Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could potentially execute arbitrary code on the container or cause denial of service by exploiting the OpenSSL CMS parsing vulnerability (CVE-2025-15467), which is particularly concerning given the image's large exposed attack surface. Additional high-severity OpenSSL issues, such as CVE-2026-31789, may also be exploited depending on the platform architecture and configuration. The post-exploit findings are all low severity (max 1.68), so the risk is concentrated in the exposed surface. Upgrading OpenSSL (libcrypto3/libssl3) to a patched version is the primary mitigation; note that CVE-2026-31789 only affects 32-bit systems.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-15467 | CRITICAL10 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Directly Exposed |
| CVE-2025-15467 | CRITICAL10 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Directly Exposed |
| CVE-2026-31789 | HIGH8.33 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | HIGH8.33 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-28388 | HIGH7.5 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28388 | HIGH7.5 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl 1.2.5-r1 fixed in 1.2.5-r3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl-utils 1.2.5-r1 fixed in 1.2.5-r3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22184 | MEDIUM6.63 | zlib 1.3.1-r1 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.3.3-r0 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.3.3-r0 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r1 fixed in 1.2.5-r2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl-utils 1.2.5-r1 fixed in 1.2.5-r2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r1 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.3.3-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libcrypto3 3.3.3-r0 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libssl3 3.3.3-r0 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-46394 | LOW1.68 | busybox 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-58251 | NONE0 | busybox 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.36.1-r29 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.