This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could bypass authentication, perform man-in-the-middle attacks, or cause denial of service, potentially leading to unauthorized access or disruption of the Redis service. Specifically, CVE-2026-42010 could lead to authentication bypass if Redis uses gnutls with RSA-PSK for authentication, and other issues like CVE-2026-42013 affect certificate validation when TLS is configured. These vulnerabilities, particularly those in the gnutls library, are highly impactful, making this image unsuitable for environments requiring strong security guarantees without significant mitigation.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-42010 | HIGH7.84 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42013 | MEDIUM6.56 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2019-9192 | MEDIUM6.38 | libc-bin 2.36-9+deb12u14 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2019-9192 | MEDIUM6.38 | libc6 2.36-9+deb12u14 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-41989 | MEDIUM6.38 | libgcrypt20 1.10.1-3 fixed in 1.10.1-3+deb12u1 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33846 | MEDIUM6.38 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3833 | MEDIUM6.29 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42011 | MEDIUM5.92 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42012 | MEDIUM5.68 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.36-9+deb12u14 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.36-9+deb12u14 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42015 | MEDIUM5.3 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libblkid1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libmount1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libsmartcols1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libuuid1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.36-9+deb12u14 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.36-9+deb12u14 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-2236 | MEDIUM5.02 | libgcrypt20 1.10.1-3 No fix yet | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.02 | libtasn1-6 4.19.0-2+deb12u1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42250 | MEDIUM5 | libbz2-1.0 1.0.8-5+b1 No fix yet | — | Directly Exposed |
| CVE-2026-5260 | MEDIUM4.92 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Directly Exposed |
| CVE-2026-48962 | MEDIUM4.68 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Post-Exploit |
| CVE-2022-27943 | MEDIUM4.67 | gcc-12-base 12.2.0-14+deb12u1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libblkid1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libgcc-s1 12.2.0-14+deb12u1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libmount1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libsmartcols1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libstdc++6 12.2.0-14+deb12u1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libuuid1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.2.13.dfsg-1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libblkid1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2019-1010024 | MEDIUM4.5 | libc-bin 2.36-9+deb12u14 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2019-1010025 | MEDIUM4.5 | libc-bin 2.36-9+deb12u14 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2019-1010024 | MEDIUM4.5 | libc6 2.36-9+deb12u14 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2019-1010025 | MEDIUM4.5 | libc6 2.36-9+deb12u14 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | liblzma5 5.4.1-1 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libmount1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libsmartcols1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libsystemd0 252.39-1~deb12u2 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libsystemd0 252.39-1~deb12u2 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libsystemd0 252.39-1~deb12u2 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libudev1 252.39-1~deb12u2 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libudev1 252.39-1~deb12u2 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libudev1 252.39-1~deb12u2 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libuuid1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2011-3389 | MEDIUM4.3 | libgnutls30 3.7.9-2+deb12u6 No fix yet | 3.9% Low-Moderate Risk | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.36-9+deb12u14 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.36-9+deb12u14 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.36-9+deb12u14 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.36-9+deb12u14 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-31486 | MEDIUM4.13 | perl-base 5.36.0-7+deb12u3 No fix yet | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2011-3374 | LOW3.7 | libapt-pkg6.0 2.6.1 No fix yet | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2026-5419 | LOW3.7 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Directly Exposed |
| CVE-2005-2541 | LOW3.6 | tar 1.34+dfsg-1.2+deb12u1 No fix yet | 3.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-8376 | LOW3.53 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Post-Exploit |
