Last scanned:
This image is safe for production use. The RabbitMQ container is an official Docker image pinned by digest with a perfect trust score and a threat score of 0. While the scan reports 7 exposed-surface and 6 post-exploit-only entries, all are below severity 4.17, which is well under the threshold for meaningful risk. No specific CVE IDs were provided in the top findings, and no practically exploitable high-severity issues were identified. Standard container hygiene and regular updates remain good practice.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-18374 | MEDIUM4.17 | libc-bin 2.39-0ubuntu8.9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.39-0ubuntu8.9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-89092 | LOW3.57 | libc-bin 2.39-0ubuntu8.9 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-89092 | LOW3.57 | libc6 2.39-0ubuntu8.9 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd0 255.4-1ubuntu8.17 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 255.4-1ubuntu8.17 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-86145 | LOW2.51 | libpcre2-8-0 10.42-4ubuntu2.1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-89161 | LOW2.39 | libpcre2-8-0 10.42-4ubuntu2.1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-18477 | LOW2.24 | tar 1.35+dfsg-3ubuntu0.4 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-18508 | LOW2.24 | tar 1.35+dfsg-3ubuntu0.4 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | login 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-85091 | NONE0 | zlib1g 1:1.3.dfsg-3.1ubuntu2.2 No fix yet | 0.6% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.