Last scanned:
This image is safe for production use. The pre-calculated threat score is 0, and the exposed surface has no findings. Although the post-exploit scan lists 4 vulnerabilities, their maximum severity is 1.68, which is negligible in practice. No CVE IDs are present in the provided findings, so there are no specific security concerns to address. The image's reputation and digest pinning further support its production readiness.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-46394 | LOW1.68 | busybox 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-15467 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Not Applicable |
| CVE-2026-31789 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-15467 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Not Applicable |
| CVE-2026-28387 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-28387 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-40200 | NONE0 | musl 1.2.5-r1 fixed in 1.2.5-r3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-40200 | NONE0 | musl-utils 1.2.5-r1 fixed in 1.2.5-r3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-22184 | NONE0 | zlib 1.3.1-r1 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69421 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-28388 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-28389 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-28390 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-69421 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-28388 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-28389 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-28390 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-69419 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69419 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-9231 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-31790 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-15468 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-66199 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69420 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-22796 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-9231 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-31790 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-15468 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-66199 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69420 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-22796 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-9230 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2025-9230 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2026-22795 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22795 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-6042 | NONE0 | musl 1.2.5-r1 fixed in 1.2.5-r2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-6042 | NONE0 | musl-utils 1.2.5-r1 fixed in 1.2.5-r2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27171 | NONE0 | zlib 1.3.1-r1 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-68160 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-68160 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-69418 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-69418 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-46394 | NONE0 | ssl_client 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-9232 | NONE0 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2025-9232 | NONE0 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.