Last scanned:
This image is safe for production use. It does carry a small number of known issues - 2 on the exposed surface with a maximum severity of 3.15, plus 18 post-exploit-only findings with a maximum severity of 2.7 - but all of these are low severity and none reach the threshold where they would meaningfully change the risk posture of a socket proxy. Because the entry point is HAProxy fronting the Docker API, the practical risk is governed far more by which ALLOW_* API groups the operator enables and whether AUTH is turned on than by these low-severity items. The image is also pinned by digest and comes from a long-established publisher with over 71 million pulls, which supports reproducibility and supply-chain confidence. Standard hygiene still applies: enable AUTH, disable any unused ALLOW_* endpoints, and rebuild on digest updates.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-75803 | LOW3.15 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-75803 | LOW3.15 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-18798 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63072 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63076 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-14457 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-54874 | LOW2.7 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-18798 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63072 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63076 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-14457 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-54874 | LOW2.7 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-14456 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-63074 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-63075 | LOW2.29 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-14456 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-63074 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-63075 | LOW2.29 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-63073 | LOW2.12 | libcrypto3 3.5.7-r0 fixed in 3.5.8-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-63073 | LOW2.12 | libssl3 3.5.7-r0 fixed in 3.5.8-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.