Vulnerability Reportnode:18-alpine

node:18-alpine
digestsha256:8d6421d663b4c28fd3ebc498332f249011d118945588d0a35cb9bc4b8ca09d9e

Executive Summary

Last scanned:

Threat Score
75/100DANGEROUS
Reputation
TRUSTED

This base/runtime image ships critical vulnerabilities that any image built on it would inherit; they must be remediated before the final image goes to production. An attacker could achieve remote code execution via CVE-2025-15467 if the application processes CMS or PKCS#7 data, or cause denial of service via ReDoS using CVE-2026-26996 or CVE-2026-33750. Note: CVE-2025-15467 only applies if the application parses attacker-controlled CMS messages, which is uncommon in typical Node.js deployments. Update the affected packages (OpenSSL, minimatch, brace-expansion) in derived images to eliminate these risks. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

75 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-15467HIGH8
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-15467HIGH8
libssl3
3.3.3-r0
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-33750MEDIUM6.38
brace-expansion
2.0.1
fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-26996MEDIUM6.38
minimatch
9.0.5
fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2025-69419MEDIUM6.29
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-9231MEDIUM5.9
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-9231MEDIUM5.9
libssl3
3.3.3-r0
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-48815MEDIUM5.9
sigstore
2.3.1
fixed in 4.1.1
Directly Exposed
CVE-2025-9230MEDIUM5.6
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-9230MEDIUM5.6
libssl3
3.3.3-r0
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2026-27904MEDIUM5.52
minimatch
9.0.5
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48758MEDIUM5.4
@sigstore/core
1.1.0
fixed in 3.2.1
Directly Exposed
CVE-2026-42338MEDIUM5.18
ip-address
9.0.5
fixed in 10.1.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM5.1
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-69421MEDIUM5.1
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-13149MEDIUM5.1
brace-expansion
2.0.1
fixed in 5.0.7, 1.1.16, 2.1.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-24001MEDIUM5.1
diff
5.2.0
fixed in 8.0.3, 5.2.2, 4.0.4, 3.5.1
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-31790MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-27903MEDIUM5.02
minimatch
9.0.5
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM4.13
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM4.13
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40200LOW3.98
musl
1.2.5-r9
fixed in 1.2.5-r11
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40200LOW3.98
musl-utils
1.2.5-r9
fixed in 1.2.5-r11
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW3.83
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-28389LOW3.83
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28390LOW3.83
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28388LOW3.83
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-28389LOW3.83
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28390LOW3.83
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-21538LOW3.74
cross-spawn
7.0.3
fixed in 7.0.5, 6.0.6
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-26960LOW3.62
tar
6.2.1
fixed in 7.5.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-69418LOW3.4
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-29786LOW3.21
tar
6.2.1
fixed in 7.5.10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-23745LOW3.11
tar
6.2.1
fixed in 7.5.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW3.1
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-9232LOW3.1
libssl3
3.3.3-r0
fixed in 3.3.5-r0
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-6042LOW2.8
musl-utils
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31802LOW2.8
tar
6.2.1
fixed in 7.5.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-53655LOW2.8
tar
6.2.1
fixed in 7.5.16
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-64756LOW2.7
glob
10.4.2
fixed in 11.1.0, 10.5.0
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-59875LOW2.7
tar
6.2.1
fixed in 7.5.17
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-5889LOW2.63
brace-expansion
2.0.1
fixed in 2.0.2, 1.1.12, 3.0.1, 4.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-24842LOW2.51
tar
6.2.1
fixed in 7.5.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-22184LOW2.39
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-59873LOW2.29
tar
6.2.1
fixed in 7.5.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59874LOW2.29
tar
6.2.1
fixed in 7.5.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59871LOW2.29
tar
6.2.1
fixed in 7.5.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23950LOW1.81
tar
6.2.1
fixed in 7.5.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox
1.37.0-r12
fixed in 1.37.0-r14
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox-binsh
1.37.0-r12
fixed in 1.37.0-r14
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
ssl_client
1.37.0-r12
fixed in 1.37.0-r14
0.1%
Theoretical Threat
Post-Exploit
CVE-2024-58251NONE0
busybox
1.37.0-r12
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox-binsh
1.37.0-r12
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
ssl_client
1.37.0-r12
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Not Applicable
CVE-2026-14257NONE0
brace-expansion
2.0.1
fixed in 5.0.8
Not Applicable
GHSA-r292-9mhp-454mNONE0
tar
6.2.1
fixed in 7.5.21
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.