Vulnerability Reportlitellm/litellm-database:main-v1.83.7-stable

digestsha256:44b7a2ac44889134cd9c52f0fa11a15db8ef45c470e657ab561981195fe31c72

Executive Summary

Last scanned:

Threat Score
100/100DANGEROUS
Reputation
UNVERIFIED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit CVE-2026-40217 to achieve remote code execution via bytecode rewriting, or use CVE-2026-49468 to bypass authentication and gain unauthorized access to management routes. Additionally, privilege escalation flaws (CVE-2026-47101) allow internal users to elevate to proxy_admin. The image has 209 exposed vulnerabilities and a low trust score, making it unsuitable for any production deployment.

Vulnerabilities

Vulnerability Log

278 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-40217HIGH8.8
litellm
1.83.7
fixed in 1.83.10
6.5%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2026-49468HIGH8.33
litellm
1.83.7
fixed in 1.84.0
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-47101HIGH7.48
litellm
1.83.7
fixed in 1.83.14
0.7%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-47102HIGH7.48
litellm
1.83.7
fixed in 1.83.10
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-59822MEDIUM6.97
litellm
1.83.7
fixed in 1.84.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-59197MEDIUM6.97
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libcrypto3
3.6.1-r4
fixed in 3.6.2-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libssl3
3.6.1-r4
fixed in 3.6.2-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-6100MEDIUM6.88
python-3.13
3.13.13-r1
fixed in 3.13.13-r2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-6100MEDIUM6.88
python-3.13-base
3.13.13-r1
fixed in 3.13.13-r2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-59950MEDIUM6.88
mcp
1.26.0
fixed in 1.28.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42311MEDIUM6.63
pillow
12.1.1
fixed in 12.2.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-48710MEDIUM6.5
starlette
0.49.1
fixed in 1.0.1
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-28386MEDIUM6.38
libcrypto3
3.6.1-r4
fixed in 3.6.2-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45186MEDIUM6.38
libexpat1
2.7.5-r1
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-28386MEDIUM6.38
libssl3
3.6.1-r4
fixed in 3.6.2-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-15308MEDIUM6.38
python-3.13
3.13.13-r1
fixed in 3.13.14-r3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7210MEDIUM6.38
python-3.13
3.13.13-r1
fixed in 3.13.14-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-15308MEDIUM6.38
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7210MEDIUM6.38
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-13149MEDIUM6.38
brace-expansion
5.0.4
fixed in 5.0.7, 1.1.16, 2.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33750MEDIUM6.38
brace-expansion
5.0.4
fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45149MEDIUM6.38
brace-expansion
5.0.4
fixed in 5.0.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-13149MEDIUM6.38
brace-expansion
5.0.5
fixed in 5.0.7, 1.1.16, 2.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45149MEDIUM6.38
brace-expansion
5.0.5
fixed in 5.0.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47265MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54273MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54274MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54277MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54278MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-50269MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54275MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54279MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54280MEDIUM6.38
aiohttp
3.13.5
fixed in 3.14.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-40192MEDIUM6.38
pillow
12.1.1
fixed in 12.2.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-54059MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-54060MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-55379MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-55380MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59199MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59200MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59204MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59205MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59198MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59203MEDIUM6.38
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59885MEDIUM6.38
pyasn1
0.6.3
fixed in 0.6.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59886MEDIUM6.38
