Last scanned:
This image is safe for production use. The provided stats show 3 exposed vulnerabilities and 4 post-exploit-only issues, but their maximum severities are 4.67 and 2.45 respectively, and none reach the 6.0 threshold, so there is no high-severity exposed risk in the supplied data. No top exposed-surface or post-exploit-only findings were provided, so no specific CVE-level consequence is available for prioritization. The remaining caveat is trust: this is an unverified community image pinned by digest, so use standard supply-chain hygiene and verify the publisher if your environment is sensitive.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-6368 | MEDIUM4.67 | libc6 2.43-2ubuntu2.3 fixed in 2.43-2ubuntu2.4 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-19542 | MEDIUM4.2 | libc6 2.43-2ubuntu2.3 fixed in 2.43-2ubuntu2.4 | — | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.43-2ubuntu2.3 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-19499 | LOW2.45 | libc6 2.43-2ubuntu2.3 fixed in 2.43-2ubuntu2.4 | — | Post-Exploit |
| CVE-2026-77117 | LOW2.12 | libc6 2.43-2ubuntu2.3 fixed in 2.43-2ubuntu2.4 | — | Post-Exploit |
| CVE-2026-80489 | LOW2.12 | libc6 2.43-2ubuntu2.3 fixed in 2.43-2ubuntu2.4 | — | Post-Exploit |
| CVE-2026-6791 | LOW1.81 | libc6 2.43-2ubuntu2.3 fixed in 2.43-2ubuntu2.4 | 0.2% Theoretical Threat | Post-Exploit |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.