Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit CVE-2026-40217 to achieve remote code execution via bytecode rewriting, or use CVE-2026-49468 to bypass authentication and gain unauthorized access to management routes. Additionally, privilege escalation flaws (CVE-2026-47101) allow internal users to elevate to proxy_admin. The image has 209 exposed vulnerabilities and a low trust score, making it unsuitable for any production deployment.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-40217 | HIGH8.8 | litellm 1.83.7 fixed in 1.83.10 | 6.5% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2026-49468 | HIGH8.33 | litellm 1.83.7 fixed in 1.84.0 | 0.6% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-47101 | HIGH7.48 | litellm 1.83.7 fixed in 1.83.14 | 0.7% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-47102 | HIGH7.48 | litellm 1.83.7 fixed in 1.83.10 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-59822 | MEDIUM6.97 | litellm 1.83.7 fixed in 1.84.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59197 | MEDIUM6.97 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libcrypto3 3.6.1-r4 fixed in 3.6.2-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl3 3.6.1-r4 fixed in 3.6.2-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-6100 | MEDIUM6.88 | python-3.13 3.13.13-r1 fixed in 3.13.13-r2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-6100 | MEDIUM6.88 | python-3.13-base 3.13.13-r1 fixed in 3.13.13-r2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-59950 | MEDIUM6.88 | mcp 1.26.0 fixed in 1.28.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42311 | MEDIUM6.63 | pillow 12.1.1 fixed in 12.2.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-48710 | MEDIUM6.5 | starlette 0.49.1 fixed in 1.0.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28386 | MEDIUM6.38 | libcrypto3 3.6.1-r4 fixed in 3.6.2-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45186 | MEDIUM6.38 | libexpat1 2.7.5-r1 fixed in 2.8.1-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-28386 | MEDIUM6.38 | libssl3 3.6.1-r4 fixed in 3.6.2-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-15308 | MEDIUM6.38 | python-3.13 3.13.13-r1 fixed in 3.13.14-r3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-7210 | MEDIUM6.38 | python-3.13 3.13.13-r1 fixed in 3.13.14-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-15308 | MEDIUM6.38 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-7210 | MEDIUM6.38 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-13149 | MEDIUM6.38 | brace-expansion 5.0.4 fixed in 5.0.7, 1.1.16, 2.1.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33750 | MEDIUM6.38 | brace-expansion 5.0.4 fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45149 | MEDIUM6.38 | brace-expansion 5.0.4 fixed in 5.0.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-13149 | MEDIUM6.38 | brace-expansion 5.0.5 fixed in 5.0.7, 1.1.16, 2.1.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45149 | MEDIUM6.38 | brace-expansion 5.0.5 fixed in 5.0.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-47265 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54273 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54274 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54277 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54278 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-50269 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54275 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54279 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54280 | MEDIUM6.38 | aiohttp 3.13.5 fixed in 3.14.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-40192 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.2.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-54059 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54060 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55379 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55380 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59199 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59200 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59204 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59205 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59198 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59203 | MEDIUM6.38 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59885 | MEDIUM6.38 | pyasn1 0.6.3 fixed in 0.6.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59886 | MEDIUM6.38 | pyasn1 0.6.3 fixed in 0.6.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59935 | MEDIUM6.38 | pypdf 6.9.2 fixed in 6.14.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59936 | MEDIUM6.38 | pypdf 6.9.2 fixed in 6.14.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59937 | MEDIUM6.38 | pypdf 6.9.2 fixed in 6.14.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42561 | MEDIUM6.38 | python-multipart 0.0.20 fixed in 0.0.27 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-48818 | MEDIUM6.38 | starlette 0.49.1 fixed in 1.1.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54283 | MEDIUM6.38 | starlette 0.49.1 fixed in 1.3.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-44432 | MEDIUM6.38 | urllib3 2.6.3 fixed in 2.7.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48526 | MEDIUM6.29 | PyJWT 2.12.0 fixed in 2.13.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34993 | MEDIUM6.21 | aiohttp 3.13.5 fixed in 3.14.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54058 | MEDIUM6.18 | pillow 12.1.1 fixed in 12.3.0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-4786 | MEDIUM6.03 | python-3.13 3.13.13-r1 fixed in 3.13.13-r2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4786 | MEDIUM6.03 | python-3.13-base 3.13.13-r1 fixed in 3.13.13-r2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-28684 | MEDIUM6.03 | python-dotenv 1.0.1 fixed in 1.2.