pyasn1
0.6.3
fixed in 0.6.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59935MEDIUM6.38
pypdf
6.9.2
fixed in 6.14.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59936MEDIUM6.38
pypdf
6.9.2
fixed in 6.14.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59937MEDIUM6.38
pypdf
6.9.2
fixed in 6.14.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42561MEDIUM6.38
python-multipart
0.0.20
fixed in 0.0.27
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-48818MEDIUM6.38
starlette
0.49.1
fixed in 1.1.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-54283MEDIUM6.38
starlette
0.49.1
fixed in 1.3.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44432MEDIUM6.38
urllib3
2.6.3
fixed in 2.7.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-48526MEDIUM6.29
PyJWT
2.12.0
fixed in 2.13.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34993MEDIUM6.21
aiohttp
3.13.5
fixed in 3.14.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54058MEDIUM6.18
pillow
12.1.1
fixed in 12.3.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4786MEDIUM6.03
python-3.13
3.13.13-r1
fixed in 3.13.13-r2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4786MEDIUM6.03
python-3.13-base
3.13.13-r1
fixed in 3.13.13-r2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-28684MEDIUM6.03
python-dotenv
1.0.1
fixed in 1.2.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-24486MEDIUM6
python-multipart
0.0.20
fixed in 0.0.22
2.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-31790MEDIUM5.9
libcrypto3
3.6.1-r4
fixed in 3.6.2-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libssl3
3.6.1-r4
fixed in 3.6.2-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libssl3
3.6.1-r4
fixed in 3.6.3-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-56132MEDIUM5.87
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56404MEDIUM5.87
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.43-r3
fixed in 2.43-r4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-locale-posix
2.43-r3
fixed in 2.43-r4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
ld-linux
2.43-r3
fixed in 2.43-r4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libcrypt1
2.43-r3
fixed in 2.43-r4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-11972MEDIUM5.52
python-3.13
3.13.13-r1
fixed in 3.13.14-r2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-7774MEDIUM5.52
python-3.13
3.13.13-r1
fixed in 3.13.14-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-11972MEDIUM5.52
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-7774MEDIUM5.52
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-48816MEDIUM5.52
@sigstore/verify
3.1.0
fixed in 3.1.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33671MEDIUM5.52
picomatch
4.0.3
fixed in 4.0.4, 3.0.2, 2.3.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41312MEDIUM5.52
pypdf
6.9.2
fixed in 6.10.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41313MEDIUM5.52
pypdf
6.9.2
fixed in 6.10.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41314MEDIUM5.52
pypdf
6.9.2
fixed in 6.10.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-6019MEDIUM5.18
python-3.13
3.13.13-r1
fixed in 3.13.13-r3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6019MEDIUM5.18
python-3.13-base
3.13.13-r1
fixed in 3.13.13-r3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42338MEDIUM5.18
ip-address
10.1.0
fixed in 10.1.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-54276MEDIUM5.18
aiohttp
3.13.5
fixed in 3.14.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-35188MEDIUM5.02
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42765MEDIUM5.02
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50219MEDIUM5.02
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-35188MEDIUM5.02
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42765MEDIUM5.02
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-9669MEDIUM5.02
python-3.13
3.13.13-r1
fixed in 3.13.14-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-9669MEDIUM5.02
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-48815MEDIUM5.02
sigstore
4.1.0
fixed in 4.1.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-48524MEDIUM5.02
PyJWT
2.12.0
fixed in 2.13.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-53539MEDIUM5.02
python-multipart
0.0.20
fixed in 0.0.30
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-40347MEDIUM5.02
python-multipart
0.0.20
fixed in 0.0.26
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
libcrypto3
3.6.1-r4
fixed in 3.6.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
libssl3
3.6.1-r4
