This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Several EXPOSED_SURFACE vulnerabilities, notably CVE-2026-33810 (certificate validation bypass) and CVE-2026-32280 (denial of service), are related to TLS certificate handling in the underlying Go standard library. The practical impact of these findings is highly dependent on whether Node Exporter is configured to use TLS for incoming or outgoing connections, as an attacker could disrupt service or spoof services if TLS is enabled. If TLS is not utilized for external or untrusted communications, the attack surface for these specific vulnerabilities is significantly reduced.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-33810 | MEDIUM6.97 | stdlib v1.26.1 fixed in 1.26.2 | <0.1% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-32281 | MEDIUM6.38 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33811 | MEDIUM5.1 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | <0.1% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33814 | MEDIUM5.1 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | <0.1% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-39820 | LOW3.83 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-39836 | LOW2.29 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-32289 | LOW1.87 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-39826 | LOW1.65 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-39823 | NONE0 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.26.1 fixed in 1.25.11, 1.26.4 | — | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.26.1 fixed in 1.25.11, 1.26.4 | — | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.26.1 fixed in 1.25.11, 1.26.4 | — | Not Applicable |