This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker with local access could exploit runc to escape the container and gain host root, and if the Extension backend is enabled on flannel, remote command injection is possible. Upgrading flannel to v0.28.2 or using default vxlan/wireguard backends fully mitigates CVE-2026-32241. Remediation of runc and stdlib vulnerabilities is required to reduce the attack surface.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-32241 | HIGH7.04 | github.com/flannel-io/flannel v0.27.0 fixed in 0.28.2 | 2.7% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-68121 | MEDIUM6.8 | stdlib v1.24.6 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-31133 | MEDIUM6.63 | github.com/opencontainers/runc v1.3.1 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | 0.7% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.24.6 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32281 | MEDIUM6.38 | stdlib v1.24.6 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.24.6 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-33811 | MEDIUM6.38 | stdlib v1.24.6 fixed in 1.25.10, 1.26.3 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | stdlib v1.24.6 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39820 | MEDIUM6.38 | stdlib v1.24.6 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39836 | MEDIUM6.38 | stdlib v1.24.6 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32285 | MEDIUM6.38 | github.com/buger/jsonparser v1.1.1 fixed in 1.1.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-34986 | MEDIUM6.38 | github.com/go-jose/go-jose/v4 v4.0.5 fixed in 4.1.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27889 | MEDIUM6.38 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.14, 2.12.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-29785 | MEDIUM6.38 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.14, 2.12.5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-33216 | MEDIUM6.38 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33218 | MEDIUM6.38 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-27571 | MEDIUM6.38 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.12, 2.12.3 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33219 | MEDIUM6.38 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-52881 | MEDIUM6.38 | github.com/opencontainers/selinux v1.11.1 fixed in 1.13.0 | 0.5% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-40898 | MEDIUM6.38 | github.com/quic-go/quic-go v0.50.1 fixed in 0.59.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-29181 | MEDIUM6.38 | go.opentelemetry.io/otel v1.37.0 fixed in 1.41.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-52565 | MEDIUM6.38 | github.com/opencontainers/runc v1.3.1 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2025-52881 | MEDIUM6.38 | github.com/opencontainers/runc v1.3.1 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-33186 | MEDIUM6.18 | google.golang.org/grpc v1.73.0 fixed in 1.79.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33186 | MEDIUM6.18 | google.golang.org/grpc v1.72.1 fixed in 1.79.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42306 | MEDIUM6.12 | github.com/docker/docker v25.0.8+incompatible No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-39883 | MEDIUM5.95 | go.opentelemetry.io/otel/sdk v1.37.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-61727 | MEDIUM5.52 | stdlib v1.24.6 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-35469 | MEDIUM5.52 | github.com/moby/spdystream v0.5.0 fixed in 0.5.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-33217 | MEDIUM5.52 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-33215 | MEDIUM5.52 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-22872 | MEDIUM5.52 | golang.org/x/net v0.35.0 fixed in 0.38.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.24.6 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33249 | MEDIUM5.44 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32289 | MEDIUM5.18 | stdlib v1.24.6 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-61726 | MEDIUM5.1 | stdlib v1.24.6 fixed in 1.24.12, 1.25.6 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-61729 | MEDIUM5.1 | stdlib v1.24.6 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-25679 | MEDIUM5.1 | stdlib v1.24.6 fixed in 1.25.8, 1.26.1 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-58183 | MEDIUM5.1 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-61728 | MEDIUM5.1 | stdlib v1.24.6 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-26014 | MEDIUM5.02 | github.com/pion/dtls/v2 v2.2.12 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-26014 | MEDIUM5.02 | github.com/pion/dtls/v3 v3.0.4 fixed in 3.1.1, 3.0.11 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.24.6 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27142 | MEDIUM4.59 | stdlib v1.24.6 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.24.6 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-33223 | MEDIUM4.59 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-33246 | MEDIUM4.59 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-47912 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58185 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58187 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.9, 1.25.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58188 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58189 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61723 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61724 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61725 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61730 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58186 | MEDIUM4.5 | stdlib v1.24.6 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33247 | MEDIUM4.5 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-59530 | MEDIUM4.5 | github.com/quic-go/quic-go v0.50.1 fixed in 0.49.1, 0.54.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-64702 | MEDIUM4.5 | github.com/quic-go/quic-go v0.50.1 fixed in 0.57.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-47914 | MEDIUM4.5 | golang.org/x/crypto v0.36.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58181 | MEDIUM4.5 | golang.org/x/crypto v0.36.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-54410 | MEDIUM4.42 | github.com/docker/docker v25.0.8+incompatible fixed in 25.0.13, 28.0.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33222 | MEDIUM4.17 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33248 | MEDIUM4.08 | github.com/nats-io/nats-server/v2 v2.11.6 fixed in 2.11.15, 2.12.6 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-22870 | LOW3.74 | golang.org/x/net v0.35.0 fixed in 0.36.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-26958 | LOW3.15 | filippo.io/edwards25519 v1.1.0 fixed in 1.1.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-67499 | LOW3.06 | github.com/containernetworking/plugins v1.7.1 fixed in 1.9.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-41889 | LOW3 | github.com/jackc/pgx/v5 v5.7.5 fixed in 5.9.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34040 | LOW2.81 | github.com/docker/docker v25.0.8+incompatible fixed in 29.3.1 | 8.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-33816 | LOW2.54 | github.com/jackc/pgx/v5 v5.7.5 fixed in 5.9.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-33997 | LOW2.48 | github.com/docker/docker v25.0.8+incompatible fixed in 29.3.1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-15558 | LOW2.45 | github.com/docker/cli v28.3.2+incompatible fixed in 29.2.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-68156 | LOW2.29 | github.com/expr-lang/expr v1.17.5 fixed in 1.17.7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-21434 | LOW2.29 | github.com/quic-go/webtransport-go v0.8.1-0.20241018022711-4ac2c9250e66 fixed in 0.10.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-21435 | LOW2.29 | github.com/quic-go/webtransport-go v0.8.1-0.20241018022711-4ac2c9250e66 fixed in 0.10.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-27139 | LOW2.12 | stdlib v1.24.6 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | NONE0 | stdlib v1.24.6 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.24.6 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.24.6 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.24.6 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.24.6 fixed in 1.25.11, 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.24.6 fixed in 1.25.11, 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-41567 | NONE0 | github.com/docker/docker v25.0.8+incompatible No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-41568 | NONE0 | github.com/docker/docker v25.0.8+incompatible No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35480 | NONE0 | github.com/ipld/go-ipld-prime v0.21.0 fixed in 0.22.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-42328 | NONE0 | github.com/ipld/go-ipld-prime v0.21.0 fixed in 0.23.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-49140 | NONE0 | github.com/pion/interceptor v0.1.37 fixed in 0.1.39 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21438 | NONE0 | github.com/quic-go/webtransport-go v0.8.1-0.20241018022711-4ac2c9250e66 fixed in 0.10.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-24051 | NONE0 | go.opentelemetry.io/otel/sdk v1.37.0 fixed in 1.40.0 | 0.2% Theoretical Threat | Not Applicable |