fixed in 3.6.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34180MEDIUM5
libssl3
3.6.1-r4
fixed in 3.6.3-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-0864MEDIUM4.67
python-3.13
3.13.13-r1
fixed in 3.13.14-r2
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-0864MEDIUM4.67
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r2
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-67221MEDIUM4.67
orjson
3.10.15
fixed in 3.11.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42308MEDIUM4.67
pillow
12.1.1
fixed in 12.2.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42309MEDIUM4.67
pillow
12.1.1
fixed in 12.2.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42310MEDIUM4.67
pillow
12.1.1
fixed in 12.2.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-48155MEDIUM4.67
pypdf
6.9.2
fixed in 6.12.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-48735MEDIUM4.67
pypdf
6.9.2
fixed in 6.12.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-49461MEDIUM4.67
pypdf
6.9.2
fixed in 6.12.2
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54530MEDIUM4.67
pypdf
6.9.2
fixed in 6.13.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54531MEDIUM4.67
pypdf
6.9.2
fixed in 6.13.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54651MEDIUM4.67
pypdf
6.9.2
fixed in 6.13.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-48758MEDIUM4.59
@sigstore/core
3.1.0
fixed in 3.2.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-48758MEDIUM4.59
@sigstore/core
3.2.0
fixed in 3.2.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-48523MEDIUM4.59
PyJWT
2.12.0
fixed in 2.13.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.43-r3
fixed in 2.43-r6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-locale-posix
2.43-r3
fixed in 2.43-r6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
ld-linux
2.43-r3
fixed in 2.43-r6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libcrypt1
2.43-r3
fixed in 2.43-r6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.6.1-r4
fixed in 3.6.3-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-12781MEDIUM4.5
python-3.13
3.13.13-r1
fixed in 3.13.14-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-3276MEDIUM4.5
python-3.13
3.13.13-r1
fixed in 3.13.14-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4360MEDIUM4.5
python-3.13
3.13.13-r1
fixed in 3.13.14-r2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-12781MEDIUM4.5
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-3276MEDIUM4.5
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4360MEDIUM4.5
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33672MEDIUM4.5
picomatch
4.0.3
fixed in 4.0.4, 3.0.2, 2.3.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-48525MEDIUM4.5
PyJWT
2.12.0
fixed in 2.13.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34073MEDIUM4.5
cryptography
46.0.5
fixed in 46.0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45409MEDIUM4.5
idna
3.11
fixed in 3.15
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-40260MEDIUM4.5
pypdf
6.9.2
fixed in 6.10.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41168MEDIUM4.5
pypdf
6.9.2
fixed in 6.10.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59938MEDIUM4.5
pypdf
6.9.2
fixed in 6.14.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-53537MEDIUM4.5
python-multipart
0.0.20
fixed in 0.0.30
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-48817MEDIUM4.5
starlette
0.49.1
fixed in 1.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54282MEDIUM4.5
starlette
0.49.1
fixed in 1.3.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-49854MEDIUM4.5
tornado
6.5.5
fixed in 6.5.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44431MEDIUM4.5
urllib3
2.6.3
fixed in 2.7.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.43-r3
fixed in 2.43-r7
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.43-r3
fixed in 2.43-r7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-locale-posix
2.43-r3
fixed in 2.43-r7
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-locale-posix
2.43-r3
fixed in 2.43-r7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
ld-linux
2.43-r3
fixed in 2.43-r7
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
ld-linux
2.43-r3
fixed in 2.43-r7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libcrypt1
2.43-r3
fixed in 2.43-r7
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libcrypt1
2.43-r3
fixed in 2.43-r7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59819MEDIUM4.17
litellm
1.83.7
fixed in 1.83.10
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-53538MEDIUM4.08
python-multipart
0.0.20