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-24486 | MEDIUM6 | python-multipart 0.0.20 fixed in 0.0.22 | 2.2% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.6.1-r4 fixed in 3.6.2-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.6.1-r4 fixed in 3.6.2-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-56132 | MEDIUM5.87 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56404 | MEDIUM5.87 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | glibc 2.43-r3 fixed in 2.43-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | glibc-locale-posix 2.43-r3 fixed in 2.43-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | ld-linux 2.43-r3 fixed in 2.43-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | libcrypt1 2.43-r3 fixed in 2.43-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11972 | MEDIUM5.52 | python-3.13 3.13.13-r1 fixed in 3.13.14-r2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-7774 | MEDIUM5.52 | python-3.13 3.13.13-r1 fixed in 3.13.14-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-11972 | MEDIUM5.52 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-7774 | MEDIUM5.52 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-48816 | MEDIUM5.52 | @sigstore/verify 3.1.0 fixed in 3.1.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33671 | MEDIUM5.52 | picomatch 4.0.3 fixed in 4.0.4, 3.0.2, 2.3.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-41312 | MEDIUM5.52 | pypdf 6.9.2 fixed in 6.10.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-41313 | MEDIUM5.52 | pypdf 6.9.2 fixed in 6.10.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-41314 | MEDIUM5.52 | pypdf 6.9.2 fixed in 6.10.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-6019 | MEDIUM5.18 | python-3.13 3.13.13-r1 fixed in 3.13.13-r3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6019 | MEDIUM5.18 | python-3.13-base 3.13.13-r1 fixed in 3.13.13-r3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42338 | MEDIUM5.18 | ip-address 10.1.0 fixed in 10.1.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-54276 | MEDIUM5.18 | aiohttp 3.13.5 fixed in 3.14.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-35188 | MEDIUM5.02 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42765 | MEDIUM5.02 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-35188 | MEDIUM5.02 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42765 | MEDIUM5.02 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-9669 | MEDIUM5.02 | python-3.13 3.13.13-r1 fixed in 3.13.14-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-9669 | MEDIUM5.02 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48815 | MEDIUM5.02 | sigstore 4.1.0 fixed in 4.1.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-48524 | MEDIUM5.02 | PyJWT 2.12.0 fixed in 2.13.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-53539 | MEDIUM5.02 | python-multipart 0.0.20 fixed in 0.0.30 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-40347 | MEDIUM5.02 | python-multipart 0.0.20 fixed in 0.0.26 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | MEDIUM5 | libcrypto3 3.6.1-r4 fixed in 3.6.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | MEDIUM5 | libssl3 3.6.1-r4 fixed in 3.6.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-0864 | MEDIUM4.67 | python-3.13 3.13.13-r1 fixed in 3.13.14-r2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-0864 | MEDIUM4.67 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-67221 | MEDIUM4.67 | orjson 3.10.15 fixed in 3.11.6 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42308 | MEDIUM4.67 | pillow 12.1.1 fixed in 12.2.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42309 | MEDIUM4.67 | pillow 12.1.1 fixed in 12.2.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42310 | MEDIUM4.67 | pillow 12.1.1 fixed in 12.2.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-48155 | MEDIUM4.67 | pypdf 6.9.2 fixed in 6.12.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-48735 | MEDIUM4.67 | pypdf 6.9.2 fixed in 6.12.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-49461 | MEDIUM4.67 | pypdf 6.9.2 fixed in 6.12.2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54530 | MEDIUM4.67 | pypdf 6.9.2 fixed in 6.13.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54531 | MEDIUM4.67 | pypdf 6.9.2 fixed in 6.13.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54651 | MEDIUM4.67 | pypdf 6.9.2 fixed in 6.13.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-48758 | MEDIUM4.59 | @sigstore/core 3.1.0 fixed in 3.2.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-48758 | MEDIUM4.59 | @sigstore/core 3.2.0 fixed in 3.2.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-48523 | MEDIUM4.59 | PyJWT 2.12.0 fixed in 2.13.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | glibc 2.43-r3 fixed in 2.43-r6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | glibc-locale-posix 2.43-r3 fixed in 2.43-r6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | ld-linux 2.43-r3 fixed in 2.43-r6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libcrypt1 2.43-r3 fixed in 2.43-r6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-12781 | MEDIUM4.5 | python-3.13 3.13.13-r1 fixed in 3.13.14-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-3276 | MEDIUM4.5 | python-3.13 3.13.13-r1 fixed in 3.13.14-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-4360 | MEDIUM4.5 | python-3.13 3.13.13-r1 fixed in 3.13.14-r2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-12781 | MEDIUM4.5 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-3276 | MEDIUM4.5 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-4360 | MEDIUM4.5 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33672 | MEDIUM4.5 | picomatch 4.0.3 fixed in 4.0.4, 3.0.2, 2.3.