13u3 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-48962 | LOW3.98 | perl 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-48962 | LOW3.98 | perl-base 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-48962 | LOW3.98 | perl-modules-5.40 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2008-3234 | LOW3.9 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-12064 | LOW3.82 | curl 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | curl 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | curl 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9079 | LOW3.82 | curl 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | curl 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-41992 | LOW3.82 | gzip 1.13-1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW3.82 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9079 | LOW3.82 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW3.82 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9079 | LOW3.82 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59999 | LOW3.82 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-60000 | LOW3.82 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42497 | LOW3.82 | perl 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9538 | LOW3.82 | perl 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42497 | LOW3.82 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9538 | LOW3.82 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42497 | LOW3.82 | perl-modules-5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9538 | LOW3.82 | perl-modules-5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | curl 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | curl 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW3.7 | libapt-pkg7.0 3.0.3 No fix yet | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2005-2541 | LOW3.6 | tar 1.35+dfsg-3.1 No fix yet | 4.0% Low-Moderate Risk | Post-Exploit |
| CVE-2020-14145 | LOW3.54 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010022 | LOW3.53 | libc-bin 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010022 | LOW3.53 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11856 | LOW3.31 | curl 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | curl 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW3.31 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW3.31 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-66032 | LOW3.31 | libssh2-1t64 1.11.1-1+deb13u1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-66033 | LOW3.31 | libssh2-1t64 1.11.1-1+deb13u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59998 | LOW3.31 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-60001 | LOW3.31 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-15649 | LOW3.31 | perl 5.40.1-6 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15649 | LOW3.31 | perl-base 5.40.1-6 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15649 | LOW3.31 | perl-modules-5.40 5.40.1-6 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2016-20012 | LOW3.18 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 5.3% Low-Moderate Risk | Post-Exploit |
| CVE-2018-15919 | LOW3.18 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 3.6% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010023 | LOW3.17 | libc-bin 2.41-12+deb13u3 No fix yet | 3.1% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010023 | LOW3.17 | libc6 2.41-12+deb13u3 No fix yet | 3.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-41080 | LOW3.15 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | LOW3.11 | bsdutils 1:2.41-5 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-56391 | LOW3.11 | coreutils 9.7-3 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | mount 2.41-5 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | util-linux 2.41-5 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2020-15778 | LOW3.07 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 13.0% High Exploitation Risk | Post-Exploit |
| CVE-2025-10966 | LOW3.01 | curl 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-10966 | LOW3.01 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-10966 | LOW3.01 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-66034 | LOW3.01 | libssh2-1t64 1.11.1-1+deb13u1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | libperl5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | perl 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | perl-modules-5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2018-1000021 | LOW3 | git 1:2.47.3-0+deb13u1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2007-2243 | LOW3 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-60002 | LOW2.87 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2019-6110 | LOW2.81 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 20.9% High Exploitation Risk | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | bsdutils 1:2.41-5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | mount 2.41-5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.35+dfsg-3.1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | util-linux 2.41-5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2011-4116 | LOW2.8 | libperl5.40 5.40.1-6 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-70873 | LOW2.8 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libudev1 257.13-1~deb13u1 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 257.13-1~deb13u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13221 | LOW2.78 | libperl5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42496 | LOW2.78 | libperl5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-13221 | LOW2.78 | perl 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-13221 | LOW2.78 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-13221 | LOW2.78 | perl-modules-5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59995 | LOW2.75 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59996 | LOW2.75 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59997 | LOW2.75 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2018-20796 | LOW2.7 | libc-bin 2.41-12+deb13u3 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9192 | LOW2.7 | libc-bin 2.41-12+deb13u3 No fix yet | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2018-20796 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9192 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2018-5709 | LOW2.7 | libgssapi-krb5-2 1.21.3-5+deb13u1 No fix yet | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2018-5709 | LOW2.7 | libk5crypto3 1.21.3-5+deb13u1 No fix yet | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2018-5709 | LOW2.7 | libkrb5-3 1.21.3-5+deb13u1 No fix yet | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2018-5709 | LOW2.7 | libkrb5support0 1.21.3-5+deb13u1 No fix yet | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2017-17740 | LOW2.7 | libldap2 2.6.10+dfsg-1 No fix yet | 7.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-13595 | LOW2.7 | bsdutils 1:2.41-5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | bsdutils 1:2.41-5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-66035 | LOW2.7 | libssh2-1t64 1.11.1-1+deb13u1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-13595 | LOW2.7 | mount 2.41-5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | mount 2.41-5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-12087 | LOW2.7 | perl 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-12087 | LOW2.7 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-12087 | LOW2.7 | perl-modules-5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-13595 | LOW2.7 | util-linux 2.41-5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | util-linux 2.41-5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-39828 | LOW2.69 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-39832 | LOW2.66 | golang.org/x/crypto v0.36.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2007-2768 | LOW2.58 | openssh-client 1:10.0p1-7+deb13u4 No fix yet | 8.