Vulnerability Reportprom/node-exporter:v1.10.1

prom/node-exporter:v1.10.1
DIGESTsha256:b01f6d5e6945d5001894165cce46a80fd8d0cfee68c35c8b251c50d8d446ba75

Executive Summary

NEEDS_ATTENTION

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most notable issue is CVE-2025-61726, which could allow memory exhaustion via crafted HTTP query parameters, directly affecting the Node Exporter's HTTP server. Additionally, CVE-2025-68121 may permit TLS session resumption bypass if the server uses dynamic TLS configuration changes. If your deployment does not mutate TLS configs between handshakes, the latter vulnerability is not applicable. Overall, the threat score is low (25), and there are no high-severity exposed vulnerabilities.

Threat Score
25/100
NEEDS_ATTENTION
Reputation
RELIABLE
prom

Vulnerabilities

Vulnerability Log

29 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-68121MEDIUM6.8
stdlib
v1.25.3
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-61726MEDIUM6.38
stdlib
v1.25.3
fixed in 1.24.12, 1.25.6
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-32282MEDIUM5.44
stdlib
v1.25.3
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM5.1
stdlib
v1.25.3
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-25679MEDIUM5.1
stdlib
v1.25.3
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32283MEDIUM5.1
stdlib
v1.25.3
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32288MEDIUM4.67
stdlib
v1.25.3
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM4.42
stdlib
v1.25.3
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-61730LOW2.7
stdlib
v1.25.3
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-52881LOW2.29
github.com/opencontainers/selinux
v1.12.0
fixed in 1.13.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-32280LOW2.29
stdlib
v1.25.3
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-32281LOW2.29
stdlib
v1.25.3
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-33811LOW2.29
stdlib
v1.25.3
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
stdlib
v1.25.3
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.25.3
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.25.3
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-61728LOW2.29
stdlib
v1.25.3
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.25.3
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289LOW1.87
stdlib
v1.25.3
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27142LOW1.65
stdlib
v1.25.3
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39826LOW1.65
stdlib
v1.25.3
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-47914LOW1.62
golang.org/x/crypto
v0.42.0
fixed in 0.45.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-58181LOW1.62
golang.org/x/crypto
v0.42.0
fixed in 0.45.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39823NONE0
stdlib
v1.25.3
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.25.3
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.25.3
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.25.3
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.25.3
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.25.3
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable