Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could exploit CVE-2026-82659 to read local files or trigger server-side requests through nodemailer, or CVE-2026-93990 to inject malformed XML through libexpat, impacting n8n workflows that process untrusted input. Disabling nodemailer raw message options would eliminate the CVE-2026-82659 exposure, and upgrading affected dependencies to fixed versions would remove the top exposed findings. Note that CVE-2026-82659 applies only with authenticated access and use of nodemailer raw message options. The image is verified and digest-pinned, but it still carries 56 exposed findings, including 9 at severity 6.0 or higher and a maximum exposed severity of 6.38.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-76956 | MEDIUM6.38 | libexpat 2.8.3-r1 fixed in 2.8.4-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-93990 | MEDIUM6.38 | libexpat 2.8.3-r1 fixed in 2.8.5-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-83613 | MEDIUM6.38 | @xmldom/xmldom 0.8.14 fixed in 0.8.15, 0.9.12 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-83614 | MEDIUM6.38 | @xmldom/xmldom 0.8.14 fixed in 0.8.15, 0.9.12 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-83615 | MEDIUM6.38 | @xmldom/xmldom 0.8.14 fixed in 0.8.15, 0.9.12 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-83616 | MEDIUM6.38 | @xmldom/xmldom 0.8.14 fixed in 0.8.15, 0.9.12 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-83619 | MEDIUM6.38 | @xmldom/xmldom 0.8.14 fixed in 0.8.15 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-82417 | MEDIUM6.38 | qs 6.15.2 fixed in 6.16.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-82659 | MEDIUM6.03 | nodemailer 8.0.10 fixed in 9.0.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-63073 | MEDIUM5.9 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63073 | MEDIUM5.9 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-77301 | MEDIUM5.52 | adm-zip 0.6.0 fixed in 0.6.1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-76845 | MEDIUM5.52 | adm-zip 0.6.0 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-71429 | MEDIUM5.27 | stream-json 1.9.1 fixed in 3.5.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59710 | MEDIUM5.18 | showdown 2.1.0 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59711 | MEDIUM5.18 | showdown 2.1.0 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-2327 | MEDIUM5.1 | markdown-it 13.0.2 fixed in 14.1.1 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-18798 | MEDIUM4.5 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63072 | MEDIUM4.5 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63076 | MEDIUM4.5 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-14457 | MEDIUM4.5 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54874 | MEDIUM4.5 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-18798 | MEDIUM4.5 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63072 | MEDIUM4.5 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63076 | MEDIUM4.5 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-14457 | MEDIUM4.5 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54874 | MEDIUM4.5 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-83610 | MEDIUM4.5 | @xmldom/xmldom 0.8.14 fixed in 0.8.15, 0.9.12 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-83611 | MEDIUM4.5 | @xmldom/xmldom 0.8.14 fixed in 0.8.15, 0.9.12 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-48988 | MEDIUM4.5 | markdown-it 13.0.2 fixed in 14.2.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-76957 | LOW3.98 | libexpat 2.8.3-r1 fixed in 2.8.4-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-14456 | LOW3.83 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-63074 | LOW3.83 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | LOW3.83 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-66046 | LOW3.83 | libexpat 2.8.3-r1 fixed in 2.8.4-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-76641 | LOW3.83 | libexpat 2.8.3-r1 fixed in 2.8.4-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-14456 | LOW3.83 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-63074 | LOW3.83 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | LOW3.83 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-59999 | LOW3.82 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-59999 | LOW3.82 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-19931 | LOW3.31 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-59998 | LOW3.31 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-60001 | LOW3.31 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-59998 | LOW3.31 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-60001 | LOW3.31 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-59998 | LOW3.31 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-60001 | LOW3.31 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-59998 | LOW3.31 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-60001 | LOW3.31 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-75803 | LOW3.15 | libcrypto3 3.5.7-r1 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-75803 | LOW3.15 | libssl3 3.5.7-r1 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-82562 | LOW3.15 | qs 6.15.2 fixed in 6.16.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-63376 | LOW3.15 | toml 3.0.0 fixed in 4.1.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-77465 | LOW2.98 | toml 3.0.0 fixed in 4.2.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-60002 | LOW2.87 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-60002 | LOW2.87 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-60002 | LOW2.87 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-60002 | LOW2.87 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-73282 | LOW2.86 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-73282 | LOW2.86 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-73282 | LOW2.86 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-73282 | LOW2.86 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-59995 | LOW2.75 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59996 | LOW2.75 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-59997 | LOW2.75 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-73283 | LOW2.75 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-59995 | LOW2.75 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59996 | LOW2.75 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-59997 | LOW2.75 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-73283 | LOW2.75 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-59995 | LOW2.75 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59996 | LOW2.75 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-59997 | LOW2.75 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-73283 | LOW2.75 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-59995 | LOW2.75 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59996 | LOW2.75 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-59997 | LOW2.75 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-73283 | LOW2.75 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-60000 | LOW2.7 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-60000 | LOW2.7 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-60000 | LOW2.7 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-60000 | LOW2.7 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-83608 | LOW2.63 | @xmldom/xmldom 0.8.14 fixed in 0.8.15, 0.9.12 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-82208 | LOW2.45 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59999 | LOW2.29 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-59999 | LOW2.29 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-13608 | LOW1.89 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-18924 | LOW1.89 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-80230 | LOW1.89 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-80231 | LOW1.89 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-80255 | LOW1.89 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-73281 | LOW1.78 | openssh 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-73281 | LOW1.78 | openssh-keygen 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-73281 | LOW1.78 | openssh-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-73281 | LOW1.78 | openssh-sftp-server 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-82209 | LOW1.58 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-60002 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-60002 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-60002 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-59999 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-60000 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-59999 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-60000 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-59999 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-60000 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-59998 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-60001 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-59998 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-60001 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-59998 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-60001 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-73282 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-73282 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-73282 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-59995 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-59996 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-59997 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-73283 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-59995 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-59996 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-59997 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-73283 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-59995 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-59996 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-59997 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-73283 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-73281 | NONE0 | openssh-client-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-73281 | NONE0 | openssh-client-default 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-73281 | NONE0 | openssh-server-common 10.3_p1-r0 fixed in 10.3_p1-r1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-80229 | NONE0 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-80256 | NONE0 | libcurl 8.21.0-r0 fixed in 8.22.0-r0 | — | Not Applicable |
| GHSA-j95f-988m-3j2f | NONE0 | @tiptap/core 3.27.0 fixed in 3.30.5 | — | Not Applicable |
| GHSA-cp6q-959q-f8rh | NONE0 | @tiptap/core 3.27.0 fixed in 3.30.4 | — | Not Applicable |
| CVE-2025-57665 | NONE0 | element-plus 2.4.3 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-84363 | NONE0 | hono 4.12.34 fixed in 4.13.5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-84364 | NONE0 | hono 4.12.34 fixed in 4.13.5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-84365 | NONE0 | hono 4.12.34 fixed in 4.13.5 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-2x7j-588g-ccc2 | NONE0 | nodemailer 8.0.10 fixed in 9.1.0 | — | Not Applicable |
| GHSA-8m3c-c648-2xjj | NONE0 | nodemailer 8.0.10 fixed in 9.1.1 | — | Not Applicable |
| GHSA-cc9r-2j5m-2m83 | NONE0 | nodemailer 8.0.10 fixed in 9.1.0 | — | Not Applicable |
| GHSA-wmmp-3585-3rmp | NONE0 | nodemailer 8.0.10 fixed in 9.1.0 | — | Not Applicable |
| CVE-2024-1899 | NONE0 | showdown 2.1.0 No fix yet | 0.8% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.