fixed in 0.0.30
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-39810LOW3.98
busybox
1.37.0-r57
fixed in 1.37.0-r58
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-44432LOW3.82
py3-pip-wheel
26.0.1-r2
fixed in 26.1.2-r1
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-66471LOW3.82
py3.13-pip
26.0.1-r2
fixed in 26.1.1-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-44432LOW3.82
py3.13-pip
26.0.1-r2
fixed in 26.1.2-r1
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-66471LOW3.82
py3.13-pip-base
26.0.1-r2
fixed in 26.1.1-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-44432LOW3.82
py3.13-pip-base
26.0.1-r2
fixed in 26.1.2-r1
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-59873LOW3.82
tar
7.5.11
fixed in 7.5.19
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-59874LOW3.82
tar
7.5.11
fixed in 7.5.18
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-59871LOW3.82
tar
7.5.11
fixed in 7.5.18
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-1502LOW3.82
python-3.13
3.13.13-r1
fixed in 3.13.13-r2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-1502LOW3.82
python-3.13-base
3.13.13-r1
fixed in 3.13.13-r2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-55798LOW3.82
pillow
12.1.1
fixed in 12.3.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34182LOW3.77
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-26157LOW3.57
busybox
1.37.0-r57
fixed in 1.37.0-r58
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-26158LOW3.57
busybox
1.37.0-r57
fixed in 1.37.0-r58
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-48522LOW3.57
PyJWT
2.12.0
fixed in 2.13.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42764LOW3.54
openssl
3.6.2-r2
fixed in 3.6.3-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-4438LOW3.4
glibc
2.43-r3
fixed in 2.43-r4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-locale-posix
2.43-r3
fixed in 2.43-r4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
ld-linux
2.43-r3
fixed in 2.43-r4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libcrypt1
2.43-r3
fixed in 2.43-r4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34181LOW3.21
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW3.15
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41080LOW3.15
libexpat1
2.7.5-r1
fixed in 2.8.0-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-53540LOW3.15
python-multipart
0.0.20
fixed in 0.0.31
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-50181LOW3.11
py3-pip-wheel
26.0.1-r2
fixed in 26.1.1-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-50181LOW3.11
py3.13-pip
26.0.1-r2
fixed in 26.1.1-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-50181LOW3.11
py3.13-pip-base
26.0.1-r2
fixed in 26.1.1-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-35188LOW3.01
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42765LOW3.01
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39892LOW3
cryptography
46.0.5
fixed in 46.0.7
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW3
openssl
3.6.2-r2
fixed in 3.6.3-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-6357LOW2.96
py3-pip-wheel
26.0.1-r2
fixed in 26.1.1-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-6357LOW2.96
py3.13-pip
26.0.1-r2
fixed in 26.1.1-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-6357LOW2.96
py3.13-pip-base
26.0.1-r2
fixed in 26.1.1-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.6.1-r4
fixed in 3.6.3-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.6.2-r2
fixed in 3.6.3-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-25645LOW2.8
py3-pip-wheel
26.0.1-r2
fixed in 26.1.1-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-25645LOW2.8
py3.13-pip
26.0.1-r2
fixed in 26.1.1-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-25645LOW2.8
py3.13-pip-base
26.0.1-r2
fixed in 26.1.1-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-53655LOW2.8
tar
7.5.11
fixed in 7.5.16
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-48156LOW2.8
pypdf
6.9.2
fixed in 6.12.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-49460LOW2.8
pypdf
6.9.2
fixed in 6.12.2
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45445LOW2.78
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.6.1-r4
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.7
libcrypto3
3.6.1-r4
fixed in 3.6.2-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libcrypto3
3.6.1-r4
fixed in 3.6.2-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libcrypto3
3.6.1-r4
fixed in 3.6.2-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
libcrypto3
3.6.1-r4
