Vulnerability Reportredis:7

redis:7.4.9-bookwormredis:7.4.9redis:7.4-bookwormredis:7.4redis:7-bookwormredis:7
DIGESTsha256:d3be87a1060455213a204d2b0a7f04d45d19a16a98e85b3c37b7c33b5f0c489e

Executive Summary

DANGEROUS

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could bypass authentication, perform man-in-the-middle attacks, or cause denial of service, potentially leading to unauthorized access or disruption of the Redis service. Specifically, CVE-2026-42010 could lead to authentication bypass if Redis uses gnutls with RSA-PSK for authentication, and other issues like CVE-2026-42013 affect certificate validation when TLS is configured. These vulnerabilities, particularly those in the gnutls library, are highly impactful, making this image unsuitable for environments requiring strong security guarantees without significant mitigation.

Threat Score
75/100
DANGEROUS
Reputation
TRUSTED
Docker Official
BaseImage/
redis:7
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

142 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42010HIGH7.84
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly ExposedContext importance: MEDIUM
CVE-2026-42013MEDIUM6.56
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly ExposedContext importance: MEDIUM
CVE-2019-9192MEDIUM6.38
libc-bin
2.36-9+deb12u14
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2019-9192MEDIUM6.38
libc6
2.36-9+deb12u14
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-41989MEDIUM6.38
libgcrypt20
1.10.1-3
fixed in 1.10.1-3+deb12u1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33846MEDIUM6.38
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM5.92
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly ExposedContext importance: MEDIUM
CVE-2026-42012MEDIUM5.68
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly ExposedContext importance: MEDIUM
CVE-2026-6238MEDIUM5.52
libc-bin
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc6
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM5.3
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly Exposed
CVE-2025-14104MEDIUM5.18
libblkid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libmount1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libsmartcols1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14104MEDIUM5.18
libuuid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc-bin
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-2236MEDIUM5.02
libgcrypt20
1.10.1-3
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.02
libtasn1-6
4.19.0-2+deb12u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42250MEDIUM5
libbz2-1.0
1.0.8-5+b1
No fix yet
Directly Exposed
CVE-2026-5260MEDIUM4.92
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly Exposed
CVE-2026-48962MEDIUM4.68
perl-base
5.36.0-7+deb12u3
No fix yet
Post-Exploit
CVE-2022-27943MEDIUM4.67
gcc-12-base
12.2.0-14+deb12u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libblkid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc-s1
12.2.0-14+deb12u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libmount1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libsmartcols1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libstdc++6
12.2.0-14+deb12u1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2022-0563MEDIUM4.67
libuuid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.2.13.dfsg-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libblkid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM4.5
libc-bin
2.36-9+deb12u14
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc-bin
2.36-9+deb12u14
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2019-1010024MEDIUM4.5
libc6
2.36-9+deb12u14
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2019-1010025MEDIUM4.5
libc6
2.36-9+deb12u14
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.4.1-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libmount1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libsmartcols1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libsystemd0
252.39-1~deb12u2
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libsystemd0
252.39-1~deb12u2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libsystemd0
252.39-1~deb12u2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31437MEDIUM4.5
libudev1
252.39-1~deb12u2
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31438MEDIUM4.5
libudev1
252.39-1~deb12u2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31439MEDIUM4.5
libudev1
252.39-1~deb12u2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libuuid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2011-3389MEDIUM4.3
libgnutls30
3.7.9-2+deb12u6
No fix yet
3.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc-bin
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc-bin
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
libc6
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
libc6
2.36-9+deb12u14
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2023-31486MEDIUM4.13
perl-base
5.36.0-7+deb12u3
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-27456MEDIUM4
libblkid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2011-3374LOW3.7
libapt-pkg6.0
2.6.1
No fix yet
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-5419LOW3.7
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Directly Exposed
CVE-2005-2541LOW3.6
tar
1.34+dfsg-1.2+deb12u1
No fix yet
3.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-8376LOW3.53
perl-base
5.36.0-7+deb12u3
No fix yet
Post-Exploit
CVE-2023-45853LOW3.53
zlib1g
1:1.2.13.dfsg-1
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2010-4756LOW3.4
libc-bin
2.36-9+deb12u14
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2010-4756LOW3.4
libc6
2.36-9+deb12u14
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2016-2781LOW3.31
