Vulnerability Reportoven/bun:1.2.8-alpine

oven/bun:1.2.8-alpine
digestsha256:60179f5ab9a193228941d94b6e0570f152aea0ac092d5df14f4f2c4fbd8f3ca8

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. The scanner identified a total of 31 exposed and 19 post-exploit findings, but none exceed severity 6.0, and the top post-exploit finding (CVE-2025-15467) is rated LOW importance, requiring the application to parse untrusted CMS/PKCS#7 content—a non-default path for a Bun runtime. No exposed_surface findings were flagged, and the image is widely used and publisher-reliable. Note: CVE-2025-15467 only applies if your code decodes untrusted CMS/PKCS#7 messages using AEAD ciphers; standard Bun usage is unaffected.

Vulnerabilities

Vulnerability Log

50 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-31790MEDIUM5.9
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-9231MEDIUM5.9
libssl3
3.3.3-r0
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-9230MEDIUM5.6
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-9230MEDIUM5.6
libssl3
3.3.3-r0
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-15468MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r1
fixed in 1.2.5-r2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl-utils
1.2.5-r1
fixed in 1.2.5-r2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r1
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-28388MEDIUM4.5
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388MEDIUM4.5
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28387MEDIUM4.13
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM4.13
libssl3
3.3.3-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
libssl3
3.3.3-r0
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-68160MEDIUM4
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-9231LOW3.54
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-69418LOW3.4
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-9232LOW3.1
libcrypto3
3.3.3-r0
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-9232LOW3.1
libssl3
3.3.3-r0
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389LOW2.7
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libcrypto3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libssl3
3.3.3-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-40200LOW2.39
musl
1.2.5-r1
fixed in 1.2.5-r3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-40200LOW2.39
musl-utils
1.2.5-r1
fixed in 1.2.5-r3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22184LOW2.39
zlib
1.3.1-r1
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-69419LOW2.26
libcrypto3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69419LOW2.26
libssl3
3.3.3-r0
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox-binsh
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
ssl_client
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-58251NONE0
busybox
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox-binsh
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
ssl_client
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.