fixed in 3.6.3-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28388LOW2.7
libssl3
3.6.1-r4
fixed in 3.6.2-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libssl3
3.6.1-r4
fixed in 3.6.2-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libssl3
3.6.1-r4
fixed in 3.6.2-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
libssl3
3.6.1-r4
fixed in 3.6.3-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
openssl
3.6.2-r2
fixed in 3.6.3-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-21441LOW2.7
py3-pip-wheel
26.0.1-r2
fixed in 26.1.1-r0
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-21441LOW2.7
py3.13-pip
26.0.1-r2
fixed in 26.1.1-r0
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-21441LOW2.7
py3.13-pip-base
26.0.1-r2
fixed in 26.1.1-r0
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.6.2-r2
fixed in 3.6.3-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-44431LOW2.7
py3-pip-wheel
26.0.1-r2
fixed in 26.1.2-r1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45409LOW2.7
py3-pip-wheel
26.0.1-r2
fixed in 26.1.2-r1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-44431LOW2.7
py3.13-pip
26.0.1-r2
fixed in 26.1.2-r1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45409LOW2.7
py3.13-pip
26.0.1-r2
fixed in 26.1.2-r1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-44431LOW2.7
py3.13-pip-base
26.0.1-r2
fixed in 26.1.2-r1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45409LOW2.7
py3.13-pip-base
26.0.1-r2
fixed in 26.1.2-r1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-59875LOW2.7
tar
7.5.11
fixed in 7.5.17
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3219LOW2.55
py3-pip-wheel
26.0.1-r2
fixed in 26.1.1-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3219LOW2.55
py3.13-pip
26.0.1-r2
fixed in 26.1.1-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3219LOW2.55
py3.13-pip-base
26.0.1-r2
fixed in 26.1.1-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-66418LOW2.29
py3-pip-wheel
26.0.1-r2
fixed in 26.1.1-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-66471LOW2.29
py3-pip-wheel
26.0.1-r2
fixed in 26.1.1-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-66418LOW2.29
py3.13-pip
26.0.1-r2
fixed in 26.1.1-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-66418LOW2.29
py3.13-pip-base
26.0.1-r2
fixed in 26.1.1-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.6.2-r2
fixed in 3.6.3-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6791NONE0
glibc
2.43-r3
fixed in 2.43-r10
Not Applicable
CVE-2026-6791NONE0
glibc-locale-posix
2.43-r3
fixed in 2.43-r10
Not Applicable
CVE-2026-6791NONE0
ld-linux
2.43-r3
fixed in 2.43-r10
Not Applicable
CVE-2026-6791NONE0
libcrypt1
2.43-r3
fixed in 2.43-r10
Not Applicable
CVE-2026-56131NONE0
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56407NONE0
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56408NONE0
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat1
2.7.5-r1
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-11940NONE0
python-3.13
3.13.13-r1
fixed in 3.13.14-r2
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python-3.13
3.13.13-r1
fixed in 3.13.13-r6
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11940NONE0
python-3.13-base
3.13.13-r1
fixed in 3.13.14-r2
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python-3.13-base
3.13.13-r1
fixed in 3.13.13-r6
0.5%
Theoretical Threat
Not Applicable
CVE-2026-14257NONE0
brace-expansion
5.0.4
fixed in 5.0.8
0.3%
Theoretical Threat
Not Applicable
CVE-2026-14257NONE0
brace-expansion
5.0.5
fixed in 5.0.8
0.3%
Theoretical Threat
Not Applicable
GHSA-r292-9mhp-454mNONE0
tar
7.5.11
fixed in 7.5.21
Not Applicable
GHSA-537c-gmf6-5ccfNONE0
cryptography
46.0.5
fixed in 48.0.1
Not Applicable
CVE-2026-50271NONE0
ddtrace
2.19.0
fixed in 4.8.2
0.4%
Theoretical Threat
Not Applicable
CVE-2025-14546NONE0
fastapi-sso
0.16.0
fixed in 0.19.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-52869NONE0
mcp
1.26.0
fixed in 1.27.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-52870NONE0
mcp
1.26.0
fixed in 1.27.2
0.2%
Theoretical Threat
Not Applicable
GHSA-4xgf-cpjx-pc3jNONE0
pydantic-settings
2.13.1
fixed in 2.14.2
Not Applicable
GHSA-jm82-fx9c-mx94NONE0
pypdf
6.9.2
fixed in 6.13.3
Not Applicable
GHSA-98x5-vq43-vc5pNONE0
semantic-router
0.1.11
fixed in 0.1.15
Not Applicable
CVE-2026-49853NONE0
tornado
6.5.5
fixed in 6.5.6
0.4%
Theoretical Threat
Not Applicable
CVE-2026-49855NONE0
tornado
6.5.5
fixed in 6.5.6
0.6%
Theoretical Threat
Not Applicable
GHSA-pw6j-qg29-8w7fNONE0
tornado
6.5.5
fixed in 6.5.7
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.