Vulnerability Reportprom/alertmanager:v0.30.1

prom/alertmanager:v0.30.1
DIGESTsha256:286ad8838533a5a01d89bd09643f43d2b68b65203123b5700e54a8f80ff9c1f4

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The only notable finding, CVE-2025-68121, is a TLS certificate validation flaw that requires a non-default configuration pattern (using Config.Clone() or GetConfigForClient with mutated certificate pools) to be exploitable, which is uncommon in typical alertmanager deployments. Updating to a Go version containing the fix or avoiding the specific TLS mutation pattern would fully eliminate the risk.

Vulnerabilities

Vulnerability Log

31 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-68121MEDIUM6.8
stdlib
v1.25.5
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.38.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.25.5
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.25.5
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-29181MEDIUM5.1
go.opentelemetry.io/otel
v1.38.0
fixed in 1.41.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-61726MEDIUM5.1
stdlib
v1.25.5
fixed in 1.24.12, 1.25.6
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-25679MEDIUM5.1
stdlib
v1.25.5
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32280MEDIUM5.1
stdlib
v1.25.5
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32281MEDIUM5.1
stdlib
v1.25.5
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32283MEDIUM5.1
stdlib
v1.25.5
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.25.5
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32288MEDIUM4.67
stdlib
v1.25.5
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.25.5
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39826MEDIUM4.59
stdlib
v1.25.5
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2025-61730LOW3.6
stdlib
v1.25.5
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33186LOW2.78
google.golang.org/grpc
v1.75.0
fixed in 1.79.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-33811LOW2.29
stdlib
v1.25.5
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.25.5
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.25.5
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-61728LOW2.29
stdlib
v1.25.5
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.25.5
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47914LOW1.62
golang.org/x/crypto
v0.44.0
fixed in 0.45.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-58181LOW1.62
golang.org/x/crypto
v0.44.0
fixed in 0.45.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39882NONE0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
v1.38.0
fixed in 1.43.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-24051NONE0
go.opentelemetry.io/otel/sdk
v1.38.0
fixed in 1.40.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.25.5
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.25.5
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.25.5
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.25.5
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.25.5
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.25.5
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable