Last scanned:
AI verdict failed due to an error.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-12151 | NONE0 | node-gyp 13.0.0-r0 fixed in 13.0.0-r1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-12151 | NONE0 | npm 11.17.0-r0 fixed in 11.17.0-r1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-59871 | NONE0 | npm 11.17.0-r0 fixed in 12.0.0-r1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-59873 | NONE0 | npm 11.17.0-r0 fixed in 12.0.0-r1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-59874 | NONE0 | npm 11.17.0-r0 fixed in 12.0.0-r1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-56132 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56403 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56404 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56405 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56406 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56407 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56410 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56411 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-50219 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-56412 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-9679 | NONE0 | node-gyp 13.0.0-r0 fixed in 13.0.0-r1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-9679 | NONE0 | npm 11.17.0-r0 fixed in 11.17.0-r1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-53655 | NONE0 | npm 11.17.0-r0 fixed in 11.17.0-r2 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-58055 | NONE0 | libnghttp2-14 1.69.0-r0 fixed in 1.70.0-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-59875 | NONE0 | npm 11.17.0-r0 fixed in 12.0.0-r1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-56131 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-11525 | NONE0 | node-gyp 13.0.0-r0 fixed in 13.0.0-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-6733 | NONE0 | node-gyp 13.0.0-r0 fixed in 13.0.0-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-11525 | NONE0 | npm 11.17.0-r0 fixed in 11.17.0-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-6733 | NONE0 | npm 11.17.0-r0 fixed in 11.17.0-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-6791 | NONE0 | glibc 2.43-r8 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | glibc-locale-posix 2.43-r8 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | ld-linux 2.43-r8 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | libcrypt1 2.43-r8 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-56408 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat1 2.8.1-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-14257 | NONE0 | npm 11.17.0-r0 fixed in 12.0.1-r2 | 0.3% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.