Vulnerability Reportthanosio/thanos:main-2026-06-17-421734b

thanosio/thanos:main-2026-06-17-421734b
digestsha256:1ea77b1e0407410d4bede6f501c2ccb014465b8a6faf11e73d6300b779b3cef6

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. While the scan identified a small number of vulnerabilities (6 exposed, 4 post-exploit), the maximum severity is low (4.14 exposed, 2.39 post-exploit) and there are no notable findings that indicate practical exploitation in this context. The image is from a popular community source and is pinned by digest, adding supply chain assurance.

Vulnerabilities

Vulnerability Log

10 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-40179MEDIUM4.14
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.2-0.20260410083055-07c6232d159b
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42505LOW2.7
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39822LOW2.39
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42151LOW2.29
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42154LOW2.29
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3, 0.305.2
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-44903LOW1.87
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2303NONE0
go.mongodb.org/mongo-driver
v1.17.6
fixed in 1.17.7
0.2%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.81.1
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.