Vulnerability Reportphp:8.5.9-cli-alpine3.24

php:cli-alpine3.24php:cli-alpinephp:alpine3.24php:alpinephp:8.5.9-cli-alpine3.24php:8.5.9-cli-alpinephp:8.5.9-alpine3.24php:8.5.9-alpinephp:8.5-cli-alpine3.24php:8.5-cli-alpinephp:8.5-alpine3.24php:8.5-alpinephp:8-cli-alpine3.24php:8-cli-alpinephp:8-alpine3.24php:8-alpine
digestsha256:0554eb53778b5316f6b9a3447c9dfa3cf2141c0c02ff816c42cdc9aa240a34aa

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. It has no exposed vulnerabilities and the 37 post-exploit findings are all low severity (max 3.82), posing negligible risk in containerized deployments. The image is officially maintained and pinned by digest, ensuring consistency and trust. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

37 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-11586LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-33630LOW3.6
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Post-ExploitContext importance: MEDIUM
CVE-2026-11564LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.92
curl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-8925LOW2.92
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11352LOW2.7
curl
8.20.0-r1
fixed in 8.21.0-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-9079LOW2.7
curl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11352LOW2.7
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-9079LOW2.7
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-8286LOW2.48
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8286LOW2.48
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
curl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW2.34
curl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11856LOW2.34
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-8458NONE0
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-8458NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.