Last scanned:
This base/runtime image ships critical vulnerabilities that any image built on it would inherit; they must be remediated before the final image goes to production. An attacker could achieve remote code execution via CVE-2025-15467 if the application processes CMS or PKCS#7 data, or cause denial of service via ReDoS using CVE-2026-26996 or CVE-2026-33750. Note: CVE-2025-15467 only applies if the application parses attacker-controlled CMS messages, which is uncommon in typical Node.js deployments. Update the affected packages (OpenSSL, minimatch, brace-expansion) in derived images to eliminate these risks. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-15467 | HIGH8 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-15467 | HIGH8 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33750 | MEDIUM6.38 | brace-expansion 2.0.1 fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-26996 | MEDIUM6.38 | minimatch 9.0.5 fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2025-69419 | MEDIUM6.29 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-48815 | MEDIUM5.9 | sigstore 2.3.1 fixed in 4.1.1 | — | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2026-27904 | MEDIUM5.52 | minimatch 9.0.5 fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-48758 | MEDIUM5.4 | @sigstore/core 1.1.0 fixed in 3.2.1 | — | Directly Exposed |
| CVE-2026-42338 | MEDIUM5.18 | ip-address 9.0.5 fixed in 10.1.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM5.1 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-69421 | MEDIUM5.1 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-13149 | MEDIUM5.1 | brace-expansion 2.0.1 fixed in 5.0.7, 1.1.16, 2.1.2 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-24001 | MEDIUM5.1 | diff 5.2.0 fixed in 8.0.3, 5.2.2, 4.0.4, 3.5.1 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-31790 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-27903 | MEDIUM5.02 | minimatch 9.0.5 fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | MEDIUM5 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | MEDIUM5 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r9 fixed in 1.2.5-r10 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM4.13 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM4.13 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | LOW3.98 | musl 1.2.5-r9 fixed in 1.2.5-r11 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | LOW3.98 | musl-utils 1.2.5-r9 fixed in 1.2.5-r11 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW3.83 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-28389 | LOW3.83 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28390 | LOW3.83 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28388 | LOW3.83 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-28389 | LOW3.83 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28390 | LOW3.83 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-21538 | LOW3.74 | cross-spawn 7.0.3 fixed in 7.0.5, 6.0.6 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-26960 | LOW3.62 | tar 6.2.1 fixed in 7.5.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-29786 | LOW3.21 | tar 6.2.1 fixed in 7.5.10 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-23745 | LOW3.11 | tar 6.2.1 fixed in 7.5.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW3.1 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-6042 | LOW2.8 | musl-utils 1.2.5-r9 fixed in 1.2.5-r10 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31802 | LOW2.8 | tar 6.2.1 fixed in 7.5.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-53655 | LOW2.8 | tar 6.2.1 fixed in 7.5.16 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-64756 | LOW2.7 | glob 10.4.2 fixed in 11.1.0, 10.5.0 | 3.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-59875 | LOW2.7 | tar 6.2.1 fixed in 7.5.17 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-5889 | LOW2.63 | brace-expansion 2.0.1 fixed in 2.0.2, 1.1.12, 3.0.1, 4.0.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-24842 | LOW2.51 | tar 6.2.1 fixed in 7.5.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-22184 | LOW2.39 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59873 | LOW2.29 | tar 6.2.1 fixed in 7.5.19 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59874 | LOW2.29 | tar 6.2.1 fixed in 7.5.18 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59871 | LOW2.29 | tar 6.2.1 fixed in 7.5.18 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-23950 | LOW1.81 | tar 6.2.1 fixed in 7.5.4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.37.0-r12 fixed in 1.37.0-r14 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.37.0-r12 fixed in 1.37.0-r14 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.37.0-r12 fixed in 1.37.0-r14 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-58251 | NONE0 | busybox 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.37.0-r12 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-14257 | NONE0 | brace-expansion 2.0.1 fixed in 5.0.8 | — | Not Applicable |
| GHSA-r292-9mhp-454m | NONE0 | tar 6.2.1 fixed in 7.5.21 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.