| CVE-2023-45853 | LOW3.53 | zlib1g 1:1.2.13.dfsg-1 No fix yet | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2010-4756 | LOW3.4 | libc-bin 2.36-9+deb12u14 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2010-4756 | LOW3.4 | libc6 2.36-9+deb12u14 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2016-2781 | LOW3.31 | coreutils 9.1-1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-42496 | LOW3.28 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | bsdutils 1:2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | mount 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | util-linux 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | util-linux-extra 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2019-1010022 | LOW3 | libc-bin 2.36-9+deb12u14 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2019-1010022 | LOW3 | libc6 2.36-9+deb12u14 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | bsdutils 1:2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | mount 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.34+dfsg-1.2+deb12u1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | util-linux 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | util-linux-extra 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2013-4392 | LOW2.8 | libsystemd0 252.39-1~deb12u2 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd0 252.39-1~deb12u2 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libudev1 252.39-1~deb12u2 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 252.39-1~deb12u2 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33845 | LOW2.78 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2018-20796 | LOW2.7 | libc-bin 2.36-9+deb12u14 No fix yet | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2018-20796 | LOW2.7 | libc6 2.36-9+deb12u14 No fix yet | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42009 | LOW2.7 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Post-Exploit |
| CVE-2026-42497 | LOW2.7 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Post-Exploit |
| CVE-2026-9538 | LOW2.7 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | bsdutils 1:2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | mount 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | util-linux 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | util-linux-extra 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2019-1010023 | LOW2.69 | libc-bin 2.36-9+deb12u14 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2019-1010023 | LOW2.69 | libc6 2.36-9+deb12u14 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2007-5686 | LOW2.5 | login 1:4.13+dfsg1-1+deb12u2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2007-5686 | LOW2.5 | passwd 1:4.13+dfsg1-1+deb12u2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2017-18018 | LOW2.4 | coreutils 9.1-1 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-30258 | LOW2.4 | gpgv 2.2.40-1.1+deb12u2 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gpgv 2.2.40-1.1+deb12u2 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux-extra 2.38.1-5+deb12u3 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2018-6829 | LOW2.29 | libgcrypt20 1.10.1-3 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-5278 | LOW2.24 | coreutils 9.1-1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW2.22 | apt 2.6.1 No fix yet | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2024-56433 | LOW2.16 | login 1:4.13+dfsg1-1+deb12u2 No fix yet | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2024-56433 | LOW2.16 | passwd 1:4.13+dfsg1-1+deb12u2 No fix yet | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2022-3219 | LOW1.68 | gpgv 2.2.40-1.1+deb12u2 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2011-4116 | LOW1.68 | perl-base 5.36.0-7+deb12u3 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69720 | NONE0 | libtinfo6 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-base 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-bin 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libtinfo6 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-base 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-bin 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-modules 1.5.2-6+deb12u2 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-modules-bin 1.5.2-6+deb12u2 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-runtime 1.5.2-6+deb12u2 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam0g 1.5.2-6+deb12u2 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libtinfo6 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-base 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-bin 6.4-4 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| TEMP-0841856-B18BAF | NONE0 | bash 5.2.15-2+b13 No fix yet | — | Not Applicable |
| CVE-2026-42014 | NONE0 | libgnutls30 3.7.9-2+deb12u6 fixed in 3.7.9-2+deb12u7 | — | Not Applicable |
| CVE-2025-27587 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-34180 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-34182 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-42766 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-42767 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-42770 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-45445 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-45446 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-45447 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-7383 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| CVE-2026-9076 | NONE0 | libssl3 3.0.20-1~deb12u1 No fix yet | — | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | login 1:4.13+dfsg1-1+deb12u2 No fix yet | — | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | passwd 1:4.13+dfsg1-1+deb12u2 No fix yet | — | Not Applicable |
| CVE-2026-48959 | NONE0 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Not Applicable |
| CVE-2025-15649 | NONE0 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Not Applicable |
| CVE-2026-7010 | NONE0 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Not Applicable |
| CVE-2026-48961 | NONE0 | perl-base 5.36.0-7+deb12u3 No fix yet | — | Not Applicable |
| TEMP-0517018-A83CE6 | NONE0 | sysvinit-utils 3.06-4 No fix yet | — | Not Applicable |
| TEMP-0290435-0B57B5 | NONE0 | tar 1.34+dfsg-1.2+deb12u1 No fix yet | — | Not Applicable |