Vulnerability Reportprom/statsd-exporter:v0.29.0

prom/statsd-exporter:v0.29.0
DIGESTsha256:632f705804922d50c1c95ba8ff9c8c0cc18d4bbb0cc265dc4f9ae708271c95b3

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most notable issue is CVE-2026-25679, a medium-severity vulnerability in the Go stdlib URL parser that could allow a remote attacker to cause a denial of service by sending a specially crafted request to the exporter's HTTP endpoint. Upgrading the underlying Go runtime would fully mitigate this vulnerability. The remaining 26 exposed vulnerabilities are low severity and do not pose significant risk in this context.

Vulnerabilities

Vulnerability Log

44 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-25679MEDIUM6.38
stdlib
v1.26.0
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32282MEDIUM5.44
stdlib
v1.26.0
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM5.1
stdlib
v1.26.0
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32288MEDIUM4.67
stdlib
v1.26.0
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.26.0
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27138LOW3.15
stdlib
v1.26.0
fixed in 1.26.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33810LOW2.51
stdlib
v1.26.0
fixed in 1.26.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39829LOW2.29
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39830LOW2.29
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
golang.org/x/net
v0.48.0
fixed in 0.53.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-27137LOW2.29
stdlib
v1.26.0
fixed in 1.26.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-32280LOW2.29
stdlib
v1.26.0
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-32281LOW2.29
stdlib
v1.26.0
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-33811LOW2.29
stdlib
v1.26.0
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
stdlib
v1.26.0
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.26.0
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.26.0
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42508LOW2.26
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-46595LOW2.17
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.26.0
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289LOW1.87
stdlib
v1.26.0
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27142LOW1.65
stdlib
v1.26.0
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39826LOW1.65
stdlib
v1.26.0
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39827NONE0
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39835NONE0
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-46597NONE0
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39831NONE0
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39832NONE0
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39833NONE0
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39834NONE0
golang.org/x/crypto
v0.46.0
fixed in 0.52.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25680NONE0
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-25681NONE0
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27136NONE0
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42502NONE0
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42506NONE0
golang.org/x/net
v0.48.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.39.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.0
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.0
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.0
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.0
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.0
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable