Vulnerability Reportlibrary/traefik:3.7.12

library/traefik:v3.7.12library/traefik:3.7.12
digestsha256:9c2a54d87f76f5c2f5f2682c68394af92fb12c0a2686798d6462a3f84bd78eaf

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. It is an official Docker Hub image pinned by digest, with a trusted reputation score of 100 and a pre-calculated threat score of 0. Although INPUT 3 reports 6 exposed-surface findings and 20 post-exploit-only findings, none reach severity 6.0: the exposed maximum is 0.0 and the post-exploit maximum is 2.7. No CVE IDs are present in INPUT 4 or INPUT 5, so there are no specific listed findings to remediate from those top-findings inputs. Continue normal production hardening and keep the digest pin.

Vulnerabilities

Vulnerability Log

26 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-18798LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-14456LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63072LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63072LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-56855LOW1.91
golang.org/x/crypto
v0.55.0
fixed in 0.56.0
Post-Exploit
CVE-2026-78662LOW1.91
golang.org/x/crypto
v0.55.0
fixed in 0.56.0
Post-Exploit
CVE-2026-63073LOW1.81
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-63073LOW1.81
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-75803NONE0
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-75803NONE0
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.55.0
No fix yet
Not Applicable
CVE-2026-84304NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.83.1
0.4%
Theoretical Threat
Not Applicable
CVE-2026-84445NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e
Not Applicable
CVE-2026-84303NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.83.1
0.3%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.