Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker reaching this service could trigger heap corruption and crafted-message memory exhaustion in the bundled OpenSSL libraries, degrading or taking down availability of the BindPlane server (CVE-2026-63072, CVE-2026-63074) rather than gaining code execution or data access. None of the exposed findings reaches severity 7.0, and the 16 post-exploit-only findings top out at 2.7, so the practical impact is disruption of service availability, not host compromise. Upgrading the bundled libcrypto3 and libssl3 packages to versions containing the upstream fixes is the only measure that fully eliminates the OpenSSL denial-of-service findings. Note: CVE-2026-63075 only applies if the QUIC stack is actually reachable from an untrusted peer, and the image is digest-pinned, so the reviewed artifact cannot change silently.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-63072 | MEDIUM6.38 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63074 | MEDIUM6.38 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | MEDIUM6.38 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-63072 | MEDIUM6.38 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63074 | MEDIUM6.38 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | MEDIUM6.38 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-56860 | MEDIUM6.38 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-56862 | MEDIUM6.38 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56854 | MEDIUM5.78 | golang.org/x/crypto v0.54.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56858 | MEDIUM5.5 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-56853 | MEDIUM5.1 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-63073 | MEDIUM5.02 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-63073 | MEDIUM5.02 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-56855 | MEDIUM4.5 | golang.org/x/crypto v0.54.0 fixed in 0.56.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-78662 | MEDIUM4.5 | golang.org/x/crypto v0.54.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM4.18 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-18798 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63076 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-18798 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63076 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-56865 | LOW2.69 | golang.org/x/mod v0.38.0 fixed in 0.40.0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-56864 | LOW2.48 | golang.org/x/mod v0.38.0 fixed in 0.40.0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-17106 | LOW2.39 | github.com/moby/go-archive v0.2.0 fixed in 0.3.0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-14456 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-14457 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-54874 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-14456 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-14457 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-54874 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-33818 | LOW2.29 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-46600 | LOW2.29 | stdlib v1.26.5 fixed in 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-56859 | LOW2.29 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-75803 | NONE0 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-75803 | NONE0 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.54.0 No fix yet | — | Not Applicable |
| CVE-2026-84304 | NONE0 | google.golang.org/grpc v1.82.1 fixed in 1.83.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-84445 | NONE0 | google.golang.org/grpc v1.82.1 fixed in 1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e | — | Not Applicable |
| CVE-2026-84303 | NONE0 | google.golang.org/grpc v1.82.1 fixed in 1.83.1 | 0.3% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.