Vulnerability Reportvictoriametrics/victoria-metrics:v1.145.0-enterprise-scratch

victoriametrics/victoria-metrics:v1.145.0-enterprise-scratchvictoriametrics/victoria-metrics:v1.145.0-enterprise-rc0-scratch
digestsha256:464528e7771d7945dfbdc8e1ca027e639cb25d2af2a45d487edae7712e782a1d

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. While there are 4 low-severity and 1 negligible-severity vulnerabilities detected, none appear in the exposed surface or post-exploit analysis, and they pose no practical risk to the container's operation as a metrics service. The image is published by a trusted vendor and pinned by digest, ensuring integrity.

Vulnerabilities

Vulnerability Log

5 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42505LOW3.6
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39822LOW2.39
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
GO-2026-5932NONE0
golang.org/x/crypto
v0.52.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.55.0
fixed in 0.56.0
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.37.0
fixed in 0.39.0
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.