Last scanned:
This image is safe for production use. Although 16 exposed and 26 post-exploit findings are present, their maximum severities are 5.02 and 4.06 respectively, remaining below the medium threshold. The only notable finding, CVE-2025-15467, affects OpenSSL CMS/PKCS#7 parsing and is not reachable unless a custom application explicitly parses untrusted CMS messages, which is not part of the Bun runtime's normal operation. No exposed surface findings were reported, and the image's popular community status and digest pinning further support its safe deployment.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r1 fixed in 1.2.5-r2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r1 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15467 | MEDIUM4.06 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | LOW3 | libcrypto3 3.3.5-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libssl3 3.3.5-r0 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libcrypto3 3.3.5-r0 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libcrypto3 3.3.5-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | libcrypto3 3.3.5-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libssl3 3.3.5-r0 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libssl3 3.3.5-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | libssl3 3.3.5-r0 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28387 | LOW2.48 | libcrypto3 3.3.5-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-28387 | LOW2.48 | libssl3 3.3.5-r0 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-40200 | LOW2.39 | musl 1.2.5-r1 fixed in 1.2.5-r3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-22184 | LOW2.39 | zlib 1.3.1-r1 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW2.29 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW2.29 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW2.26 | libcrypto3 3.3.5-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW2.26 | libssl3 3.3.5-r0 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-31790 | LOW2.12 | libcrypto3 3.3.5-r0 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-31790 | LOW2.12 | libssl3 3.3.5-r0 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.36.1-r30 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.36.1-r30 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.36.1-r30 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-40200 | NONE0 | musl-utils 1.2.5-r1 fixed in 1.2.5-r3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-6042 | NONE0 | musl-utils 1.2.5-r1 fixed in 1.2.5-r2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox 1.36.1-r30 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.36.1-r30 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.36.1-r30 fixed in 1.36.1-r31 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.