Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker who already has a foothold in the container could exploit util-linux mount flaws such as CVE-2026-78410 or ACL symlink traversal in CVE-2026-54369 to escalate privileges and tamper with host-mounted files or permissions. Note that CVE-2026-78410 and CVE-2026-76642 only apply when restricted bind mounts use X-mount.owner/group/mode options, and CVE-2026-89157 affects 32-bit platforms only, so many standard deployments are not actually exposed. Removing host bind-mount passthrough and related fstab X-mount options fully eliminates the practical impact of these local escalation paths.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-78410 | MEDIUM6.63 | libblkid1 2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-78410 | MEDIUM6.63 | libmount1 2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-89161 | MEDIUM6.63 | libpcre2-8-0 10.46-1~deb13u1 fixed in 10.46-1~deb13u2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-78410 | MEDIUM6.63 | libsmartcols1 2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-76642 | MEDIUM6.63 | libuuid1 2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-78410 | MEDIUM6.63 | libuuid1 2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-89157 | MEDIUM6.29 | libpcre2-8-0 10.46-1~deb13u1 fixed in 10.46-1~deb13u2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54369 | MEDIUM6.03 | libacl1 2.3.2-2+b1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-78409 | MEDIUM5.95 | libblkid1 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-78409 | MEDIUM5.95 | libmount1 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-78409 | MEDIUM5.95 | libsmartcols1 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-78409 | MEDIUM5.95 | libuuid1 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-77117 | MEDIUM5.9 | libc-bin 2.41-12+deb13u3 No fix yet | — | Directly Exposed |
| CVE-2026-80489 | MEDIUM5.9 | libc-bin 2.41-12+deb13u3 No fix yet | — | Directly Exposed |
| CVE-2026-77117 | MEDIUM5.9 | libc6 2.41-12+deb13u3 No fix yet | — | Directly Exposed |
| CVE-2026-80489 | MEDIUM5.9 | libc6 2.41-12+deb13u3 No fix yet | — | Directly Exposed |
| CVE-2026-19499 | MEDIUM5.78 | libc-bin 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-19499 | MEDIUM5.78 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.41-12+deb13u3 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-89158 | MEDIUM5.52 | libpcre2-8-0 10.46-1~deb13u1 fixed in 10.46-1~deb13u2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-89160 | MEDIUM5.52 | libpcre2-8-0 10.46-1~deb13u1 fixed in 10.46-1~deb13u2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54370 | MEDIUM5.35 | libacl1 2.3.2-2+b1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54371 | MEDIUM5.35 | libattr1 1:2.5.2-3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-8674 | MEDIUM5.3 | libc-bin 2.41-12+deb13u3 No fix yet | — | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc-bin 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc-bin 2.41-12+deb13u3 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-8674 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | — | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc6 2.41-12+deb13u3 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6791 | MEDIUM5.02 | libc-bin 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6791 | MEDIUM5.02 | libc6 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-89156 | MEDIUM5.02 | libpcre2-8-0 10.46-1~deb13u1 fixed in 10.46-1~deb13u2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libblkid1 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6368 | MEDIUM4.67 | libc-bin 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6368 | MEDIUM4.67 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libmount1 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libsmartcols1 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-50812 | MEDIUM4.67 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-50813 | MEDIUM4.67 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-15059 | MEDIUM4.67 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-15059 | MEDIUM4.67 | libudev1 257.13-1~deb13u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libuuid1 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libblkid1 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libmount1 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libsmartcols1 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libudev1 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libudev1 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libudev1 257.13-1~deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libuuid1 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2021-45346 | MEDIUM4.3 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42250 | MEDIUM4.25 | libbz2-1.0 1.0.8-6 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.41-12+deb13u3 fixed in 2.41-12+deb13u4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.41-12+deb13u3 fixed in 2.41-12+deb13u4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.41-12+deb13u3 fixed in 2.41-12+deb13u4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.41-12+deb13u3 fixed in 2.41-12+deb13u4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc-bin 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.41-12+deb13u3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc-bin 2.41-12+deb13u3 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc6 2.41-12+deb13u3 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-76642 | LOW3.98 | bsdutils 1:2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-78410 | LOW3.98 | bsdutils 1:2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-76642 | LOW3.98 | mount 2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-78410 | LOW3.98 | mount 2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-48962 | LOW3.98 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-76642 | LOW3.98 | util-linux 2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-78410 | LOW3.98 | util-linux 2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-57433 | LOW3.82 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9538 | LOW3.82 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW3.7 | libapt-pkg7.0 3.0.3 No fix yet | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2005-2541 | LOW3.6 | tar 1.35+dfsg-3.1 No fix yet | 4.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-78409 | LOW3.57 | bsdutils 1:2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-78409 | LOW3.57 | mount 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-78409 | LOW3.57 | util-linux 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-19542 | LOW3.57 | libc-bin 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-89092 | LOW3.57 | libc-bin 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-19542 | LOW3.57 | libc6 2.41-12+deb13u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-89092 | LOW3.57 | libc6 2.41-12+deb13u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2019-1010022 | LOW3.53 | libc-bin 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010022 | LOW3.53 | libc6 2.41-12+deb13u3 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-15649 | LOW3.31 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-19487 | LOW3.31 | perl-base 5.40.1-6 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2019-1010023 | LOW3.17 | libc-bin 2.41-12+deb13u3 No fix yet | 3.0% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010023 | LOW3.17 | libc6 2.41-12+deb13u3 No fix yet | 3.