Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The primary concern is CVE-2025-68121, which could allow a malicious Redis endpoint to bypass TLS certificate validation during session resumption, but only if the client dynamically changes its CA configuration (e.g., via Config.Clone or GetConfigForClient). In standard deployments without this dynamic mutation, the vulnerability is not applicable. The remaining exposed findings are moderate at most, and post-exploit findings are low severity, so the practical risk is limited. Pinning by digest and a strong community reputation further support a controlled production rollout.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-68121 | MEDIUM6.8 | stdlib v1.25.3 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-61729 | MEDIUM5.1 | stdlib v1.25.3 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-27145 | MEDIUM5.1 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32280 | MEDIUM5.1 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32283 | MEDIUM5.1 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | MEDIUM4.59 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61726 | MEDIUM4.5 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2025-61730 | MEDIUM4.5 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.25.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | MEDIUM4.5 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-25679 | LOW3.83 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-32281 | LOW3.83 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61727 | LOW3.31 | stdlib v1.25.3 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39822 | LOW2.39 | stdlib v1.25.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-33811 | LOW2.29 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-33814 | LOW2.29 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-39820 | LOW2.29 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-39836 | LOW2.29 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-42499 | LOW2.29 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-42504 | LOW2.29 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-61728 | LOW2.29 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-27139 | LOW2.12 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39825 | LOW1.99 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-32289 | LOW1.87 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-27142 | LOW1.65 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.35.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.