This image is safe for production use. While 23 low-severity vulnerabilities are present in the exposed surface and 4 in the post-exploit layer, their maximum severity is below critical thresholds and none pose a practical risk in typical deployments. The image is widely trusted, verified by digest, and has no high-severity findings that require immediate action.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-39883 | MEDIUM5.95 | go.opentelemetry.io/otel/sdk v1.42.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-33810 | MEDIUM5.58 | stdlib v1.26.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-32285 | MEDIUM5.1 | github.com/buger/jsonparser v1.1.1 fixed in 1.1.2 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32280 | MEDIUM5.1 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32281 | MEDIUM5.1 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32283 | MEDIUM5.1 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33811 | MEDIUM5.1 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33814 | MEDIUM5.1 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-40179 | MEDIUM4.14 | github.com/prometheus/prometheus 3.11.0 fixed in 0.311.2-0.20260410083055-07c6232d159b | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32289 | MEDIUM4.14 | stdlib v1.26.1 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34040 | LOW2.81 | github.com/docker/docker v28.5.2+incompatible fixed in 29.3.1 | 8.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-39826 | LOW2.75 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-33997 | LOW2.48 | github.com/docker/docker v28.5.2+incompatible fixed in 29.3.1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-39820 | LOW2.29 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-39836 | LOW2.29 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-41567 | NONE0 | github.com/docker/docker v28.5.2+incompatible No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-42306 | NONE0 | github.com/docker/docker v28.5.2+incompatible No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-41568 | NONE0 | github.com/docker/docker v28.5.2+incompatible No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-39882 | NONE0 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.42.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-39823 | NONE0 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.26.1 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.26.1 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.26.1 fixed in 1.25.11, 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.26.1 fixed in 1.25.11, 1.26.4 | 0.3% Theoretical Threat | Not Applicable |