This image poses a critical security risk and must not be used in production, especially as an internet-facing service. Exploitation could lead to severe consequences including loss of data confidentiality, integrity bypass, and potentially remote code execution or denial of service. A total of 30 vulnerabilities were detected, with the highest severity findings related to OpenSSL (CVE-2026-45445, CVE-2026-45447). It is crucial to verify if the container's application uses the specific, less-recommended OpenSSL APIs or acts as a QUIC client/server, as these are conditions for some of the critical vulnerabilities to be exploitable. Due to the DANGEROUS threat score, this image requires immediate remediation or replacement.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-45445 | HIGH7.28 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-45445 | HIGH7.28 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-45447 | MEDIUM6.48 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-45447 | MEDIUM6.48 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34181 | MEDIUM6.3 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42768 | MEDIUM6.3 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-34181 | MEDIUM6.3 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42768 | MEDIUM6.3 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-34183 | MEDIUM6 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34183 | MEDIUM6 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34182 | MEDIUM5.92 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34182 | MEDIUM5.92 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-9076 | MEDIUM5.9 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-7383 | MEDIUM5.5 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-7383 | MEDIUM5.5 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42766 | MEDIUM5.3 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42767 | MEDIUM5.3 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42766 | MEDIUM5.3 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42767 | MEDIUM5.3 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-9076 | MEDIUM4.72 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-45446 | LOW3.7 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-45446 | LOW3.7 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42764 | LOW3.54 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42769 | LOW3.54 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42770 | LOW3.54 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42764 | LOW3.54 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42769 | LOW3.54 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |
| CVE-2026-42770 | LOW3.54 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | — | Directly Exposed |