Vulnerability Reportthanosio/thanos:main-2026-06-15-42acfa1

thanosio/thanos:main-2026-06-15-42acfa1
DIGESTsha256:2fa27ee4c567bf88b7a8bdad3650d9ddd5012231c2b70fa07658eeb7750d548b

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The container has 24 exposed vulnerabilities, three of which (CVE-2026-42154, CVE-2026-29181, CVE-2026-33814) are denial-of-service weaknesses with severity 6.38. These are reachable via network but do not allow code execution or data breach. Post-exploit findings are low severity (max 2.69). The image is from a popular community publisher with high trust. No configuration-specific caveats apply to the top findings.

Vulnerabilities

Vulnerability Log

31 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42154MEDIUM6.38
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3, 0.305.2
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-29181MEDIUM6.38
go.opentelemetry.io/otel
v1.39.0
fixed in 1.41.0
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.49.0
fixed in 0.53.0
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.39.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42151MEDIUM5.1
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-40179MEDIUM4.14
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.2-0.20260410083055-07c6232d159b
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-44903MEDIUM4.14
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34986LOW3.83
github.com/go-jose/go-jose/v4
v4.1.3
fixed in 4.1.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39829LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39830LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42508LOW2.26
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-46595LOW2.17
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-46598LOW1.62
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-2303NONE0
go.mongodb.org/mongo-driver
v1.17.6
fixed in 1.17.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39882NONE0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
v1.39.0
fixed in 1.43.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-24051NONE0
go.opentelemetry.io/otel/sdk
v1.39.0
fixed in 1.40.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39827NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39835NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-46597NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39831NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39832NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39833NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39834NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25680NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-25681NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27136NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42502NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42506NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.40.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable