Vulnerability Reportoven/bun:1.2.10-alpine

oven/bun:1.2.10-alpine
digestsha256:e8e1d291c25b617d7dda08c839fe00d1524a8ccb253c37eb8e9c6e0525da3c89

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. The pre-calculated threat score is 0, and the exposed surface has no findings. Although the post-exploit scan lists 4 vulnerabilities, their maximum severity is 1.68, which is negligible in practice. No CVE IDs are present in the provided findings, so there are no specific security concerns to address. The image's reputation and digest pinning further support its production readiness.

Vulnerabilities

Vulnerability Log

50 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-46394LOW1.68
busybox
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox-binsh
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-15467NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Not Applicable
CVE-2026-31789NONE0
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-15467NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Not Applicable
CVE-2026-28387NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-28387NONE0
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-40200NONE0
musl
1.2.5-r1
fixed in 1.2.5-r3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-40200NONE0
musl-utils
1.2.5-r1
fixed in 1.2.5-r3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22184NONE0
zlib
1.3.1-r1
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69421NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-28388NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-28389NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-28390NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2025-69421NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-28388NONE0
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-28389NONE0
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-28390NONE0
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2025-69419NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69419NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-9231NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2026-31790NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-15468NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-66199NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69420NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-22796NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-9231NONE0
libssl3
3.3.3-r0
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2026-31790NONE0
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-15468NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-66199NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69420NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-22796NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-9230NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Not Applicable
CVE-2025-9230NONE0
libssl3
3.3.3-r0
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Not Applicable
CVE-2026-22795NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22795NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl
1.2.5-r1
fixed in 1.2.5-r2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl-utils
1.2.5-r1
fixed in 1.2.5-r2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27171NONE0
zlib
1.3.1-r1
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-68160NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-68160NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-69418NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-69418NONE0
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-46394NONE0
ssl_client
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable
CVE-2025-9232NONE0
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Not Applicable
CVE-2025-9232NONE0
libssl3
3.3.3-r0
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Not Applicable
CVE-2024-58251NONE0
busybox
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox-binsh
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
ssl_client
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.