Last scanned:
This image is safe for production use. Although the image contains 18 exposed and 12 post-exploit findings, the maximum severity is low (5.27 and 2.8 respectively), and there are no high-severity or exploitable vulnerabilities in the provided data. The image is well-regarded, pinned by digest, and scores 0 on the pre-calculated threat score, reflecting its low practical risk.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.25.3-4ubuntu2.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg-3.1ubuntu2.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM4.42 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-4437 | MEDIUM4.42 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5704 | LOW2.8 | tar 1.35+dfsg-3ubuntu0.2 fixed in 1.35+dfsg-3ubuntu0.4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-40228 | LOW2.8 | libsystemd0 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-2236 | LOW2.12 | libgcrypt20 1.10.3-2ubuntu0.1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-4046 | LOW1.62 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4046 | LOW1.62 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-54411 | NONE0 | libpam-modules 1.5.3-5ubuntu5.5 fixed in 1.5.3-5ubuntu5.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules-bin 1.5.3-5ubuntu5.5 fixed in 1.5.3-5ubuntu5.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-runtime 1.5.3-5ubuntu5.5 fixed in 1.5.3-5ubuntu5.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam0g 1.5.3-5ubuntu5.5 fixed in 1.5.3-5ubuntu5.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-56433 | NONE0 | login 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-50812 | NONE0 | libsqlite3-0 3.45.1-1ubuntu2.6 fixed in 3.45.1-1ubuntu2.7 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-50813 | NONE0 | libsqlite3-0 3.45.1-1ubuntu2.6 fixed in 3.45.1-1ubuntu2.7 | 0.1% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.