Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could cause denial of service through multiple vectors (e.g., CVE-2026-59725, CVE-2026-26996) and under specific conditions achieve arbitrary code execution via CVE-2026-4800 if the application passes untrusted input to lodash template imports. Note that CVE-2026-4800 only applies if untrusted input reaches the template imports option. Upgrading to the latest versions of lodash, engine.io, minimatch, multer, and ws would resolve these vulnerabilities.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-4800 | HIGH7.84 | lodash 4.17.21 fixed in 4.18.0 | 1.7% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59725 | MEDIUM6.38 | engine.io 6.6.2 fixed in 6.6.7 | 0.4% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-59869 | MEDIUM6.38 | js-yaml 4.1.1 fixed in 3.15.0, 4.3.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-26996 | MEDIUM6.38 | minimatch 9.0.5 fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-2359 | MEDIUM6.38 | multer 2.0.2 fixed in 2.1.0 | 0.7% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-3304 | MEDIUM6.38 | multer 2.0.2 fixed in 2.1.0 | 0.7% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-3520 | MEDIUM6.38 | multer 2.0.2 fixed in 2.1.1 | 0.7% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-5038 | MEDIUM6.38 | multer 2.0.2 fixed in 2.2.0, 3.0.0-alpha.2 | 0.3% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-48779 | MEDIUM6.38 | ws 8.17.1 fixed in 5.2.5, 6.2.4, 7.5.11, 8.21.0 | 0.8% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-48815 | MEDIUM5.9 | sigstore 3.1.0 fixed in 4.1.1 | — | Directly Exposed |
| CVE-2026-27904 | MEDIUM5.52 | minimatch 9.0.5 fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33671 | MEDIUM5.52 | picomatch 4.0.2 fixed in 4.0.4, 3.0.2, 2.3.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48758 | MEDIUM5.4 | @sigstore/core 2.0.0 fixed in 3.2.1 | — | Directly Exposed |
| CVE-2025-13465 | MEDIUM5.3 | lodash 4.17.21 fixed in 4.17.23 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2026-39244 | MEDIUM5.2 | adm-zip 0.5.10 fixed in 0.6.0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42338 | MEDIUM5.18 | ip-address 9.0.5 fixed in 10.1.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-13149 | MEDIUM5.1 | brace-expansion 2.0.2 fixed in 5.0.7, 1.1.16, 2.1.2 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33750 | MEDIUM5.1 | brace-expansion 2.0.2 fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-2391 | MEDIUM5.1 | qs 6.13.0 fixed in 6.14.2 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-2391 | MEDIUM5.1 | qs 6.14.0 fixed in 6.14.2 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-45736 | MEDIUM5.1 | ws 8.17.1 fixed in 8.20.1 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-12590 | MEDIUM5.02 | body-parser 1.20.3 fixed in 1.20.6, 2.3.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-12590 | MEDIUM5.02 | body-parser 2.2.1 fixed in 1.20.6, 2.3.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27903 | MEDIUM5.02 | minimatch 9.0.5 fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-4923 | MEDIUM5.02 | path-to-regexp 8.2.0 fixed in 8.4.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-31808 | MEDIUM4.5 | file-type 16.5.4 fixed in 21.3.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-31808 | MEDIUM4.5 | file-type 20.4.1 fixed in 21.3.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-32630 | MEDIUM4.5 | file-type 20.4.1 fixed in 21.3.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-53550 | MEDIUM4.5 | js-yaml 4.1.1 fixed in 4.2.0, 3.15.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-2950 | MEDIUM4.5 | lodash 4.17.21 fixed in 4.18.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33672 | MEDIUM4.5 | picomatch 4.0.2 fixed in 4.0.4, 3.0.2, 2.3.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | LOW3.98 | musl-utils 1.2.5-r21 fixed in 1.2.5-r23 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15284 | LOW3.83 | qs 6.13.0 fixed in 6.14.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-15284 | LOW3.83 | qs 6.14.0 fixed in 6.14.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-26960 | LOW3.62 | tar 6.2.1 fixed in 7.5.