Vulnerability Reportthanosio/thanos:main-2026-06-17-a50c989

thanosio/thanos:main-2026-06-17-a50c989
digestsha256:f8935c6b538c5a4d5c159a04e72f56ab5e6821d8cc786e07f238b4bfebdebdd0

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The image has 22 exposed vulnerabilities, notably CVE-2026-42154 and CVE-2026-33814, both denial-of-service flaws with severity 6.38. They are exploitable by unauthenticated attackers via the remote read endpoint and HTTP/2, respectively, potentially causing resource exhaustion. No higher severity or post-exploit vulnerabilities exist, and the image is widely used and trusted.

Vulnerabilities

Vulnerability Log

36 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42154MEDIUM6.38
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3, 0.305.2
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.49.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.39.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40179MEDIUM5.18
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.2-0.20260410083055-07c6232d159b
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-44903MEDIUM5.18
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34986MEDIUM5.1
github.com/go-jose/go-jose/v4
v4.1.3
fixed in 4.1.4
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42151MEDIUM5.1
github.com/prometheus/prometheus
v0.309.1
fixed in 0.311.3
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-29181MEDIUM5.1
go.opentelemetry.io/otel
v1.39.0
fixed in 1.41.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39832LOW2.66
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39831LOW2.48
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39882LOW2.29
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
v1.39.0
fixed in 1.43.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39829LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39830LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39835LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-46597LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42508LOW2.26
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-46595LOW2.17
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25680LOW1.99
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2303NONE0
go.mongodb.org/mongo-driver
v1.17.6
fixed in 1.17.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-24051NONE0
go.opentelemetry.io/otel/sdk
v1.39.0
fixed in 1.40.0
0.2%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.47.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.49.0
fixed in 0.56.0
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.40.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.33.0
fixed in 0.39.0
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.