Vulnerability Reportprom/prometheus:v3.11.1

prom/prometheus:v3.11.1prom/prometheus:v3.11.1-busybox
DIGESTsha256:759ea6db49103737f2a6f420b0d1632062d8ad99dec086c76db605fd0bf23e15

Executive Summary

NEEDS_ATTENTION

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The two medium-severity CVEs (CVE-2026-32283 and CVE-2026-33814) can cause denial of service of the web UI via crafted TLS or HTTP/2 traffic. Post-exploit findings are all low severity. Using a reverse proxy for TLS termination and HTTP/2 handling fully eliminates the risk of both CVEs.

Threat Score
25/100
NEEDS_ATTENTION
Reputation
RELIABLE
prom

Vulnerabilities

Vulnerability Log

27 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-32283MEDIUM6.38
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-33814MEDIUM6.38
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.42.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33810MEDIUM5.58
stdlib
v1.26.1
fixed in 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32282MEDIUM5.44
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-40179MEDIUM5.18
github.com/prometheus/prometheus
3.11.1
fixed in 0.311.2-0.20260410083055-07c6232d159b
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-32280MEDIUM5.1
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32281MEDIUM5.1
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32288MEDIUM4.67
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM4.14
stdlib
v1.26.1
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39826LOW3.67
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34040LOW2.81
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
8.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-33997LOW2.48
github.com/docker/docker
v28.5.2+incompatible
fixed in 29.3.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-32285LOW2.29
github.com/buger/jsonparser
v1.1.1
fixed in 1.1.2
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-41567NONE0
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-42306NONE0
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-41568NONE0
github.com/docker/docker
v28.5.2+incompatible
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-39882NONE0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
v1.42.0
fixed in 1.43.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.1
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.1
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.1
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.1
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable