Vulnerability Reportminio/minio:RELEASE.2024-06-13T22-53-53Z

minio/minio:RELEASE.2024-06-13T22-53-53Z
digestsha256:c7175077d39a8cc10c9fd611cdcc68b6a5b365793e9ac6f4198ffff1ef0fe555

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could cause memory exhaustion denial of service via crafted HTTP requests or bypass gRPC authorization controls if path-based policies are in place. Note that CVE-2026-33186 only affects configurations using gRPC authorization interceptors; disabling gRPC or using network segmentation can reduce risk. Additionally, CVE-2025-61726 requires no special configuration and is readily exploitable. Given the high volume of additional vulnerabilities, thorough assessment is advised.

  1. Vulnerability scan
    Full CVE sweep across OS packages and app dependencies
  2. Exploitability check
    CVEs ranked by exploit probability (EPSS) and matched against CISA KEV
  3. Result analysis
    Plain-English summary of what actually matters — and why
  1. Hardening recommendations
    A hardened build plan — patch, remove unused packages, lock down the runtime — with parity tests proving nothing broke

This report ran the first 3 stages — get the full report to unlock the rest.

Vulnerabilities

Vulnerability Log

198 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-61726HIGH7.5
stdlib
v1.22.4
fixed in 1.24.12, 1.25.6
1.9%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2026-33186HIGH7.28
google.golang.org/grpc
v1.63.2
fixed in 1.79.3
1.6%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-33186HIGH7.28
google.golang.org/grpc
v1.64.0
fixed in 1.79.3
1.6%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-68121MEDIUM6.8
stdlib
v1.22.4
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt/v4
v4.5.0
fixed in 4.5.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-22869MEDIUM6.38
golang.org/x/crypto
v0.23.0
fixed in 0.35.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-47913MEDIUM6.38
golang.org/x/crypto
v0.23.0
fixed in 0.43.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-45338MEDIUM6.38
golang.org/x/net
v0.25.0
fixed in 0.33.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.25.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM6.38
stdlib
v1.22.4
fixed in 1.24.11, 1.25.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.8, 1.26.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.22.4
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.22.4
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32285MEDIUM6.38
github.com/buger/jsonparser
v1.1.1
fixed in 1.1.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-32934MEDIUM6.38
github.com/coredns/coredns
v1.11.3
fixed in 1.14.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-32936MEDIUM6.38
github.com/coredns/coredns
v1.11.3
fixed in 1.14.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-33190MEDIUM6.38
github.com/coredns/coredns
v1.11.3
fixed in 1.14.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33489MEDIUM6.38
github.com/coredns/coredns
v1.11.3
fixed in 1.14.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68151MEDIUM6.38
github.com/coredns/coredns
v1.11.3
fixed in 1.14.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34986MEDIUM6.38
github.com/go-jose/go-jose/v4
v4.0.2
fixed in 4.1.4
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-27144MEDIUM6.38
github.com/go-jose/go-jose/v4
v4.0.2
fixed in 4.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22869MEDIUM6.38
golang.org/x/crypto
v0.24.0
fixed in 0.35.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-47913MEDIUM6.38
golang.org/x/crypto
v0.24.0
fixed in 0.43.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-45338MEDIUM6.38
golang.org/x/net
v0.26.0
fixed in 0.33.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.26.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-22868MEDIUM6.38
golang.org/x/oauth2
v0.21.0
fixed in 0.27.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-54369MEDIUM6.03
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-4802MEDIUM5.95
glibc
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.19
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-4802MEDIUM5.95
glibc-common
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.19
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-4802MEDIUM5.95
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.19
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4878MEDIUM5.95
libcap
2.48-9.el9_2
fixed in 2.48-10.el9_8.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47907MEDIUM5.95
stdlib
v1.22.4
fixed in 1.23.12, 1.24.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-24791MEDIUM5.9
stdlib
v1.22.4
fixed in 1.21.12, 1.22.5
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2024-34158MEDIUM5.9
stdlib
v1.22.4
fixed in 1.22.7, 1.23.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-4673MEDIUM5.78
stdlib
v1.22.4
fixed in 1.23.10, 1.24.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.25.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.26.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4437MEDIUM5.52
glibc
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-common
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-common
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22872MEDIUM5.52
golang.org/x/net
v0.25.0
fixed in 0.38.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.25.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47906MEDIUM5.52
stdlib
v1.22.4
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.22.4
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.22.4
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22872MEDIUM5.52
golang.org/x/net
v0.26.0
fixed in 0.38.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.26.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.22.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54371MEDIUM5.35
libattr
2.5.1-3.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-26017MEDIUM5.35
github.com/coredns/coredns
v1.11.3
fixed in 1.14.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47950MEDIUM5.3
github.com/coredns/coredns
v1.11.3
fixed in 1.12.2
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.25.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.22.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.26.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15281MEDIUM5.02
glibc
2.34-100.el9_4.2
fixed in 2.34-231.el9_7.10
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-34155MEDIUM5.02
stdlib
v1.22.4
fixed in 1.22.7, 1.23.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-45336MEDIUM5.02
stdlib
v1.22.4
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-5702MEDIUM4.76
glibc
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.20
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-5702MEDIUM4.76
glibc-common
