Last scanned:
This image is safe for production use. While it contains 42 exposed and 36 post-exploit packages with known vulnerabilities, none exceed medium severity and all are below the actionable threshold. The image's high popularity, immutability, and reliable publisher further support deployment confidence. No CVEs require immediate attention.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-42764 | MEDIUM5.9 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-27904 | MEDIUM5.52 | minimatch 10.1.1 fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33671 | MEDIUM5.52 | picomatch 4.0.3 fixed in 4.0.4, 3.0.2, 2.3.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-1527 | MEDIUM5.52 | undici 6.23.0 fixed in 6.24.0, 7.24.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2017-16137 | MEDIUM5.3 | debug 4.1.1 fixed in 2.6.9, 3.1.0, 3.2.7, 4.3.1 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42338 | MEDIUM5.18 | ip-address 10.1.0 fixed in 10.1.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-48779 | MEDIUM5.1 | ws 6.2.3 fixed in 5.2.5, 6.2.4, 7.5.11, 8.21.0 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-48779 | MEDIUM5.1 | ws 7.5.10 fixed in 5.2.5, 6.2.4, 7.5.11, 8.21.0 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42769 | MEDIUM5.02 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-27903 | MEDIUM5.02 | minimatch 10.1.1 fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-48815 | MEDIUM5.02 | sigstore 3.1.0 fixed in 4.1.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-9679 | MEDIUM5.02 | undici 6.23.0 fixed in 6.27.0, 7.28.0, 8.5.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-48758 | MEDIUM4.59 | @sigstore/core 2.0.0 fixed in 3.2.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54285 | MEDIUM4.5 | @opentelemetry/core 2.7.1 fixed in 2.8.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-53550 | MEDIUM4.5 | js-yaml 4.1.1 fixed in 4.2.0, 3.15.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-33672 | MEDIUM4.5 | picomatch 4.0.3 fixed in 4.0.4, 3.0.2, 2.3.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-29786 | LOW3.21 | tar 7.5.9 fixed in 7.5.10 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW3.15 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-47764 | LOW3.15 | cookie 0.4.2 fixed in 0.7.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-11525 | LOW3.15 | undici 6.23.0 fixed in 6.27.0, 7.28.0, 8.5.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6733 | LOW3.15 | undici 6.23.0 fixed in 6.27.0, 7.28.0, 8.5.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-1525 | LOW3 | undici 6.23.0 fixed in 6.24.0, 7.24.0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-53655 | LOW2.8 | tar 7.5.11 fixed in 7.5.16 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-31802 | LOW2.8 | tar 7.5.9 fixed in 7.5.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-53655 | LOW2.8 | tar 7.5.9 fixed in 7.5.16 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-1526 | LOW2.7 | undici 6.23.0 fixed in 6.24.0, 7.24.0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-59875 | LOW2.7 | tar 7.5.11 fixed in 7.5.17 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59875 | LOW2.7 | tar 7.5.9 fixed in 7.5.17 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-13149 | LOW2.29 | brace-expansion 2.0.2 fixed in 5.0.7, 1.1.16, 2.1.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-33750 | LOW2.29 | brace-expansion 2.0.2 fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-13149 | LOW2.29 | brace-expansion 5.0.4 fixed in 5.0.7, 1.1.16, 2.1.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-33750 | LOW2.29 | brace-expansion 5.0.4 fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-45149 | LOW2.29 | brace-expansion 5.0.4 fixed in 5.0.6 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59869 | LOW2.29 | js-yaml 4.1.1 fixed in 3.15.0, 4.3.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-26996 | LOW2.29 | minimatch 10.1.1 fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-33151 | LOW2.29 | socket.io-parser 3.3.4 fixed in 3.3.5, 3.4.4, 4.2.6 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-33151 | LOW2.29 | socket.io-parser 3.4.3 fixed in 3.3.5, 3.4.4, 4.2.6 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-59873 | LOW2.29 | tar 7.5.11 fixed in 7.5.19 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59874 | LOW2.29 | tar 7.5.11 fixed in 7.5.18 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59871 | LOW2.29 | tar 7.5.11 fixed in 7.5.18 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59873 | LOW2.29 | tar 7.5.9 fixed in 7.5.19 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59874 | LOW2.29 | tar 7.5.9 fixed in 7.5.18 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-59871 | LOW2.29 | tar 7.5.9 fixed in 7.5.18 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-12151 | LOW2.29 | undici 6.23.0 fixed in 6.27.0, 7.28.0, 8.5.0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-1528 | LOW2.29 | undici 6.23.0 fixed in 6.24.0, 7.24.0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-2229 | LOW2.29 | undici 6.23.0 fixed in 6.24.0, 7.24.0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW2.26 | libcrypto3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW2.26 | libssl3 3.5.6-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-14257 | NONE0 | brace-expansion 2.0.2 fixed in 5.0.8 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-14257 | NONE0 | brace-expansion 5.0.4 fixed in 5.0.8 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-36751 | NONE0 | parseuri 0.0.6 fixed in 2.0.0 | 0.5% Theoretical Threat | Not Applicable |
| GHSA-r292-9mhp-454m | NONE0 | tar 7.5.11 fixed in 7.5.21 | — | Not Applicable |
| GHSA-r292-9mhp-454m | NONE0 | tar 7.5.9 fixed in 7.5.21 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.