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-26960 | LOW3.62 | tar 7.4.3 fixed in 7.5.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-29786 | LOW3.21 | tar 6.2.1 fixed in 7.5.10 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-29786 | LOW3.21 | tar 7.4.3 fixed in 7.5.10 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-23745 | LOW3.11 | tar 6.2.1 fixed in 7.5.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-23745 | LOW3.11 | tar 7.4.3 fixed in 7.5.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6042 | LOW2.8 | musl-utils 1.2.5-r21 fixed in 1.2.5-r22 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31802 | LOW2.8 | tar 6.2.1 fixed in 7.5.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-53655 | LOW2.8 | tar 6.2.1 fixed in 7.5.16 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-31802 | LOW2.8 | tar 7.4.3 fixed in 7.5.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-53655 | LOW2.8 | tar 7.4.3 fixed in 7.5.16 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-64756 | LOW2.7 | glob 10.4.5 fixed in 11.1.0, 10.5.0 | 3.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-59875 | LOW2.7 | tar 6.2.1 fixed in 7.5.17 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59875 | LOW2.7 | tar 7.4.3 fixed in 7.5.17 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-24842 | LOW2.51 | tar 6.2.1 fixed in 7.5.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-24842 | LOW2.51 | tar 7.4.3 fixed in 7.5.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-22184 | LOW2.39 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-24001 | LOW2.29 | diff 4.0.2 fixed in 8.0.3, 5.2.2, 4.0.4, 3.5.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-24001 | LOW2.29 | diff 5.2.0 fixed in 8.0.3, 5.2.2, 4.0.4, 3.5.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-12143 | LOW2.29 | form-data 4.0.5 fixed in 2.5.6, 3.0.5, 4.0.6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4926 | LOW2.29 | path-to-regexp 8.2.0 fixed in 8.4.0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-59873 | LOW2.29 | tar 6.2.1 fixed in 7.5.19 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59874 | LOW2.29 | tar 6.2.1 fixed in 7.5.18 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59871 | LOW2.29 | tar 6.2.1 fixed in 7.5.18 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59873 | LOW2.29 | tar 7.4.3 fixed in 7.5.19 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59874 | LOW2.29 | tar 7.4.3 fixed in 7.5.18 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59871 | LOW2.29 | tar 7.4.3 fixed in 7.5.18 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-41907 | LOW2.29 | uuid 8.3.2 fixed in 11.1.1, 12.0.1, 13.0.1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-23950 | LOW1.81 | tar 6.2.1 fixed in 7.5.4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-23950 | LOW1.81 | tar 7.4.3 fixed in 7.5.4 | 0.2% Theoretical Threat | Post-Exploit |
| GHSA-gcfj-64vw-6mp9 | NONE0 | axios 1.16.0 fixed in 0.33.0, 1.18.0 | — | Not Applicable |
| GHSA-42h9-826w-cgv3 | NONE0 | axios 1.16.0 fixed in 0.33.0, 1.18.0 | — | Not Applicable |
| GHSA-7q8q-rj6j-mhjq | NONE0 | axios 1.16.0 fixed in 0.33.0, 1.18.0 | — | Not Applicable |
| GHSA-f4gw-2p7v-4548 | NONE0 | axios 1.16.0 fixed in 1.18.0, 0.33.0 | — | Not Applicable |
| GHSA-hcpx-6fm6-wx23 | NONE0 | axios 1.16.0 fixed in 0.33.0, 1.18.0 | — | Not Applicable |
| GHSA-jqh4-m9w3-8hp9 | NONE0 | axios 1.16.0 fixed in 1.18.0 | — | Not Applicable |
| GHSA-mmx7-hfxf-jppx | NONE0 | axios 1.16.0 fixed in 1.18.0, 0.33.0 | — | Not Applicable |
| GHSA-mwf2-3pr3-8698 | NONE0 | axios 1.16.0 fixed in 1.18.0 | — | Not Applicable |
| GHSA-pmv8-rq9r-6j72 | NONE0 | axios 1.16.0 fixed in 0.33.0, 1.18.0 | — | Not Applicable |
| GHSA-xj6q-8x83-jv6g | NONE0 | axios 1.16.0 fixed in 1.18.0 | — | Not Applicable |
| CVE-2026-5079 | NONE0 | multer 2.0.2 fixed in 2.2.0, 3.0.0-alpha.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-8723 | NONE0 | qs 6.13.0 fixed in 6.15.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-8723 | NONE0 | qs 6.14.0 fixed in 6.15.2 | 0.4% Theoretical Threat | Not Applicable |
Want to check another image? Run a full scan with the Docker Security Scanner.