Vulnerability Reportprom/node-exporter:latest

prom/node-exporter:latestprom/node-exporter:v1prom/node-exporter:v1-busyboxprom/node-exporter:latest-busyboxprom/node-exporter:v1.11.1prom/node-exporter:v1.11.1-busybox
DIGESTsha256:e9cff4fc67b1818f8c97adb115b9f12c9a54b533de86765d4a0effc01b357205

Executive Summary

NEEDS_ATTENTION

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Several EXPOSED_SURFACE vulnerabilities, notably CVE-2026-33810 (certificate validation bypass) and CVE-2026-32280 (denial of service), are related to TLS certificate handling in the underlying Go standard library. The practical impact of these findings is highly dependent on whether Node Exporter is configured to use TLS for incoming or outgoing connections, as an attacker could disrupt service or spoof services if TLS is enabled. If TLS is not utilized for external or untrusted communications, the attack surface for these specific vulnerabilities is significantly reduced.

Threat Score
30/100
NEEDS_ATTENTION
Reputation
RELIABLE
prom
BaseImage/
prom/node-exporter:latest
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

18 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33810MEDIUM6.97
stdlib
v1.26.1
fixed in 1.26.2
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-32280MEDIUM6.38
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-32281MEDIUM6.38
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-32283MEDIUM6.38
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-32282MEDIUM5.44
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM5.1
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32288MEDIUM4.67
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-39820LOW3.83
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-39836LOW2.29
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-32289LOW1.87
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39826LOW1.65
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39823NONE0
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.1
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.1
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.1
fixed in 1.25.11, 1.26.4
Not Applicable