Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. While the image is official and trusted, it contains 69 exposed vulnerabilities, and an attacker could trigger denial of service or memory-corruption issues by serving malicious PNG or XML content (e.g., CVE-2026-33636, CVE-2026-25210). The higher-severity findings are mostly local or require specific conditions, but the sheer volume of medium-severity issues warrants caution. Keeping the image updated and minimizing exposure to untrusted input would help reduce the practical risk.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-25210 | MEDIUM6.63 | libexpat 2.7.0-r0 fixed in 2.7.4-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl 1.2.5-r9 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-33636 | MEDIUM6.46 | libpng 1.6.47-r0 fixed in 1.6.56-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-45186 | MEDIUM6.38 | libexpat 2.7.0-r0 fixed in 2.8.1-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-32414 | MEDIUM6.38 | libxml2 2.13.4-r5 fixed in 2.13.4-r6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-32415 | MEDIUM6.38 | libxml2 2.13.4-r5 fixed in 2.13.4-r6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-49795 | MEDIUM6.38 | libxml2 2.13.4-r5 fixed in 2.13.9-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-6732 | MEDIUM6.38 | libxml2 2.13.4-r5 fixed in 2.13.9-r1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | nghttp2-libs 1.64.0-r0 fixed in 1.68.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-64720 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.53-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-65018 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.53-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-66293 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.53-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22695 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.54-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-56132 | MEDIUM5.87 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56404 | MEDIUM5.87 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56407 | MEDIUM5.87 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-59375 | MEDIUM5.3 | libexpat 2.7.0-r0 fixed in 2.7.2-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-64506 | MEDIUM5.18 | libpng 1.6.47-r0 fixed in 1.6.53-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-62408 | MEDIUM5.02 | c-ares 1.34.5-r0 fixed in 1.34.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-32776 | MEDIUM4.67 | libexpat 2.7.0-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32777 | MEDIUM4.67 | libexpat 2.7.0-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32778 | MEDIUM4.67 | libexpat 2.7.0-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-4367 | MEDIUM4.67 | libxpm 3.5.17-r0 fixed in 3.5.19-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r9 fixed in 1.2.5-r10 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | xz-libs 5.6.3-r1 fixed in 5.8.3-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-15467 | MEDIUM4.06 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56131 | LOW3.82 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-64505 | LOW3.74 | libpng 1.6.47-r0 fixed in 1.6.53-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34757 | LOW3.74 | libpng 1.6.47-r0 fixed in 1.6.57-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-49796 | LOW3.28 | libxml2 2.13.4-r5 fixed in 2.13.9-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-41080 | LOW3.15 | libexpat 2.7.0-r0 fixed in 2.8.1-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31789 | LOW3 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-8961 | LOW2.8 | tiff 4.7.0-r0 fixed in 4.7.1-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-9165 | LOW2.8 | tiff 4.7.0-r0 fixed in 4.7.1-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-49794 | LOW2.78 | libxml2 2.13.4-r5 fixed in 2.13.9-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-33630 | LOW2.7 | c-ares 1.34.5-r0 fixed in 1.34.8-r0 | — | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-33416 | LOW2.7 | libpng 1.6.47-r0 fixed in 1.6.56-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-6021 | LOW2.7 | libxml2 2.13.4-r5 fixed in 2.13.9-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-5399 | LOW2.58 | curl 8.12.1-r1 fixed in 8.14.1-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-5399 | LOW2.58 | libcurl 8.12.1-r1 fixed in 8.14.1-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28387 | LOW2.48 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-25646 | LOW2.48 | libpng 1.6.47-r0 fixed in 1.6.55-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-28387 | LOW2.48 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-5025 | LOW2.45 | curl 8.12.1-r1 fixed in 8.14.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | curl 8.12.1-r1 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-5025 | LOW2.45 | libcurl 8.12.1-r1 fixed in 8.14.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | libcurl 8.12.1-r1 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-22801 | LOW2.39 | libpng 1.6.47-r0 fixed in 1.6.54-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-22184 | LOW2.39 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-24515 | LOW2.12 | libexpat 2.7.0-r0 fixed in 2.7.4-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-6170 | LOW2.12 | libxml2 2.13.4-r5 fixed in 2.13.9-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-4947 | LOW1.99 | curl 8.12.1-r1 fixed in 8.14.0-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-4947 | LOW1.99 | libcurl 8.12.1-r1 fixed in 8.14.0-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-9086 | LOW1.91 | curl 8.12.1-r1 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9086 | LOW1.91 | libcurl 8.12.1-r1 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-40200 | NONE0 | musl-utils 1.2.5-r9 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-6042 | NONE0 | musl-utils 1.2.5-r9 fixed in 1.2.5-r10 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-56408 | NONE0 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat 2.7.0-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.