Vulnerability Reportmongo-express:1

mongo-express:latestmongo-express:1.0.2-18-alpine3.18mongo-express:1.0.2-18mongo-express:1.0.2mongo-express:1.0-18-alpine3.18mongo-express:1.0-18mongo-express:1.0mongo-express:1-18-alpine3.18mongo-express:1-18mongo-express:1
digestsha256:1b23d7976f0210dbec74045c209e52fbb26d29b2e873d6c6fa3d3f0ae32c2a64

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could cause denial of service by exploiting CVE-2024-6119 in openssl or via crafted HTTP requests exploiting CVE-2024-45590 in body-parser, potentially disrupting the service. While the image is official and pinned, the presence of multiple high-severity DoS vulnerabilities in exposed components warrants caution.

Vulnerabilities

Vulnerability Log

103 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2024-6119CRITICAL9.75
libcrypto3
3.1.4-r5
fixed in 3.1.7-r0
66.6%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2024-6119CRITICAL9.75
libssl3
3.1.4-r5
fixed in 3.1.7-r0
66.6%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2024-45590MEDIUM6.38
body-parser
1.20.1
fixed in 1.20.3
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-33750MEDIUM6.38
brace-expansion
1.1.11
fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33750MEDIUM6.38
brace-expansion
2.0.1
fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59869MEDIUM6.38
js-yaml
3.14.1
fixed in 3.15.0, 4.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41907MEDIUM6.38
uuid
8.3.2
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-26519MEDIUM5.95
musl
1.2.4-r2
fixed in 1.2.4-r3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-26519MEDIUM5.95
musl-utils
1.2.4-r2
fixed in 1.2.4-r3
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-5535MEDIUM5.9
libcrypto3
3.1.4-r5
fixed in 3.1.6-r0
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-5535MEDIUM5.9
libssl3
3.1.4-r5
fixed in 3.1.6-r0
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-48815MEDIUM5.9
sigstore
2.3.0
fixed in 4.1.1
Directly Exposed
CVE-2024-4741MEDIUM5.6
libcrypto3
3.1.4-r5
fixed in 3.1.6-r0
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2024-4741MEDIUM5.6
libssl3
3.1.4-r5
fixed in 3.1.6-r0
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-27904MEDIUM5.52
minimatch
3.1.2
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-27904MEDIUM5.52
minimatch
9.0.4
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48758MEDIUM5.4
@sigstore/core
1.1.0
fixed in 3.2.1
Directly Exposed
CVE-2024-4603MEDIUM5.3
libcrypto3
3.1.4-r5
fixed in 3.1.5-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-4603MEDIUM5.3
libssl3
3.1.4-r5
fixed in 3.1.5-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-13465MEDIUM5.3
lodash
4.17.21
fixed in 4.17.23
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2025-13465MEDIUM5.3
lodash-es
4.17.21
fixed in 4.17.23
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2024-29041MEDIUM5.18
express
4.18.2
fixed in 4.19.2, 5.0.0-beta.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42338MEDIUM5.18
ip-address
9.0.5
fixed in 10.1.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-15284MEDIUM5.1
qs
6.11.0
fixed in 6.14.1
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-2391MEDIUM5.1
qs
6.11.0
fixed in 6.14.2
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-12590MEDIUM5.02
body-parser
1.20.1
fixed in 1.20.6, 2.3.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33349MEDIUM5.02
fast-xml-parser
4.0.11
fixed in 4.5.5, 5.5.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27903MEDIUM5.02
minimatch
3.1.2
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-27903MEDIUM5.02
minimatch
9.0.4
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-2511MEDIUM4.81
libcrypto3
3.1.4-r5
fixed in 3.1.4-r6
54.0%
Actively Exploited
Directly Exposed
CVE-2024-2511MEDIUM4.81
libssl3
3.1.4-r5
fixed in 3.1.4-r6
54.0%
Actively Exploited
Directly Exposed
CVE-2024-27088MEDIUM4.67
es5-ext
0.10.62
fixed in 0.10.63
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41650MEDIUM4.59
fast-xml-parser
4.0.11
fixed in 5.7.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-47178MEDIUM4.5
basic-auth-connect
1.0.0
fixed in 1.1.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-64718MEDIUM4.5
js-yaml
3.14.1
fixed in 4.1.1, 3.14.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-53550MEDIUM4.5
js-yaml
3.14.1
fixed in 4.2.0, 3.15.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2950MEDIUM4.5
lodash
4.17.21
fixed in 4.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2950MEDIUM4.5
lodash-es
4.17.21
fixed in 4.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5078MEDIUM4.5
morgan
1.10.0
fixed in 1.11.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-45296MEDIUM4.5
path-to-regexp
0.1.7
fixed in 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2024-52798MEDIUM4.5
path-to-regexp
0.1.7
fixed in 0.1.12
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-4867MEDIUM4.5
path-to-regexp
0.1.7
fixed in 0.1.13
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libcrypto3
3.1.4-r5
fixed in 3.1.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libssl3
3.1.4-r5
fixed in 3.1.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-43796MEDIUM4
express
4.18.2
fixed in 4.20.0, 5.0.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-43799MEDIUM4
send
0.18.0
fixed in 0.19.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-43800MEDIUM4
