Vulnerability Reportoven/bun:1.2.2-distroless

oven/bun:1.2.2-distroless
digestsha256:e2c3f36733fa2c2c9c80d89b481d9fc7629558cac2533c776f6285ae1ba6b8fa

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. The container presents 7 exposed and 13 post-exploit findings, but all are low severity (max 5.95 exposed, 3.53 post-exploit) and no high-impact vulnerabilities were identified. The image is widely used (37M+ pulls), immutable by digest, and from a reliable publisher.

Vulnerabilities

Vulnerability Log

25 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-4802MEDIUM5.95
libc6
2.31-13+deb11u10
fixed in 2.31-13+deb11u13
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
libc6
2.31-13+deb11u10
fixed in 2.31-13+deb11u12
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.31-13+deb11u10
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.31-13+deb11u10
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
libc6
2.31-13+deb11u10
fixed in 2.31-13+deb11u14
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-4806LOW3.54
libc6
2.31-13+deb11u10
No fix yet
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2023-4813LOW3.54
libc6
2.31-13+deb11u10
No fix yet
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2019-1010022LOW3.53
libc6
2.31-13+deb11u10
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010023LOW3.17
libc6
2.31-13+deb11u10
No fix yet
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2018-20796LOW2.7
libc6
2.31-13+deb11u10
No fix yet
5.8%
Low-Moderate Risk
Post-Exploit
CVE-2019-9192LOW2.7
libc6
2.31-13+deb11u10
No fix yet
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-0861LOW2.48
libc6
2.31-13+deb11u10
fixed in 2.31-13+deb11u14
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.31-13+deb11u10
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2019-1010024LOW1.91
libc6
2.31-13+deb11u10
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010025LOW1.91
libc6
2.31-13+deb11u10
No fix yet
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.31-13+deb11u10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15281LOW1.81
libc6
2.31-13+deb11u10
fixed in 2.31-13+deb11u14
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-0915LOW1.62
libc6
2.31-13+deb11u10
fixed in 2.31-13+deb11u14
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-4046LOW1.62
libc6
2.31-13+deb11u10
fixed in 2.31-13+deb11u14
0.4%
Theoretical Threat
Post-Exploit
CVE-2010-4756LOW1.44
libc6
2.31-13+deb11u10
No fix yet
2.6%
Low-Moderate Risk
Post-Exploit
DLA-3972-1NONE0
tzdata
2024a-0+deb11u1
fixed in 2024b-0+deb11u1
Not Applicable
DLA-4085-1NONE0
tzdata
2024a-0+deb11u1
fixed in 2025a-0+deb11u1
Not Applicable
DLA-4105-1NONE0
tzdata
2024a-0+deb11u1
fixed in 2025b-0+deb11u1
Not Applicable
DLA-4403-1NONE0
tzdata
2024a-0+deb11u1
fixed in 2025b-0+deb11u2
Not Applicable
DLA-4569-1NONE0
tzdata
2024a-0+deb11u1
fixed in 2026b-0+deb11u1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.