Vulnerability Reportoliver006/redis_exporter:v1.70.0

oliver006/redis_exporter:v1.70.0
digestsha256:ba64da756cd5b76b31e8237aaa40d4126e04625acadd98f76eceb9313e66379f

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The two highest-severity findings are CVE-2025-68121 and CVE-2025-61726. CVE-2025-68121 only applies if TLS configuration is cloned/mutated or GetConfigForClient is used during session resumption; otherwise it has no impact. CVE-2025-61726 could allow a remote attacker to cause memory exhaustion via a crafted request with many query parameters, but this requires the HTTP handler to parse form/query data. Both are moderate severity and do not lead to data exposure or remote code execution, so the overall risk remains manageable.

Vulnerabilities

Vulnerability Log

45 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-68121MEDIUM6.8
stdlib
v1.24.2
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-61726MEDIUM6
stdlib
v1.24.2
fixed in 1.24.12, 1.25.6
1.9%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-47906MEDIUM5.52
stdlib
v1.24.2
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.24.2
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.24.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.24.2
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.24.2
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM5.1
stdlib
v1.24.2
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-25679MEDIUM5.1
stdlib
v1.24.2
fixed in 1.25.8, 1.26.1
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-27145MEDIUM5.1
stdlib
v1.24.2
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32280MEDIUM5.1
stdlib
v1.24.2
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32283MEDIUM5.1
stdlib
v1.24.2
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32288MEDIUM4.67
stdlib
v1.24.2
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.24.2
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.24.2
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.24.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22873MEDIUM4.5
stdlib
v1.24.2
fixed in 1.23.9, 1.24.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.24.2
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.24.2
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22874LOW3.83
stdlib
v1.24.2
fixed in 1.24.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32281LOW3.83
stdlib
v1.24.2
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39822LOW2.39
stdlib
v1.24.2
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33811LOW2.29
stdlib
v1.24.2
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
stdlib
v1.24.2
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.24.2
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.24.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42499LOW2.29
stdlib
v1.24.2
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-42504LOW2.29
stdlib
v1.24.2
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-58183LOW2.29
stdlib
v1.24.2
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-61728LOW2.29
stdlib
v1.24.2
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-47907LOW2.14
stdlib
v1.24.2
fixed in 1.23.12, 1.24.6
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.24.2
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-4673LOW2.08
stdlib
v1.24.2
fixed in 1.23.10, 1.24.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39824NONE0
golang.org/x/sys
v0.30.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-0913NONE0
stdlib
v1.24.2
fixed in 1.23.10, 1.24.4
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.