serve-static
1.15.0
fixed in 1.16.0, 2.1.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-21538LOW3.74
cross-spawn
7.0.3
fixed in 7.0.5, 6.0.6
0.9%
Theoretical Threat
Directly Exposed
CVE-2024-9143LOW3.7
libcrypto3
3.1.4-r5
fixed in 3.1.7-r1
6.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-9143LOW3.7
libssl3
3.1.4-r5
fixed in 3.1.7-r1
6.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-26960LOW3.62
tar
6.2.1
fixed in 7.5.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2024-29415LOW3.53
ip
2.0.0
No fix yet
8.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-42282LOW3.53
ip
2.0.0
fixed in 2.0.1, 1.1.9
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-4800LOW3.53
lodash
4.17.21
fixed in 4.18.0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-4800LOW3.53
lodash-es
4.17.21
fixed in 4.18.0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-29786LOW3.21
tar
6.2.1
fixed in 7.5.10
0.4%
Theoretical Threat
Post-Exploit
CVE-2022-46175LOW3.17
json5
2.2.1
fixed in 2.2.2, 1.0.2
9.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-47764LOW3.15
cookie
0.4.0
fixed in 0.7.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-47764LOW3.15
cookie
0.4.1
fixed in 0.7.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-47764LOW3.15
cookie
0.4.2
fixed in 0.7.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-47764LOW3.15
cookie
0.5.0
fixed in 0.7.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-23745LOW3.11
tar
6.2.1
fixed in 7.5.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2021-32050LOW3.06
mongodb
4.13.0
fixed in 3.6.10, 4.17.0, 5.8.0
0.5%
Theoretical Threat
Post-ExploitContext importance: MEDIUM
CVE-2026-49356LOW3.06
@babel/core
7.19.6
fixed in 8.0.0-rc.6, 7.29.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-7339LOW2.89
on-headers
1.0.2
fixed in 1.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-42363LOW2.8
busybox
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
busybox
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
busybox
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
busybox
1.36.1-r5
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42363LOW2.8
busybox-binsh
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
busybox-binsh
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
busybox-binsh
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
busybox-binsh
1.36.1-r5
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42363LOW2.8
ssl_client
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42364LOW2.8
ssl_client
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42365LOW2.8
ssl_client
1.36.1-r5
fixed in 1.36.1-r7
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-42366LOW2.8
ssl_client
1.36.1-r5
fixed in 1.36.1-r6
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-31802LOW2.8
tar
6.2.1
fixed in 7.5.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-53655LOW2.8
tar
6.2.1
fixed in 7.5.16
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-64756LOW2.7
glob
10.3.12
fixed in 11.1.0, 10.5.0
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2022-25883LOW2.7
semver
6.3.0
fixed in 7.5.2, 6.3.1, 5.7.2
2.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-59875LOW2.7
tar
6.2.1
fixed in 7.5.17
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-45133LOW2.69
@babel/traverse
7.19.6
fixed in 7.23.2, 8.0.0-alpha.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-5889LOW2.63
brace-expansion
1.1.11
fixed in 2.0.2, 1.1.12, 3.0.1, 4.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-5889LOW2.63
brace-expansion
2.0.1
fixed in 2.0.2, 1.1.12, 3.0.1, 4.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-24842LOW2.51
tar
6.2.1
fixed in 7.5.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-26920LOW2.34
fast-xml-parser
4.0.11
fixed in 4.1.2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-13149LOW2.29
brace-expansion
1.1.11
fixed in 5.0.7, 1.1.16, 2.1.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-13149LOW2.29
brace-expansion
2.0.1
fixed in 5.0.7, 1.1.16, 2.1.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-24001LOW2.29
diff
5.2.0
fixed in 8.0.3, 5.2.2, 4.0.4, 3.5.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33036LOW2.29
fast-xml-parser
4.0.11
fixed in 5.5.6, 4.5.5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-27942LOW2.29
fast-xml-parser
4.0.11
fixed in 5.3.8, 4.5.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-26996LOW2.29
minimatch
3.1.2
fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-26996LOW2.29
minimatch
9.0.4
fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-59873LOW2.29
tar
6.2.1
fixed in 7.5.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59874LOW2.29
tar
6.2.1
fixed in 7.5.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59871LOW2.29
tar
6.2.1
fixed in 7.5.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23950LOW1.81
tar
6.2.1
fixed in 7.5.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-27789NONE0
@babel/helpers
7.19.4
fixed in 7.26.10, 8.0.0-alpha.17
0.5%
Theoretical Threat
Not Applicable
CVE-2026-14257NONE0
brace-expansion
1.1.11
fixed in 5.0.8
Not Applicable
CVE-2026-14257NONE0
brace-expansion
2.0.1
fixed in 5.0.8
Not Applicable
CVE-2023-52555NONE0
mongo-express
1.0.2
No fix yet
0.2%
Theoretical Threat
Not Applicable
GHSA-r292-9mhp-454mNONE0
tar
6.2.1
fixed in 7.5.21
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.