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48525 | MEDIUM4.5 | PyJWT 2.12.0 fixed in 2.13.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34073 | MEDIUM4.5 | cryptography 46.0.5 fixed in 46.0.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45409 | MEDIUM4.5 | idna 3.11 fixed in 3.15 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-40260 | MEDIUM4.5 | pypdf 6.9.2 fixed in 6.10.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-41168 | MEDIUM4.5 | pypdf 6.9.2 fixed in 6.10.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59938 | MEDIUM4.5 | pypdf 6.9.2 fixed in 6.14.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-53537 | MEDIUM4.5 | python-multipart 0.0.20 fixed in 0.0.30 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-48817 | MEDIUM4.5 | starlette 0.49.1 fixed in 1.1.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54282 | MEDIUM4.5 | starlette 0.49.1 fixed in 1.3.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-49854 | MEDIUM4.5 | tornado 6.5.5 fixed in 6.5.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-44431 | MEDIUM4.5 | urllib3 2.6.3 fixed in 2.7.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | glibc 2.43-r3 fixed in 2.43-r7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | glibc 2.43-r3 fixed in 2.43-r7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | glibc-locale-posix 2.43-r3 fixed in 2.43-r7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | glibc-locale-posix 2.43-r3 fixed in 2.43-r7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | ld-linux 2.43-r3 fixed in 2.43-r7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | ld-linux 2.43-r3 fixed in 2.43-r7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libcrypt1 2.43-r3 fixed in 2.43-r7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libcrypt1 2.43-r3 fixed in 2.43-r7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59819 | MEDIUM4.17 | litellm 1.83.7 fixed in 1.83.10 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-53538 | MEDIUM4.08 | python-multipart 0.0.20 fixed in 0.0.30 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-39810 | LOW3.98 | busybox 1.37.0-r57 fixed in 1.37.0-r58 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-44432 | LOW3.82 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.2-r1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-66471 | LOW3.82 | py3.13-pip 26.0.1-r2 fixed in 26.1.1-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-44432 | LOW3.82 | py3.13-pip 26.0.1-r2 fixed in 26.1.2-r1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-66471 | LOW3.82 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.1-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-44432 | LOW3.82 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.2-r1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-59873 | LOW3.82 | tar 7.5.11 fixed in 7.5.19 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59874 | LOW3.82 | tar 7.5.11 fixed in 7.5.18 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59871 | LOW3.82 | tar 7.5.11 fixed in 7.5.18 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-1502 | LOW3.82 | python-3.13 3.13.13-r1 fixed in 3.13.13-r2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-1502 | LOW3.82 | python-3.13-base 3.13.13-r1 fixed in 3.13.13-r2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-55798 | LOW3.82 | pillow 12.1.1 fixed in 12.3.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | LOW3.77 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-26157 | LOW3.57 | busybox 1.37.0-r57 fixed in 1.37.0-r58 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-26158 | LOW3.57 | busybox 1.37.0-r57 fixed in 1.37.0-r58 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-48522 | LOW3.57 | PyJWT 2.12.0 fixed in 2.13.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42764 | LOW3.54 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-4438 | LOW3.4 | glibc 2.43-r3 fixed in 2.43-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | glibc-locale-posix 2.43-r3 fixed in 2.43-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | ld-linux 2.43-r3 fixed in 2.43-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | libcrypt1 2.43-r3 fixed in 2.43-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | LOW3.21 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42768 | LOW3.21 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW3.15 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-41080 | LOW3.15 | libexpat1 2.7.5-r1 fixed in 2.8.0-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-53540 | LOW3.15 | python-multipart 0.0.20 fixed in 0.0.31 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-50181 | LOW3.11 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.1-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-50181 | LOW3.11 | py3.13-pip 26.0.1-r2 fixed in 26.1.1-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-50181 | LOW3.11 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.1-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-35188 | LOW3.01 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-42765 | LOW3.01 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW3.01 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-39892 | LOW3 | cryptography 46.0.5 fixed in 46.0.7 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-6357 | LOW2.96 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.1-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-6357 | LOW2.96 | py3.13-pip 26.0.1-r2 fixed in 26.1.1-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-6357 | LOW2.96 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.1-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-25645 | LOW2.8 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.1-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-25645 | LOW2.8 | py3.13-pip 26.0.1-r2 fixed in 26.1.1-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-25645 | LOW2.8 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.1-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-53655 | LOW2.8 | tar 7.5.11 fixed in 7.5.16 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-48156 | LOW2.8 | pypdf 6.9.2 fixed in 6.12.