Vulnerability Reportoven/bun:1.3.5-distroless

oven/bun:1.3.5-distroless
digestsha256:1f24d26e134e3bafa14fe5fc8fc630473f86b3a5c660b8049534c0948a9adbe4

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. The scanner identified 9 exposed and 8 post-exploit findings, but all are low severity (max 4.5 and 3.53) and do not present practical risk. The image is a popular, reliable community image pinned by digest, and the threat score is 0. No high-impact CVE findings were reported.

Vulnerabilities

Vulnerability Log

17 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2018-20796MEDIUM4.5
libc6
2.41-12
No fix yet
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2019-9192MEDIUM4.5
libc6
2.41-12
No fix yet
2.4%
Low-Moderate Risk
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.41-12
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.41-12
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2019-1010022LOW3.53
libc6
2.41-12
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-4438LOW3.4
libc6
2.41-12
fixed in 2.41-12+deb13u3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437LOW3.31
libc6
2.41-12
fixed in 2.41-12+deb13u3
0.3%
Theoretical Threat
Directly Exposed
CVE-2019-1010023LOW3.17
libc6
2.41-12
No fix yet
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-0915LOW2.7
libc6
2.41-12
fixed in 2.41-12+deb13u2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046LOW2.7
libc6
2.41-12
fixed in 2.41-12+deb13u3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0861LOW2.48
libc6
2.41-12
fixed in 2.41-12+deb13u2
0.4%
Theoretical Threat
Post-Exploit
CVE-2010-4756LOW2.4
libc6
2.41-12
No fix yet
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-6238LOW1.99
libc6
2.41-12
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2019-1010024LOW1.91
libc6
2.41-12
No fix yet
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-1010025LOW1.91
libc6
2.41-12
No fix yet
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.41-12
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15281LOW1.81
libc6
2.41-12
fixed in 2.41-12+deb13u2
0.4%
Theoretical Threat
Post-Exploit

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.