Vulnerability Reportpaketobuildpacks/ubuntu-resolute-run-tiny:latest

paketobuildpacks/ubuntu-resolute-run-tiny:latestpaketobuildpacks/ubuntu-resolute-run-tiny:0.0.21
digestsha256:2fe8ee65b44eb458ef27ab016e3380c11f9f7509a59a210e7dfdfa610c241acd

Executive Summary

Last scanned:

Threat Score
5/100SAFE
Reputation
UNVERIFIED

This image is safe for production use. The provided stats show 3 exposed vulnerabilities and 4 post-exploit-only issues, but their maximum severities are 4.67 and 2.45 respectively, and none reach the 6.0 threshold, so there is no high-severity exposed risk in the supplied data. No top exposed-surface or post-exploit-only findings were provided, so no specific CVE-level consequence is available for prioritization. The remaining caveat is trust: this is an unverified community image pinned by digest, so use standard supply-chain hygiene and verify the publisher if your environment is sensitive.

Vulnerabilities

Vulnerability Log

7 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-6368MEDIUM4.67
libc6
2.43-2ubuntu2.3
fixed in 2.43-2ubuntu2.4
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-19542MEDIUM4.2
libc6
2.43-2ubuntu2.3
fixed in 2.43-2ubuntu2.4
Directly Exposed
CVE-2026-18374MEDIUM4.17
libc6
2.43-2ubuntu2.3
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-19499LOW2.45
libc6
2.43-2ubuntu2.3
fixed in 2.43-2ubuntu2.4
Post-Exploit
CVE-2026-77117LOW2.12
libc6
2.43-2ubuntu2.3
fixed in 2.43-2ubuntu2.4
Post-Exploit
CVE-2026-80489LOW2.12
libc6
2.43-2ubuntu2.3
fixed in 2.43-2ubuntu2.4
Post-Exploit
CVE-2026-6791LOW1.81
libc6
2.43-2ubuntu2.3
fixed in 2.43-2ubuntu2.4
0.2%
Theoretical Threat
Post-Exploit

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.