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.20
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-5702MEDIUM4.76
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.20
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc
2.34-100.el9_4.2
fixed in 2.34-125.el9_5.8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc-common
2.34-100.el9_4.2
fixed in 2.34-125.el9_5.8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-125.el9_5.8
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libgcc
11.4.1-3.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc
11.4.1-3.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.22.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.25.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-22871MEDIUM4.59
stdlib
v1.22.4
fixed in 1.23.8, 1.24.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.22.4
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.22.4
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.22.4
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58063MEDIUM4.59
github.com/coredns/coredns
v1.11.3
fixed in 1.12.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.26.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-0915MEDIUM4.5
glibc
2.34-100.el9_4.2
fixed in 2.34-231.el9_7.10
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.23.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.23.0
fixed in 0.45.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.25.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.25.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22866MEDIUM4.5
stdlib
v1.22.4
fixed in 1.22.12, 1.23.6, 1.24.0-rc.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22873MEDIUM4.5
stdlib
v1.22.4
fixed in 1.23.9, 1.24.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.22.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.22.4
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.22.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-10543MEDIUM4.5
github.com/eclipse/paho.mqtt.golang
v1.4.3
fixed in 1.5.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.24.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.24.0
fixed in 0.45.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.26.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.26.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.34-100.el9_4.2
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.34-100.el9_4.2
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
golang.org/x/net
v0.25.0
fixed in 0.36.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
stdlib
v1.22.4
fixed in 1.23.7, 1.24.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
golang.org/x/net
v0.26.0
fixed in 0.36.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
glibc
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.23
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
glibc-common
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.23
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-168.el9_6.23
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-45341LOW3.57
stdlib
v1.22.4
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-common
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-minimal-langpack
2.34-100.el9_4.2
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-26958LOW3.15
filippo.io/edwards25519
v1.1.0
fixed in 1.1.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-56391LOW3.11
coreutils-single
8.32-35.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-35579LOW3
github.com/coredns/coredns
v1.11.3
fixed in 1.14.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2024-45337LOW2.95
golang.org/x/crypto
v0.23.0
fixed in 0.31.0
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2024-45337LOW2.95
golang.org/x/crypto
v0.24.0
fixed in 0.31.0
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2020-11023LOW2.86
libgcc
11.4.1-3.el9
fixed in 11.5.0-5.el9_5
83.8%
Actively Exploited
Post-Exploit
CVE-2022-41409LOW2.7
pcre2
10.40-5.el9
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2022-41409LOW2.7
pcre2-syntax
10.40-5.el9
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-34156LOW2.7
stdlib
v1.22.4
fixed in 1.22.7, 1.23.1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-41602LOW2.7
github.com/apache/thrift
v0.20.0
fixed in 0.23.0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-26018LOW2.7
github.com/coredns/coredns
v1.11.3
fixed in 1.14.2
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39832LOW2.66
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39832LOW2.66
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2024-51744LOW2.63
github.com/golang-jwt/jwt/v4
v4.5.0
fixed in 4.5.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0861LOW2.48
glibc
2.34-100.el9_4.2
fixed in 2.34-231.el9_7.10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39831LOW2.48
golang.org/x/crypto
v0.23.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.25.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.25.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39831LOW2.48
golang.org/x/crypto
v0.24.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.26.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.26.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.22.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.32-35.el9
fixed in 8.32-41.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-56392LOW2.24
coreutils-single
8.32-35.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.22.4
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2022-29458NONE0
ncurses-base
6.2-10.20210508.el9
fixed in 6.2-10.20210508.el9_6.2
1.3%
Low-Moderate Risk
Not Applicable
CVE-2022-29458NONE0
ncurses-libs
6.2-10.20210508.el9
fixed in 6.2-10.20210508.el9_6.2
1.3%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-base
6.2-10.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.2-10.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.23.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.25.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.20.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.15.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.63.2
fixed in 1.82.1
Not Applicable
CVE-2025-0913NONE0
stdlib
v1.22.4
fixed in 1.23.10, 1.24.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-2303NONE0
go.mongodb.org/mongo-driver
v1.15.0
fixed in 1.17.7
0.2%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.24.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.26.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.21.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.16.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.64.0
fixed in 1.82.1
Not Applicable
GHSA-xr7q-jx4m-x55mNONE0
google.golang.org/grpc
v1.64.0
fixed in 1.64.1
Not Applicable

Want to check another image? Run a full scan with the Docker Security Scanner.