coreutils
9.1-1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42496LOW3.28
perl-base
5.36.0-7+deb12u3
No fix yet
Post-Exploit
CVE-2025-14104LOW3.11
bsdutils
1:2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
mount
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
util-linux
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14104LOW3.11
util-linux-extra
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010022LOW3
libc-bin
2.36-9+deb12u14
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010022LOW3
libc6
2.36-9+deb12u14
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
bsdutils
1:2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
mount
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.8
tar
1.34+dfsg-1.2+deb12u1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
util-linux
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2022-0563LOW2.8
util-linux-extra
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2013-4392LOW2.8
libsystemd0
252.39-1~deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libsystemd0
252.39-1~deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2013-4392LOW2.8
libudev1
252.39-1~deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
252.39-1~deb12u2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33845LOW2.78
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
<0.1%
Theoretical Threat
Post-Exploit
CVE-2018-20796LOW2.7
libc-bin
2.36-9+deb12u14
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2018-20796LOW2.7
libc6
2.36-9+deb12u14
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-42009LOW2.7
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Post-Exploit
CVE-2026-42497LOW2.7
perl-base
5.36.0-7+deb12u3
No fix yet
Post-Exploit
CVE-2026-9538LOW2.7
perl-base
5.36.0-7+deb12u3
No fix yet
Post-Exploit
CVE-2026-3184LOW2.7
bsdutils
1:2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
mount
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux-extra
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc-bin
2.36-9+deb12u14
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2019-1010023LOW2.69
libc6
2.36-9+deb12u14
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2007-5686LOW2.5
login
1:4.13+dfsg1-1+deb12u2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2007-5686LOW2.5
passwd
1:4.13+dfsg1-1+deb12u2
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2017-18018LOW2.4
coreutils
9.1-1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-30258LOW2.4
gpgv
2.2.40-1.1+deb12u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpgv
2.2.40-1.1+deb12u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux-extra
2.38.1-5+deb12u3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2018-6829LOW2.29
libgcrypt20
1.10.1-3
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils
9.1-1
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2011-3374LOW2.22
apt
2.6.1
No fix yet
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW2.16
login
1:4.13+dfsg1-1+deb12u2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW2.16
passwd
1:4.13+dfsg1-1+deb12u2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-3219LOW1.68
gpgv
2.2.40-1.1+deb12u2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2011-4116LOW1.68
perl-base
5.36.0-7+deb12u3
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69720NONE0
libtinfo6
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-69720NONE0
ncurses-base
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-69720NONE0
ncurses-bin
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
libtinfo6
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
ncurses-base
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
ncurses-bin
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2024-10041NONE0
libpam-modules
1.5.2-6+deb12u2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2024-10041NONE0
libpam-modules-bin
1.5.2-6+deb12u2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2024-10041NONE0
libpam-runtime
1.5.2-6+deb12u2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2024-10041NONE0
libpam0g
1.5.2-6+deb12u2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
libtinfo6
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
ncurses-base
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2025-6141NONE0
ncurses-bin
6.4-4
No fix yet
<0.1%
Theoretical Threat
Not Applicable
TEMP-0841856-B18BAFNONE0
bash
5.2.15-2+b13
No fix yet
Not Applicable
CVE-2026-42014NONE0
libgnutls30
3.7.9-2+deb12u6
fixed in 3.7.9-2+deb12u7
Not Applicable
CVE-2025-27587NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-34180NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-34182NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-42766NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-42767NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-42770NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-45445NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-45446NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-45447NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-7383NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
CVE-2026-9076NONE0
libssl3
3.0.20-1~deb12u1
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
login
1:4.13+dfsg1-1+deb12u2
No fix yet
Not Applicable
TEMP-0628843-DBAD28NONE0
passwd
1:4.13+dfsg1-1+deb12u2
No fix yet
Not Applicable
CVE-2026-48959NONE0
perl-base
5.36.0-7+deb12u3
No fix yet
Not Applicable
CVE-2025-15649NONE0
perl-base
5.36.0-7+deb12u3
No fix yet
Not Applicable
CVE-2026-7010NONE0
perl-base
5.36.0-7+deb12u3
No fix yet
Not Applicable
CVE-2026-48961NONE0
perl-base
5.36.0-7+deb12u3
No fix yet
Not Applicable
TEMP-0517018-A83CE6NONE0
sysvinit-utils
3.06-4
No fix yet
Not Applicable
TEMP-0290435-0B57B5NONE0
tar
1.34+dfsg-1.2+deb12u1
No fix yet
Not Applicable