Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most impactful exposed finding is CVE-2026-56860, a denial-of-service issue in Go net/url path resolution that can be reached through normal HTTP request handling in Sablier's API server, allowing a remote attacker to cause slowdown or outage with crafted paths. It does not require a non-default module or special configuration. The remaining exposed findings stay below severity 7.0, and the post-exploit-only findings are low severity with a maximum of 2.48, so no critical or high-severity risk is present. Patch the Go stdlib when an updated image is available to reduce the attack surface.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-56860 | MEDIUM6.38 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-39821 | MEDIUM4.18 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-56853 | LOW3.83 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-56862 | LOW3.83 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | LOW2.7 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56858 | LOW2.48 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | LOW2.39 | stdlib v1.26.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-27145 | LOW2.29 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-33818 | LOW2.29 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-42504 | LOW2.29 | stdlib v1.26.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-46600 | LOW2.29 | stdlib v1.26.3 fixed in 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-56859 | LOW2.29 | stdlib v1.26.3 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-56855 | LOW1.62 | golang.org/x/crypto v0.55.0 fixed in 0.56.0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-78662 | LOW1.62 | golang.org/x/crypto v0.55.0 fixed in 0.56.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42505 | LOW1.62 | stdlib v1.26.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Post-Exploit |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.55.0 No fix yet | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.