Vulnerability Reportnginx:1.31.6-alpine

nginx:mainline-alpine3.24nginx:mainline-alpinenginx:alpine3.24nginx:alpinenginx:1.31.6-alpine3.24nginx:1.31.6-alpinenginx:1.31-alpine3.24nginx:1.31-alpinenginx:1-alpine3.24nginx:1-alpine
digestsha256:df221db836e1754089190208cee7eeda94f233197056426eda74a43ab1abeac2

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. Although the image has 1 exposed finding and 3 post-exploit-only findings, their maximum severities are 0.0 and 2.74 respectively, so there are no high or critical vulnerabilities driving risk. The image is an official Docker Hub nginx image pinned by digest, with a trusted reputation score of 100. No specific CVE IDs or top findings were present in the provided inputs, so no high-impact exploit path can be described. As a result, no compensating controls are required for the findings shown, and it remains suitable for production use.

Vulnerabilities

Vulnerability Log

4 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-103111LOW2.74
pcre2
10.48-r0
fixed in 10.49-r0
—
Post-Exploit
CVE-2026-93990LOW2.29
libexpat
2.8.4-r0
fixed in 2.8.5-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-58055LOW1.65
nghttp2-libs
1.69.0-r0
fixed in 1.70.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-46675NONE0
libpng
1.6.58-r1
fixed in 1.6.59-r0
—
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.