Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The image has 45 exposed vulnerabilities, but the most notable is CVE-2025-15467 (severity 6.0) in OpenSSL, which is only exploitable if your application parses untrusted CMS/PKCS#7 data with AEAD ciphers—not part of Bun's default runtime behavior. Post-exploit findings are minimal, with no vulnerabilities at severity 6.0 or above. To fully mitigate CVE-2025-15467, ensure your application does not process untrusted CMS/PKCS#7 messages. Overall, risk is low given the image's popularity and the conditional nature of the top finding.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-15467 | MEDIUM6 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Directly Exposed |
| CVE-2025-15467 | MEDIUM6 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Directly Exposed |
| CVE-2025-26519 | MEDIUM5.95 | musl 1.2.5-r0 fixed in 1.2.5-r1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libcrypto3 3.3.2-r1 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.3.2-r1 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libssl3 3.3.2-r1 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.3.2-r1 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libcrypto3 3.3.2-r1 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl3 3.3.2-r1 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | MEDIUM5 | libcrypto3 3.3.2-r1 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | MEDIUM5 | libssl3 3.3.2-r1 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r0 fixed in 1.2.5-r2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r1 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-28388 | MEDIUM4.5 | libcrypto3 3.3.2-r1 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | MEDIUM4.5 | libcrypto3 3.3.2-r1 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | MEDIUM4.5 | libcrypto3 3.3.2-r1 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28388 | MEDIUM4.5 | libssl3 3.3.2-r1 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | MEDIUM4.5 | libssl3 3.3.2-r1 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | MEDIUM4.5 | libssl3 3.3.2-r1 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12797 | MEDIUM4.44 | libcrypto3 3.3.2-r1 fixed in 3.3.3-r0 | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12797 | MEDIUM4.44 | libssl3 3.3.2-r1 fixed in 3.3.3-r0 | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28387 | MEDIUM4.13 | libcrypto3 3.3.2-r1 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM4.13 | libssl3 3.3.2-r1 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libcrypto3 3.3.2-r1 fixed in 3.3.2-r2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libssl3 3.3.2-r1 fixed in 3.3.2-r2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | LOW3.98 | musl-utils 1.2.5-r0 fixed in 1.2.5-r3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW3.83 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | LOW3.83 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | LOW3.77 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | LOW3.77 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-26519 | LOW3.57 | musl-utils 1.2.5-r0 fixed in 1.2.5-r1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.3.2-r1 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.3.2-r1 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libcrypto3 3.3.2-r1 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libssl3 3.3.2-r1 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-6042 | LOW2.8 | musl-utils 1.2.5-r0 fixed in 1.2.5-r2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-40200 | LOW2.39 | musl 1.2.5-r0 fixed in 1.2.5-r3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-22184 | LOW2.39 | zlib 1.3.1-r1 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-58251 | NONE0 | busybox 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.