Vulnerability Reporttecnativa/docker-socket-proxy:v0.5.0

tecnativa/docker-socket-proxy:latesttecnativa/docker-socket-proxy:v0.5.0
digestsha256:1f5038b54f06c3e18422902cf00ba21803d1c97805aae032e5e6673d532d3459

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. It does carry a small number of known issues - 2 on the exposed surface with a maximum severity of 3.15, plus 18 post-exploit-only findings with a maximum severity of 2.7 - but all of these are low severity and none reach the threshold where they would meaningfully change the risk posture of a socket proxy. Because the entry point is HAProxy fronting the Docker API, the practical risk is governed far more by which ALLOW_* API groups the operator enables and whether AUTH is turned on than by these low-severity items. The image is also pinned by digest and comes from a long-established publisher with over 71 million pulls, which supports reproducibility and supply-chain confidence. Standard hygiene still applies: enable AUTH, disable any unused ALLOW_* endpoints, and rebuild on digest updates.

Vulnerabilities

Vulnerability Log

20 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-75803LOW3.15
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-75803LOW3.15
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-18798LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63072LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-14457LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-54874LOW2.7
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-18798LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-63072LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-63076LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-14457LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-54874LOW2.7
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-14456LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-63074LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-63075LOW2.29
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-63073LOW2.12
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-63073LOW2.12
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.2%
Low-Moderate Risk
Post-Exploit

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.