Vulnerability Reportnats:2.12.12

nats:2.12.12
digestsha256:e0882ab68e01432c3593a20150d681c5c1dd97d50a36a097c6595d05f721fcfa

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. It contains a few low-severity vulnerabilities that pose no realistic risk in this context, due to their low CVSS scores and lack of exploitable conditions. The image is official, trusted, and pinned by digest, further reducing supply chain risk.

  1. Vulnerability scan
    Full CVE sweep across OS packages and app dependencies
  2. Exploitability check
    CVEs ranked by exploit probability (EPSS) and matched against CISA KEV
  3. Result analysis
    Plain-English summary of what actually matters — and why
  1. Hardening recommendations
    A hardened build plan — patch, remove unused packages, lock down the runtime — with parity tests proving nothing broke

This report ran the first 3 stages — get the full report to unlock the rest.

Vulnerabilities

Vulnerability Log

3 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42505LOW3.6
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39822LOW2.39
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable

Want to check another image? Run a full scan with the Docker Security Scanner.