Last scanned:
This image is safe for production use. Although the scanner reports 18 post-exploit-only findings, all have a maximum severity of 2.63 (low) and none are reachable from the exposed surface, so they pose no practical risk in this context. The image is a popular community project with a strong trust score and is pinned by digest, ensuring a stable, immutable artifact. The startup command only displays help, further minimizing operational risk.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-13321 | LOW2.63 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-13321 | LOW2.63 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-11331 | LOW2.29 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11605 | LOW2.29 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-11622 | LOW2.29 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-11721 | LOW2.29 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-12617 | LOW2.29 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-13204 | LOW2.29 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-11331 | LOW2.29 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11605 | LOW2.29 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-11622 | LOW2.29 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-11721 | LOW2.29 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-12617 | LOW2.29 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-13204 | LOW2.29 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-10723 | LOW2.08 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-10723 | LOW2.08 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-10822 | LOW1.99 | bind-libs 9.20.23-r0 fixed in 9.20.26-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-10822 | LOW1.99 | bind-tools 9.20.23-r0 fixed in 9.20.26-r0 | 0.4% Theoretical Threat | Post-Exploit |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.