Vulnerability Reportkong:3.0.2

kong:3.0.2-alpinekong:3.0.2kong:3.0-alpinekong:3.0
digestsha256:3b917766bfdf5266dac28dfc38961a5ba049b2256671b3a5439346fef7b99eb1

Executive Summary

Last scanned:

Threat Score
0/100NEEDS ATTENTION
Reputation
TRUSTED

AI verdict failed due to an error.

Vulnerabilities

Vulnerability Log

4 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2023-42366LOW2.8
busybox
1.35.0-r17
fixed in 1.35.0-r18
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-26519NONE0
musl
1.2.3-r3
fixed in 1.2.3-r4
0.3%
Theoretical Threat
Not Applicable
CVE-2025-26519NONE0
musl-utils
1.2.3-r3
fixed in 1.2.3-r4
0.3%
Theoretical Threat
Not Applicable
CVE-2023-42366NONE0
ssl_client
1.35.0-r17
fixed in 1.35.0-r18
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.