Vulnerability Reportsablierapp/sablier:latest

sablierapp/sablier:latestsablierapp/sablier:1.18.0
digestsha256:c00c8a01c8c809dd258a8b362ad8ba9a9227753fc9857ae7506fd427175e038c

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
UNVERIFIED

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most impactful exposed finding is CVE-2026-56860, a denial-of-service issue in Go net/url path resolution that can be reached through normal HTTP request handling in Sablier's API server, allowing a remote attacker to cause slowdown or outage with crafted paths. It does not require a non-default module or special configuration. The remaining exposed findings stay below severity 7.0, and the post-exploit-only findings are low severity with a maximum of 2.48, so no critical or high-severity risk is present. Patch the Go stdlib when an updated image is available to reduce the attack surface.

Vulnerabilities

Vulnerability Log

16 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-56860MEDIUM6.38
stdlib
v1.26.3
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39821MEDIUM4.18
stdlib
v1.26.3
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-56853LOW3.83
stdlib
v1.26.3
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-56862LOW3.83
stdlib
v1.26.3
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42507LOW2.7
stdlib
v1.26.3
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-56858LOW2.48
stdlib
v1.26.3
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.26.3
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27145LOW2.29
stdlib
v1.26.3
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33818LOW2.29
stdlib
v1.26.3
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42504LOW2.29
stdlib
v1.26.3
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-46600LOW2.29
stdlib
v1.26.3
fixed in 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-56859LOW2.29
stdlib
v1.26.3
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-56855LOW1.62
golang.org/x/crypto
v0.55.0
fixed in 0.56.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-78662LOW1.62
golang.org/x/crypto
v0.55.0
fixed in 0.56.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42505LOW1.62
stdlib
v1.26.3
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Post-Exploit
GO-2026-5932NONE0
golang.org/x/crypto
v0.55.0
No fix yet
—
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.