Vulnerability Reportthanosio/thanos:v0.41.0

thanosio/thanos:v0.41.0
DIGESTsha256:cf3e9b292e4302ad4a4955b56379703aea39516607d382a57604a3d003c35d10

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The two high-severity vulnerabilities (CVE-2026-42154, CVE-2026-25679) are remotely exploitable denial-of-service flaws that could cause memory exhaustion or crash the service, but they do not enable unauthorized access or data compromise. Post-exploit risks are minimal with no issues above 2.69 severity. Given the image's strong reputation and the nature of the threats, production use is permissible with timely patching.

Vulnerabilities

Vulnerability Log

51 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42154MEDIUM6.38
github.com/prometheus/prometheus
v0.308.0
fixed in 0.311.3, 0.305.2
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-25679MEDIUM6.38
stdlib
v1.25.7
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.38.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32282MEDIUM5.44
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-40179MEDIUM5.18
github.com/prometheus/prometheus
v0.308.0
fixed in 0.311.2-0.20260410083055-07c6232d159b
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-44903MEDIUM5.18
github.com/prometheus/prometheus
v0.308.0
fixed in 0.311.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-29181MEDIUM5.1
go.opentelemetry.io/otel
v1.38.0
fixed in 1.41.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32280MEDIUM5.1
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32283MEDIUM5.1
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32288MEDIUM4.67
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.25.7
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.25.7
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM4.14
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32281LOW3.83
stdlib
v1.25.7
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34986LOW2.29
github.com/go-jose/go-jose/v4
v4.1.3
fixed in 4.1.4
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42151LOW2.29
github.com/prometheus/prometheus
v0.308.0
fixed in 0.311.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39829LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39830LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
golang.org/x/net
v0.49.0
fixed in 0.53.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33811LOW2.29
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42508LOW2.26
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-46595LOW2.17
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.25.7
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-2303NONE0
go.mongodb.org/mongo-driver
v1.17.4
fixed in 1.17.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39882NONE0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
v1.38.0
fixed in 1.43.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-24051NONE0
go.opentelemetry.io/otel/sdk
v1.38.0
fixed in 1.40.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39827NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39835NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-46597NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39831NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39832NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39833NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39834NONE0
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25680NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-25681NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27136NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42502NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42506NONE0
golang.org/x/net
v0.49.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.40.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.25.7
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.25.7
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.25.7
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable