Last scanned:
This image is safe for production use. One exposed-surface item was identified, but its maximum severity is only 4.17 and there are no post-exploit findings, so the practical risk in this container is negligible. The image is a well-pulled, digest-pinned community build from a reliable publisher, which further supports its suitability for production. No mandatory compensating controls are required, though routine image refresh and digest pinning remain good hygiene.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.39-0ubuntu8.8 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.