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-56391 | LOW3.11 | coreutils 9.7-3 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-56392 | LOW3.11 | coreutils 9.7-3 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-15534 | LOW2.91 | perl-base 5.40.1-6 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | bsdutils 1:2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | mount 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.35+dfsg-3.1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | util-linux 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-89162 | LOW2.8 | libpcre2-8-0 10.46-1~deb13u1 fixed in 10.46-1~deb13u2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-70873 | LOW2.8 | libsqlite3-0 3.46.1-7+deb13u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd0 257.13-1~deb13u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libudev1 257.13-1~deb13u1 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 257.13-1~deb13u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13221 | LOW2.78 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42496 | LOW2.78 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2018-20796 | LOW2.7 | libc-bin 2.41-12+deb13u3 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9192 | LOW2.7 | libc-bin 2.41-12+deb13u3 No fix yet | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2018-20796 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2019-9192 | LOW2.7 | libc6 2.41-12+deb13u3 No fix yet | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | bsdutils 1:2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-53910 | LOW2.7 | diffutils 1:3.10-4 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | mount 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-12087 | LOW2.7 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | util-linux 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-16742 | LOW2.69 | libsystemd0 257.13-1~deb13u1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-16742 | LOW2.69 | libudev1 257.13-1~deb13u1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-57432 | LOW2.57 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-48959 | LOW2.55 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-48961 | LOW2.55 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-86145 | LOW2.51 | libpcre2-8-0 10.46-1~deb13u1 fixed in 10.46-1~deb13u2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2007-5686 | LOW2.5 | passwd 1:4.17.4-2 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-78408 | LOW2.42 | bsdutils 1:2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-78408 | LOW2.42 | libblkid1 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-78408 | LOW2.42 | libmount1 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-78408 | LOW2.42 | libsmartcols1 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-78408 | LOW2.42 | libuuid1 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-78408 | LOW2.42 | mount 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-78408 | LOW2.42 | util-linux 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2017-18018 | LOW2.4 | coreutils 9.7-3 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.13-1 fixed in 1.13-1+deb13u1 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-76642 | LOW2.39 | libblkid1 2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-76642 | LOW2.39 | libmount1 2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-76642 | LOW2.39 | libsmartcols1 2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-11822 | LOW2.39 | libsqlite3-0 3.46.1-7+deb13u1 fixed in 3.46.1-7+deb13u2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-11824 | LOW2.39 | libsqlite3-0 3.46.1-7+deb13u1 fixed in 3.46.1-7+deb13u2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-41992 | LOW2.29 | gzip 1.13-1 fixed in 1.13-1+deb13u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42497 | LOW2.29 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-5278 | LOW2.24 | coreutils 9.7-3 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-18477 | LOW2.24 | tar 1.35+dfsg-3.1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-18508 | LOW2.24 | tar 1.35+dfsg-3.1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW2.22 | apt 3.0.3 No fix yet | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.17.4-2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2011-4116 | LOW1.68 | perl-base 5.40.1-6 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-78408 | NONE0 | liblastlog2-2 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-78408 | NONE0 | login 1:4.16.0-2+really2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-76642 | NONE0 | liblastlog2-2 2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-78410 | NONE0 | liblastlog2-2 2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libtinfo6 6.5+20250216-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-76642 | NONE0 | login 1:4.16.0-2+really2.41.5-0+deb13u1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-78410 | NONE0 | login 1:4.16.0-2+really2.41.5-0+deb13u1 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-base 6.5+20250216-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-bin 6.5+20250216-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-78409 | NONE0 | liblastlog2-2 2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-78409 | NONE0 | login 1:4.16.0-2+really2.41.5-0+deb13u1 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2022-0563 | NONE0 | liblastlog2-2 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2022-0563 | NONE0 | login 1:4.16.0-2+really2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-3184 | NONE0 | liblastlog2-2 2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-3184 | NONE0 | login 1:4.16.0-2+really2.41.5-0+deb13u1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2007-5686 | NONE0 | login.defs 1:4.17.4-2 No fix yet | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules 1.7.0-5 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules-bin 1.7.0-5 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-runtime 1.7.0-5 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam0g 1.7.0-5 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-56433 | NONE0 | login.defs 1:4.17.4-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libtinfo6 6.5+20250216-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-base 6.5+20250216-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-bin 6.5+20250216-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| TEMP-0841856-B18BAF | NONE0 | bash 5.2.37-2+b9 No fix yet | — | Not Applicable |
| TEMP-1147318-639065 | NONE0 | liblzma5 5.8.1-1+deb13u1 No fix yet | — | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | login.defs 1:4.17.4-2 No fix yet | — | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | passwd 1:4.17.4-2 No fix yet | — | Not Applicable |
| CVE-2026-7010 | NONE0 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-7017 | NONE0 | perl-base 5.40.1-6 fixed in 5.40.1-6+deb13u1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-82560 | NONE0 | perl-base 5.40.1-6 No fix yet | — | Not Applicable |
| TEMP-0517018-A83CE6 | NONE0 | sysvinit-utils 3.14-4 No fix yet | — | Not Applicable |
| TEMP-0290435-0B57B5 | NONE0 | tar 1.35+dfsg-3.1 No fix yet | — | Not Applicable |
| CVE-2026-85091 | NONE0 | zlib1g 1:1.3.dfsg+really1.3.1-1+b1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.