Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most significant risks include exposure of Azure OAuth client secret via the config API (CVE-2026-42151) and denial of service via the remote read endpoint (CVE-2026-42154) and HTTP/2 (CVE-2026-33814). These vulnerabilities are exploitable without authentication and affect Thanos because it incorporates Prometheus code. Patching to Prometheus versions ≥3.5.3 or upgrading the image will eliminate these issues. No post-exploit vulnerabilities of concern were found.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-42151 | MEDIUM6.38 | github.com/prometheus/prometheus v0.309.1 fixed in 0.311.3 | 0.3% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-42154 | MEDIUM6.38 | github.com/prometheus/prometheus v0.309.1 fixed in 0.311.3, 0.305.2 | 0.8% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-33814 | MEDIUM6.38 | golang.org/x/net v0.49.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-39883 | MEDIUM5.95 | go.opentelemetry.io/otel/sdk v1.39.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM5.58 | golang.org/x/net v0.49.0 fixed in 0.55.0 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-39827 | MEDIUM5.52 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39834 | MEDIUM5.52 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40179 | MEDIUM5.18 | github.com/prometheus/prometheus v0.309.1 fixed in 0.311.2-0.20260410083055-07c6232d159b | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-44903 | MEDIUM5.18 | github.com/prometheus/prometheus v0.309.1 fixed in 0.311.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42502 | MEDIUM5.18 | golang.org/x/net v0.49.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34986 | MEDIUM5.1 | github.com/go-jose/go-jose/v4 v4.1.3 fixed in 4.1.4 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-29181 | MEDIUM5.1 | go.opentelemetry.io/otel v1.39.0 fixed in 1.41.0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-39833 | MEDIUM4.67 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42506 | MEDIUM4.59 | golang.org/x/net v0.49.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-46598 | MEDIUM4.5 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39828 | LOW2.69 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-39832 | LOW2.66 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-39831 | LOW2.48 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-25681 | LOW2.48 | golang.org/x/net v0.49.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-27136 | LOW2.48 | golang.org/x/net v0.49.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | LOW2.39 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-39882 | LOW2.29 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.39.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-39829 | LOW2.29 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-39830 | LOW2.29 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-39835 | LOW2.29 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-46597 | LOW2.29 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42508 | LOW2.26 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-46595 | LOW2.17 | golang.org/x/crypto v0.47.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-25680 | LOW1.99 | golang.org/x/net v0.49.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-2303 | NONE0 | go.mongodb.org/mongo-driver v1.17.6 fixed in 1.17.7 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-24051 | NONE0 | go.opentelemetry.io/otel/sdk v1.39.0 fixed in 1.40.0 | 0.2% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.47.0 No fix yet | — | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.49.0 fixed in 0.56.0 | — | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.40.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.33.0 fixed in 0.39.0 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.