Vulnerability Reportoven/bun:1.4.2-alpine

oven/bun:alpineoven/bun:1-alpineoven/bun:1.4-alpineoven/bun:1.4.2-alpine
digestsha256:d888c0ae6c86d7866ff10c5aafdd9077b36aee6455b33dd270fb93c0dd5cef6f

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. It does carry findings — 2 exposed-surface issues peaking at severity 3.15 and 18 post-exploit-only issues peaking at 2.7 — but all sit well below the thresholds that would require remediation, and no exploitable high-severity conditions were identified in this context. The image benefits from strong trust signals, including 51M+ pulls, a reputable community publisher, and digest pinning for immutability. No compensating controls are required for this deployment.

Vulnerabilities

Vulnerability Log

20 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-75803LOW3.15
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-75803LOW3.15
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-18798LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-14456LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63072LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63072LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-14457LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-54874LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63073LOW1.81
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-63073LOW1.81
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.9%
Theoretical Threat
Post-Exploit

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.