Vulnerability Reportobserviq/bindplane-ee:1.102.0

observiq/bindplane-ee:1.102.0
digestsha256:bca7c229c1c3c7d89461d84e1307a73df33f507c9d04884fd31de3971e03d780

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
UNVERIFIED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker reaching this service could trigger heap corruption and crafted-message memory exhaustion in the bundled OpenSSL libraries, degrading or taking down availability of the BindPlane server (CVE-2026-63072, CVE-2026-63074) rather than gaining code execution or data access. None of the exposed findings reaches severity 7.0, and the 16 post-exploit-only findings top out at 2.7, so the practical impact is disruption of service availability, not host compromise. Upgrading the bundled libcrypto3 and libssl3 packages to versions containing the upstream fixes is the only measure that fully eliminates the OpenSSL denial-of-service findings. Note: CVE-2026-63075 only applies if the QUIC stack is actually reachable from an untrusted peer, and the image is digest-pinned, so the reviewed artifact cannot change silently.

Vulnerabilities

Vulnerability Log

38 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-63072MEDIUM6.38
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-63074MEDIUM6.38
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-63075MEDIUM6.38
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-63072MEDIUM6.38
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-63074MEDIUM6.38
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-63075MEDIUM6.38
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56860MEDIUM6.38
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-56862MEDIUM6.38
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56854MEDIUM5.78
golang.org/x/crypto
v0.54.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56858MEDIUM5.5
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-56853MEDIUM5.1
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-63073MEDIUM5.02
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-63073MEDIUM5.02
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-56855MEDIUM4.5
golang.org/x/crypto
v0.54.0
fixed in 0.56.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-78662MEDIUM4.5
golang.org/x/crypto
v0.54.0
fixed in 0.56.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM4.18
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-18798LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-56865LOW2.69
golang.org/x/mod
v0.38.0
fixed in 0.40.0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-56864LOW2.48
golang.org/x/mod
v0.38.0
fixed in 0.40.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-17106LOW2.39
github.com/moby/go-archive
v0.2.0
fixed in 0.3.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-33818LOW2.29
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-46600LOW2.29
stdlib
v1.26.5
fixed in 1.26.6, 1.27.0-rc.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-56859LOW2.29
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-75803NONE0
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-75803NONE0
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.54.0
No fix yet
Not Applicable
CVE-2026-84304NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.83.1
0.4%
Theoretical Threat
Not Applicable
CVE-2026-84445NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e
Not Applicable
CVE-2026-84303NONE0
google.golang.org/grpc
v1.82.1
fixed in 1.83.1
0.3%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.