Vulnerability Reportlibrary/traefik:3.7.11

library/traefik:v3.7.11
digestsha256:5203c3f39ca70de6790d964624e042463ffbd57715bc82be155cf224c0dd5144

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. It is an official Docker image pinned by digest, which makes the deployed artifact immutable and traceable to a trusted publisher. The scan does record findings - 6 exposed-surface entries and 20 post-exploit-only entries - so this is not a clean-slate result, but the exposed entries top out at severity 0.0 and the post-exploit-only entries at 2.7, which is well below the level that would change the verdict. No specific high-impact CVE IDs appeared among the top findings, so there is nothing here that warrants blocking or delaying a production rollout. Standard practice of rebuilding regularly to pick up upstream base-image updates remains advisable.

Vulnerabilities

Vulnerability Log

26 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-18798LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-14456LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63072LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63072LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-56855LOW1.91
golang.org/x/crypto
v0.55.0
fixed in 0.56.0
Post-Exploit
CVE-2026-78662LOW1.91
golang.org/x/crypto
v0.55.0
fixed in 0.56.0
Post-Exploit
CVE-2026-63073LOW1.81
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-63073LOW1.81
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-75803NONE0
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-75803NONE0
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.55.0
No fix yet
Not Applicable
CVE-2026-84304NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.83.1
0.4%
Theoretical Threat
Not Applicable
CVE-2026-84445NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e
Not Applicable
CVE-2026-84303NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.83.1
0.3%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.