Last scanned:
This image is safe for production use. The scan does report vulnerabilities - 2 exposed findings with a maximum severity of 5.95 and 6 post-exploit-only findings with a maximum severity of 2.52 - but all of them fall below the severity thresholds that would raise concern, and none reach the 6.0 or 7.0 marks used to escalate the verdict. This is an official Docker Hub image pinned by digest, which means the exact bits you deploy are immutable and cannot be silently swapped out. In practice, the residual risk for a standard nginx reverse-proxy or web-serving role is low; routine re-scanning and periodic digest refreshes are sufficient follow-up.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-78409 | MEDIUM5.95 | libuuid 2.42.1-r0 fixed in 2.42.3-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid 2.42.1-r0 fixed in 2.42.3-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-53612 | LOW2.52 | libuuid 2.42.1-r0 fixed in 2.42.3-r0 | — | Post-Exploit |
| CVE-2026-53613 | LOW2.52 | libuuid 2.42.1-r0 fixed in 2.42.3-r0 | — | Post-Exploit |
| CVE-2026-53614 | LOW2.52 | libuuid 2.42.1-r0 fixed in 2.42.3-r0 | — | Post-Exploit |
| CVE-2026-78408 | LOW2.42 | libuuid 2.42.1-r0 fixed in 2.42.3-r1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-76642 | LOW2.39 | libuuid 2.42.1-r0 fixed in 2.42.3-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-78410 | LOW2.39 | libuuid 2.42.1-r0 fixed in 2.42.3-r0 | <0.1% Theoretical Threat | Post-Exploit |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.