Vulnerability Reportredislabs/redisinsight:3.8.0

redislabs/redisinsight:latestredislabs/redisinsight:3.8redislabs/redisinsight:3.8.0
DIGESTsha256:b5e19ee240abef6edb435871b90ff8a210995422e8e018ab61c0339d318a1f84

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could cause denial of service through multiple vectors (e.g., CVE-2026-59725, CVE-2026-26996) and under specific conditions achieve arbitrary code execution via CVE-2026-4800 if the application passes untrusted input to lodash template imports. Note that CVE-2026-4800 only applies if untrusted input reaches the template imports option. Upgrading to the latest versions of lodash, engine.io, minimatch, multer, and ws would resolve these vulnerabilities.

Vulnerabilities

Vulnerability Log

78 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-4800HIGH7.84
lodash
4.17.21
fixed in 4.18.0
1.7%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-59725MEDIUM6.38
engine.io
6.6.2
fixed in 6.6.7
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-59869MEDIUM6.38
js-yaml
4.1.1
fixed in 3.15.0, 4.3.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-26996MEDIUM6.38
minimatch
9.0.5
fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-2359MEDIUM6.38
multer
2.0.2
fixed in 2.1.0
0.7%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-3304MEDIUM6.38
multer
2.0.2
fixed in 2.1.0
0.7%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-3520MEDIUM6.38
multer
2.0.2
fixed in 2.1.1
0.7%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-5038MEDIUM6.38
multer
2.0.2
fixed in 2.2.0, 3.0.0-alpha.2
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-48779MEDIUM6.38
ws
8.17.1
fixed in 5.2.5, 6.2.4, 7.5.11, 8.21.0
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-48815MEDIUM5.9
sigstore
3.1.0
fixed in 4.1.1
Directly Exposed
CVE-2026-27904MEDIUM5.52
minimatch
9.0.5
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33671MEDIUM5.52
picomatch
4.0.2
fixed in 4.0.4, 3.0.2, 2.3.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-48758MEDIUM5.4
@sigstore/core
2.0.0
fixed in 3.2.1
Directly Exposed
CVE-2025-13465MEDIUM5.3
lodash
4.17.21
fixed in 4.17.23
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-39244MEDIUM5.2
adm-zip
0.5.10
fixed in 0.6.0
Directly ExposedContext importance: MEDIUM
CVE-2026-42338MEDIUM5.18
ip-address
9.0.5
fixed in 10.1.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-13149MEDIUM5.1
brace-expansion
2.0.2
fixed in 5.0.7, 1.1.16, 2.1.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33750MEDIUM5.1
brace-expansion
2.0.2
fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-2391MEDIUM5.1
qs
6.13.0
fixed in 6.14.2
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-2391MEDIUM5.1
qs
6.14.0
fixed in 6.14.2
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-45736MEDIUM5.1
ws
8.17.1
fixed in 8.20.1
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-12590MEDIUM5.02
body-parser
1.20.3
fixed in 1.20.6, 2.3.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-12590MEDIUM5.02
body-parser
2.2.1
fixed in 1.20.6, 2.3.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27903MEDIUM5.02
minimatch
9.0.5
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4923MEDIUM5.02
path-to-regexp
8.2.0
fixed in 8.4.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31808MEDIUM4.5
file-type
16.5.4
fixed in 21.3.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-31808MEDIUM4.5
file-type
20.4.1
fixed in 21.3.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32630MEDIUM4.5
file-type
20.4.1
fixed in 21.3.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-53550MEDIUM4.5
js-yaml
4.1.1
fixed in 4.2.0, 3.15.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2950MEDIUM4.5
lodash
4.17.21
fixed in 4.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33672MEDIUM4.5
picomatch
4.0.2
fixed in 4.0.4, 3.0.2, 2.3.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-40200LOW3.98
musl-utils
1.2.5-r21
fixed in 1.2.5-r23
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15284LOW3.83
