Last scanned:
This image is safe for production use. It contains 24 post-exploit vulnerabilities, but none exceed low severity (max 4.06). The only notable finding, CVE-2022-37434 in zlib, has low contextual importance because memcached does not use the vulnerable inflateGetHeader function in standard operation. No exposed surface vulnerabilities exist, and the image is officially published and pinned by digest, ensuring supply chain security.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-26519 | MEDIUM5.95 | musl 1.2.3-r0 fixed in 1.2.3-r4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2022-37434 | MEDIUM4.06 | zlib 1.2.12-r1 fixed in 1.2.12-r2 | 15.9% High Exploitation Risk | Post-Exploit |
| CVE-2025-26519 | LOW3.57 | musl-utils 1.2.3-r0 fixed in 1.2.3-r4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-0286 | LOW3.46 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1t-r0 | 59.5% Actively Exploited | Post-Exploit |
| CVE-2023-0286 | LOW3.46 | libssl1.1 1.1.1q-r0 fixed in 1.1.1t-r0 | 59.5% Actively Exploited | Post-Exploit |
| CVE-2022-4450 | LOW3.1 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1t-r0 | 20.4% High Exploitation Risk | Post-Exploit |
| CVE-2022-4450 | LOW3.1 | libssl1.1 1.1.1q-r0 fixed in 1.1.1t-r0 | 20.4% High Exploitation Risk | Post-Exploit |
| CVE-2023-2650 | LOW3.04 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1u-r0 | 73.5% Actively Exploited | Post-Exploit |
| CVE-2023-2650 | LOW3.04 | libssl1.1 1.1.1q-r0 fixed in 1.1.1u-r0 | 73.5% Actively Exploited | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | busybox 1.35.0-r15 fixed in 1.35.0-r18 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | ssl_client 1.35.0-r15 fixed in 1.35.0-r18 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-0215 | LOW2.7 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1t-r0 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0464 | LOW2.7 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1t-r1 | 3.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0215 | LOW2.7 | libssl1.1 1.1.1q-r0 fixed in 1.1.1t-r0 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0464 | LOW2.7 | libssl1.1 1.1.1q-r0 fixed in 1.1.1t-r1 | 3.7% Low-Moderate Risk | Post-Exploit |
| CVE-2022-4304 | LOW2.44 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1t-r0 | 16.2% High Exploitation Risk | Post-Exploit |
| CVE-2022-4304 | LOW2.44 | libssl1.1 1.1.1q-r0 fixed in 1.1.1t-r0 | 16.2% High Exploitation Risk | Post-Exploit |
| CVE-2023-0465 | LOW1.91 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1t-r2 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-3446 | LOW1.91 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1u-r2 | 5.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-3817 | LOW1.91 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1v-r0 | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-5678 | LOW1.91 | libcrypto1.1 1.1.1q-r0 fixed in 1.1.1w-r1 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0465 | LOW1.91 | libssl1.1 1.1.1q-r0 fixed in 1.1.1t-r2 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-3446 | LOW1.91 | libssl1.1 1.1.1q-r0 fixed in 1.1.1u-r2 | 5.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-3817 | LOW1.91 | libssl1.1 1.1.1q-r0 fixed in 1.1.1v-r0 | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-5678 | LOW1.91 | libssl1.1 1.1.1q-r0 fixed in 1.1.1w-r1 | 4.5% Low-Moderate Risk | Post-Exploit |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.