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-49460 | LOW2.8 | pypdf 6.9.2 fixed in 6.12.2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45445 | LOW2.78 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libcrypto3 3.6.1-r4 fixed in 3.6.2-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libcrypto3 3.6.1-r4 fixed in 3.6.2-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | libcrypto3 3.6.1-r4 fixed in 3.6.2-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | libcrypto3 3.6.1-r4 fixed in 3.6.3-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libssl3 3.6.1-r4 fixed in 3.6.2-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libssl3 3.6.1-r4 fixed in 3.6.2-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | libssl3 3.6.1-r4 fixed in 3.6.2-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | libssl3 3.6.1-r4 fixed in 3.6.3-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-21441 | LOW2.7 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.1-r0 | 2.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-21441 | LOW2.7 | py3.13-pip 26.0.1-r2 fixed in 26.1.1-r0 | 2.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-21441 | LOW2.7 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.1-r0 | 2.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-42767 | LOW2.7 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-44431 | LOW2.7 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.2-r1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-45409 | LOW2.7 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.2-r1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-44431 | LOW2.7 | py3.13-pip 26.0.1-r2 fixed in 26.1.2-r1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-45409 | LOW2.7 | py3.13-pip 26.0.1-r2 fixed in 26.1.2-r1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-44431 | LOW2.7 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.2-r1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-45409 | LOW2.7 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.2-r1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59875 | LOW2.7 | tar 7.5.11 fixed in 7.5.17 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-3219 | LOW2.55 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.1-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3219 | LOW2.55 | py3.13-pip 26.0.1-r2 fixed in 26.1.1-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3219 | LOW2.55 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.1-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-66418 | LOW2.29 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.1-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-66471 | LOW2.29 | py3-pip-wheel 26.0.1-r2 fixed in 26.1.1-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-66418 | LOW2.29 | py3.13-pip 26.0.1-r2 fixed in 26.1.1-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-66418 | LOW2.29 | py3.13-pip-base 26.0.1-r2 fixed in 26.1.1-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.6.2-r2 fixed in 3.6.3-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6791 | NONE0 | glibc 2.43-r3 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | glibc-locale-posix 2.43-r3 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | ld-linux 2.43-r3 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-6791 | NONE0 | libcrypt1 2.43-r3 fixed in 2.43-r10 | — | Not Applicable |
| CVE-2026-56131 | NONE0 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56407 | NONE0 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56408 | NONE0 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat1 2.7.5-r1 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-11940 | NONE0 | python-3.13 3.13.13-r1 fixed in 3.13.14-r2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-8328 | NONE0 | python-3.13 3.13.13-r1 fixed in 3.13.13-r6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-11940 | NONE0 | python-3.13-base 3.13.13-r1 fixed in 3.13.14-r2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-8328 | NONE0 | python-3.13-base 3.13.13-r1 fixed in 3.13.13-r6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-14257 | NONE0 | brace-expansion 5.0.4 fixed in 5.0.8 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-14257 | NONE0 | brace-expansion 5.0.5 fixed in 5.0.8 | 0.3% Theoretical Threat | Not Applicable |
| GHSA-r292-9mhp-454m | NONE0 | tar 7.5.11 fixed in 7.5.21 | — | Not Applicable |
| GHSA-537c-gmf6-5ccf | NONE0 | cryptography 46.0.5 fixed in 48.0.1 | — | Not Applicable |
| CVE-2026-50271 | NONE0 | ddtrace 2.19.0 fixed in 4.8.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-14546 | NONE0 | fastapi-sso 0.16.0 fixed in 0.19.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-52869 | NONE0 | mcp 1.26.0 fixed in 1.27.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-52870 | NONE0 | mcp 1.26.0 fixed in 1.27.2 | 0.2% Theoretical Threat | Not Applicable |
| GHSA-4xgf-cpjx-pc3j | NONE0 | pydantic-settings 2.13.1 fixed in 2.14.2 | — | Not Applicable |
| GHSA-jm82-fx9c-mx94 | NONE0 | pypdf 6.9.2 fixed in 6.13.3 | — | Not Applicable |
| GHSA-98x5-vq43-vc5p | NONE0 | semantic-router 0.1.11 fixed in 0.1.15 | — | Not Applicable |
| CVE-2026-49853 | NONE0 | tornado 6.5.5 fixed in 6.5.6 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-49855 | NONE0 | tornado 6.5.5 fixed in 6.5.6 | 0.6% Theoretical Threat | Not Applicable |
| GHSA-pw6j-qg29-8w7f | NONE0 | tornado 6.5.5 fixed in 6.5.7 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.