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-57432 | LOW2.57 | libperl5.40 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-48959 | LOW2.55 | perl 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-48961 | LOW2.55 | perl 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-48959 | LOW2.55 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-48961 | LOW2.55 | perl-base 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-48959 | LOW2.55 | perl-modules-5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-48961 | LOW2.55 | perl-modules-5.40 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2007-5686 | LOW2.5 | passwd 1:4.17.4-2 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | curl 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | curl 8.14.1-2+deb13u4 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.41-5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2017-18018 | LOW2.4 | coreutils 9.7-3 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | curl 8.14.1-2+deb13u4 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | curl 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.13-1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.41-5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.41-5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-5278 | LOW2.24 | coreutils 9.7-3 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-56392 | LOW2.24 | coreutils 9.7-3 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW2.22 | apt 3.0.3 No fix yet | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-24515 | LOW2.12 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.17.4-2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2011-4116 | LOW1.68 | perl 5.40.1-6 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2011-4116 | LOW1.68 | perl-base 5.40.1-6 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2011-4116 | LOW1.68 | perl-modules-5.40 5.40.1-6 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2021-4217 | LOW1.68 | unzip 6.0-29 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-68121 | NONE0 | stdlib v1.25.3 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2024-52005 | NONE0 | git-man 1:2.47.3-0+deb13u1 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libncursesw6 6.5+20250216-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libtinfo6 6.5+20250216-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-base 6.5+20250216-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-bin 6.5+20250216-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39822 | NONE0 | stdlib v1.25.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2022-24975 | NONE0 | git-man 1:2.47.3-0+deb13u1 No fix yet | 2.6% Low-Moderate Risk | Not Applicable |
| CVE-2025-61726 | NONE0 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2025-61729 | NONE0 | stdlib v1.25.3 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25679 | NONE0 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-32280 | NONE0 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-32281 | NONE0 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32283 | NONE0 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-33811 | NONE0 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-33814 | NONE0 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39820 | NONE0 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39836 | NONE0 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61728 | NONE0 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61727 | NONE0 | stdlib v1.25.3 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32282 | NONE0 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-14104 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-32289 | NONE0 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2022-0563 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32288 | NONE0 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-27142 | NONE0 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39823 | NONE0 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39826 | NONE0 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-13595 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-3184 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61730 | NONE0 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42505 | NONE0 | stdlib v1.25.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2018-1000021 | NONE0 | git-man 1:2.47.3-0+deb13u1 No fix yet | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2007-5686 | NONE0 | login.defs 1:4.17.4-2 No fix yet | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules 1.7.0-5 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules-bin 1.7.0-5 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-runtime 1.7.0-5 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam0g 1.7.0-5 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-27456 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2024-56433 | NONE0 | login.defs 1:4.17.4-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libncursesw6 6.5+20250216-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libtinfo6 6.5+20250216-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-base 6.5+20250216-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-bin 6.5+20250216-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27139 | NONE0 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Not Applicable |
| TEMP-0841856-B18BAF | NONE0 | bash 5.2.37-2+b9 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | bsdutils 1:2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | bsdutils 1:2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | bsdutils 1:2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | bsdutils 1:2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-8458 | NONE0 | curl 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-53910 | NONE0 | diffutils 1:3.10-4 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-53615 | NONE0 | libblkid1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | libblkid1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libblkid1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | libblkid1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-8458 | NONE0 | libcurl3t64-gnutls 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-8458 | NONE0 | libcurl4t64 8.14.1-2+deb13u4 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-56131 | NONE0 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56408 | NONE0 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat1 2.7.1-2 fixed in 2.8.2-1~deb13u1 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-53615 | NONE0 | liblastlog2-2 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | liblastlog2-2 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | liblastlog2-2 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | liblastlog2-2 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libmount1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | libmount1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libmount1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | libmount1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-57433 | NONE0 | libperl5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-7010 | NONE0 | libperl5.40 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-7017 | NONE0 | libperl5.40 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-53615 | NONE0 | libsmartcols1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | libsmartcols1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libsmartcols1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | libsmartcols1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-11822 | NONE0 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-11824 | NONE0 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-50812 | NONE0 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-50813 | NONE0 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-53615 | NONE0 | libuuid1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | libuuid1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libuuid1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | libuuid1 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | login 1:4.16.0-2+really2.41-5 No fix yet | — | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | login.defs 1:4.17.4-2 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | mount 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | mount 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | mount 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | mount 2.41-5 No fix yet | — | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | passwd 1:4.17.4-2 No fix yet | — | Not Applicable |
| CVE-2026-57433 | NONE0 | perl 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-7010 | NONE0 | perl 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-7017 | NONE0 | perl 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-57433 | NONE0 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-7010 | NONE0 | perl-base 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-7017 | NONE0 | perl-base 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-57433 | NONE0 | perl-modules-5.40 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-7010 | NONE0 | perl-modules-5.40 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-7017 | NONE0 | perl-modules-5.40 5.40.1-6 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| TEMP-0517018-A83CE6 | NONE0 | sysvinit-utils 3.14-4 No fix yet | — | Not Applicable |
| TEMP-0290435-0B57B5 | NONE0 | tar 1.35+dfsg-3.1 No fix yet | — | Not Applicable |
| TEMP-1142904-117334 | NONE0 | unzip 6.0-29 No fix yet | — | Not Applicable |
| TEMP-1142905-081994 | NONE0 | unzip 6.0-29 No fix yet | — | Not Applicable |
| TEMP-1142906-2C6C79 | NONE0 | unzip 6.0-29 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | util-linux 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53612 | NONE0 | util-linux 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | util-linux 2.41-5 No fix yet | — | Not Applicable |
| CVE-2026-53614 | NONE0 | util-linux 2.41-5 No fix yet | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.20.1 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.20.1 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.36.0 No fix yet | — | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.38.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.31.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.23.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.