Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The most impactful vulnerability is CVE-2023-24534, which can be exploited remotely to exhaust memory and cause denial of service on the metrics endpoint. Additional stdlib issues like CVE-2026-32280 further enable DoS via certificate chain processing. While the image is popular and trusted, the exposed surface has 65 vulnerabilities, so applying available patches for the Go runtime is recommended to reduce the attack surface.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2023-24534 | HIGH7.5 | stdlib v1.20.1 fixed in 1.19.8, 1.20.3 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2025-65637 | MEDIUM6.38 | github.com/sirupsen/logrus v1.9.0 fixed in 1.8.3, 1.9.1, 1.9.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-25679 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-27145 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32281 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33811 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-39820 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-39836 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42499 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42504 | MEDIUM6.38 | stdlib v1.20.1 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-47907 | MEDIUM5.95 | stdlib v1.20.1 fixed in 1.23.12, 1.24.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-24786 | MEDIUM5.9 | google.golang.org/protobuf v1.28.1 fixed in 1.33.0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-24791 | MEDIUM5.9 | stdlib v1.20.1 fixed in 1.21.12, 1.22.5 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-34158 | MEDIUM5.9 | stdlib v1.20.1 fixed in 1.22.7, 1.23.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45288 | MEDIUM5.85 | stdlib v1.20.1 fixed in 1.21.9, 1.22.2 | 92.0% Actively Exploited | Directly Exposed |
| CVE-2025-4673 | MEDIUM5.78 | stdlib v1.20.1 fixed in 1.23.10, 1.24.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-24785 | MEDIUM5.52 | stdlib v1.20.1 fixed in 1.21.8, 1.22.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-47906 | MEDIUM5.52 | stdlib v1.20.1 fixed in 1.23.12, 1.24.6 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61727 | MEDIUM5.52 | stdlib v1.20.1 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39825 | MEDIUM5.52 | stdlib v1.20.1 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.20.1 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-24784 | MEDIUM5.4 | stdlib v1.20.1 fixed in 1.21.8, 1.22.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-29409 | MEDIUM5.3 | stdlib v1.20.1 fixed in 1.19.12, 1.20.7, 1.21.0-rc.4 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-39326 | MEDIUM5.3 | stdlib v1.20.1 fixed in 1.20.12, 1.21.5 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45289 | MEDIUM5.3 | stdlib v1.20.1 fixed in 1.21.8, 1.22.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45290 | MEDIUM5.3 | stdlib v1.20.1 fixed in 1.21.8, 1.22.1 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-39318 | MEDIUM5.18 | stdlib v1.20.1 fixed in 1.20.8, 1.21.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-39319 | MEDIUM5.18 | stdlib v1.20.1 fixed in 1.20.8, 1.21.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-32289 | MEDIUM5.18 | stdlib v1.20.1 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68121 | MEDIUM5.1 | stdlib v1.20.1 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-24783 | MEDIUM5.02 | stdlib v1.20.1 fixed in 1.21.8, 1.22.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-34155 | MEDIUM5.02 | stdlib v1.20.1 fixed in 1.22.7, 1.23.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-45336 | MEDIUM5.02 | stdlib v1.20.1 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-24789 | MEDIUM4.67 | stdlib v1.20.1 fixed in 1.21.11, 1.22.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.20.1 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-22871 | MEDIUM4.59 | stdlib v1.20.1 fixed in 1.23.8, 1.24.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27142 | MEDIUM4.59 | stdlib v1.20.1 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | MEDIUM4.59 | stdlib v1.20.1 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.20.1 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-39325 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.20.10, 1.21.3 | 3.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-24532 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.19.7, 1.20.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-45284 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.20.11, 1.21.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-22866 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.22.12, 1.23.6, 1.24.0-rc.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-22873 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.23.9, 1.24.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-47912 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58185 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58187 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.9, 1.25.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58188 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58189 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61723 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61724 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61725 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61730 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58186 | MEDIUM4.5 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61729 | LOW3.83 | stdlib v1.20.1 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-22870 | LOW3.74 | stdlib v1.20.1 fixed in 1.23.7, 1.24.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-45341 | LOW3.57 | stdlib v1.20.1 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-24538 | LOW3.53 | stdlib v1.20.1 fixed in 1.19.8, 1.20.3 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-24540 | LOW3.53 | stdlib v1.20.1 fixed in 1.19.9, 1.20.4 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2024-24790 | LOW3.53 | stdlib v1.20.1 fixed in 1.21.11, 1.22.4 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-24536 | LOW2.7 | stdlib v1.20.1 fixed in 1.19.8, 1.20.3 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-24537 | LOW2.7 | stdlib v1.20.1 fixed in 1.19.8, 1.20.3 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2023-45283 | LOW2.7 | stdlib v1.20.1 fixed in 1.20.11, 1.21.4, 1.20.12, 1.21.5 | 2.8% Low-Moderate Risk | Post-Exploit |
| CVE-2024-34156 | LOW2.7 | stdlib v1.20.1 fixed in 1.22.7, 1.23.1 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-61726 | LOW2.7 | stdlib v1.20.1 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Post-Exploit |
| CVE-2023-24539 | LOW2.63 | stdlib v1.20.1 fixed in 1.19.9, 1.20.4 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-29400 | LOW2.63 | stdlib v1.20.1 fixed in 1.19.9, 1.20.4 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-29403 | LOW2.39 | stdlib v1.20.1 fixed in 1.19.10, 1.20.5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | LOW2.39 | stdlib v1.20.1 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2023-29406 | LOW2.34 | stdlib v1.20.1 fixed in 1.19.11, 1.20.6 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2025-58183 | LOW2.29 | stdlib v1.20.1 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-61728 | LOW2.29 | stdlib v1.20.1 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-27139 | LOW2.12 | stdlib v1.20.1 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-0913 | NONE0 | stdlib v1.20.1 fixed in 1.23.10, 1.24.4 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.