Vulnerability Reportneilpang/acme.sh:3.1.4

neilpang/acme.sh:3.1.4
digestsha256:08bad323dd6537ea2caba64260ef6e70e96057c4d9214afb9c07861db26653d9

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. Although the scanner reports 18 post-exploit-only findings, all have a maximum severity of 2.63 (low) and none are reachable from the exposed surface, so they pose no practical risk in this context. The image is a popular community project with a strong trust score and is pinned by digest, ensuring a stable, immutable artifact. The startup command only displays help, further minimizing operational risk.

Vulnerabilities

Vulnerability Log

18 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-13321LOW2.63
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-13321LOW2.63
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-11331LOW2.29
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11605LOW2.29
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11622LOW2.29
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11721LOW2.29
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-12617LOW2.29
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-13204LOW2.29
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11331LOW2.29
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11605LOW2.29
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11622LOW2.29
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-11721LOW2.29
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-12617LOW2.29
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-13204LOW2.29
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-10723LOW2.08
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-10723LOW2.08
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-10822LOW1.99
bind-libs
9.20.23-r0
fixed in 9.20.26-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-10822LOW1.99
bind-tools
9.20.23-r0
fixed in 9.20.26-r0
0.4%
Theoretical Threat
Post-Exploit

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.