Vulnerability Reportpaketobuildpacks/ubuntu-noble-run-tiny:latest

paketobuildpacks/ubuntu-noble-run-tiny:latestpaketobuildpacks/ubuntu-noble-run-tiny:0.0.129
digestsha256:1e42340f604ecda9ab87864a2ea33319d36335a59d20beb23439ed3e4dbe7a6e

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. One exposed-surface item was identified, but its maximum severity is only 4.17 and there are no post-exploit findings, so the practical risk in this container is negligible. The image is a well-pulled, digest-pinned community build from a reliable publisher, which further supports its suitability for production. No mandatory compensating controls are required, though routine image refresh and digest pinning remain good hygiene.

Vulnerabilities

Vulnerability Log

1 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-18374MEDIUM4.17
libc6
2.39-0ubuntu8.8
No fix yet
0.1%
Theoretical Threat
Directly Exposed

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.