qs
6.13.0
fixed in 6.14.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-15284LOW3.83
qs
6.14.0
fixed in 6.14.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-26960LOW3.62
tar
6.2.1
fixed in 7.5.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-26960LOW3.62
tar
7.4.3
fixed in 7.5.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-29786LOW3.21
tar
6.2.1
fixed in 7.5.10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-29786LOW3.21
tar
7.4.3
fixed in 7.5.10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-23745LOW3.11
tar
6.2.1
fixed in 7.5.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23745LOW3.11
tar
7.4.3
fixed in 7.5.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6042LOW2.8
musl-utils
1.2.5-r21
fixed in 1.2.5-r22
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31802LOW2.8
tar
6.2.1
fixed in 7.5.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-53655LOW2.8
tar
6.2.1
fixed in 7.5.16
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-31802LOW2.8
tar
7.4.3
fixed in 7.5.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-53655LOW2.8
tar
7.4.3
fixed in 7.5.16
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-64756LOW2.7
glob
10.4.5
fixed in 11.1.0, 10.5.0
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-59875LOW2.7
tar
6.2.1
fixed in 7.5.17
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59875LOW2.7
tar
7.4.3
fixed in 7.5.17
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-24842LOW2.51
tar
6.2.1
fixed in 7.5.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-24842LOW2.51
tar
7.4.3
fixed in 7.5.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-22184LOW2.39
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-24001LOW2.29
diff
4.0.2
fixed in 8.0.3, 5.2.2, 4.0.4, 3.5.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-24001LOW2.29
diff
5.2.0
fixed in 8.0.3, 5.2.2, 4.0.4, 3.5.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-12143LOW2.29
form-data
4.0.5
fixed in 2.5.6, 3.0.5, 4.0.6
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4926LOW2.29
path-to-regexp
8.2.0
fixed in 8.4.0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-59873LOW2.29
tar
6.2.1
fixed in 7.5.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59874LOW2.29
tar
6.2.1
fixed in 7.5.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59871LOW2.29
tar
6.2.1
fixed in 7.5.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59873LOW2.29
tar
7.4.3
fixed in 7.5.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59874LOW2.29
tar
7.4.3
fixed in 7.5.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59871LOW2.29
tar
7.4.3
fixed in 7.5.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
8.3.2
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23950LOW1.81
tar
6.2.1
fixed in 7.5.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-23950LOW1.81
tar
7.4.3
fixed in 7.5.4
0.2%
Theoretical Threat
Post-Exploit
GHSA-gcfj-64vw-6mp9NONE0
axios
1.16.0
fixed in 0.33.0, 1.18.0
Not Applicable
GHSA-42h9-826w-cgv3NONE0
axios
1.16.0
fixed in 0.33.0, 1.18.0
Not Applicable
GHSA-7q8q-rj6j-mhjqNONE0
axios
1.16.0
fixed in 0.33.0, 1.18.0
Not Applicable
GHSA-f4gw-2p7v-4548NONE0
axios
1.16.0
fixed in 1.18.0, 0.33.0
Not Applicable
GHSA-hcpx-6fm6-wx23NONE0
axios
1.16.0
fixed in 0.33.0, 1.18.0
Not Applicable
GHSA-jqh4-m9w3-8hp9NONE0
axios
1.16.0
fixed in 1.18.0
Not Applicable
GHSA-mmx7-hfxf-jppxNONE0
axios
1.16.0
fixed in 1.18.0, 0.33.0
Not Applicable
GHSA-mwf2-3pr3-8698NONE0
axios
1.16.0
fixed in 1.18.0
Not Applicable
GHSA-pmv8-rq9r-6j72NONE0
axios
1.16.0
fixed in 0.33.0, 1.18.0
Not Applicable
GHSA-xj6q-8x83-jv6gNONE0
axios
1.16.0
fixed in 1.18.0
Not Applicable
CVE-2026-5079NONE0
multer
2.0.2
fixed in 2.2.0, 3.0.0-alpha.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-8723NONE0
qs
6.13.0
fixed in 6.15.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-8723NONE0
qs
6.14.0
fixed in 6.15.2
0.4%
Theoretical Threat
Not Applicable

Want to check another image? Run a full scan with the Docker Security Scanner.