This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could cause denial of service by exploiting the HTTP/2 vulnerabilities (CVE-2023-44487 and CVE-2023-45288), potentially making the Wazuh manager unavailable for security monitoring. The container has 70 known vulnerabilities, 5 of which are critical, and the high EPSS scores indicate active exploitation. No full mitigation is available without updating the affected packages. Immediate remediation, such as rebuilding with patched dependencies, is required before any production use.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2023-44487 | CRITICAL9.75 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.17.0 | 100.0% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2023-45288 | CRITICAL9.75 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.23.0 | 92.0% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2022-27664 | HIGH7.5 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.0.0-20220906165146-f3363e06e74c | 2.4% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2022-41723 | HIGH7.5 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.7.0 | 4.6% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2023-39325 | HIGH7.5 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.17.0 | 3.8% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2021-3121 | MEDIUM6.88 | github.com/gogo/protobuf v1.3.1 fixed in 1.3.2 | 3.5% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-39892 | MEDIUM6.66 | cryptography 46.0.6 fixed in 46.0.7 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-48864 | MEDIUM6.63 | libsolv 0.7.22-1.amzn2023.0.3 fixed in 0.7.22-1.amzn2023.0.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-25621 | MEDIUM6.63 | github.com/containerd/containerd v1.3.3 fixed in 1.7.29 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-25173 | MEDIUM6.63 | github.com/containerd/containerd v1.3.3 fixed in 1.5.18, 1.6.18 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-40635 | MEDIUM6.63 | github.com/containerd/containerd v1.3.3 fixed in 1.7.27, 1.6.38 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2022-23471 | MEDIUM6.5 | github.com/containerd/containerd v1.3.3 fixed in 1.5.16, 1.6.12 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-44432 | MEDIUM6.38 | urllib3 2.6.3 fixed in 2.7.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-65637 | MEDIUM6.38 | github.com/sirupsen/logrus v1.4.2 fixed in 1.8.3, 1.9.1, 1.9.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2021-43565 | MEDIUM6.38 | golang.org/x/crypto v0.0.0-20200510223506-06a226fb4e37 fixed in 0.0.0-20211202192323-5770296d904e | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-22869 | MEDIUM6.38 | golang.org/x/crypto v0.0.0-20200510223506-06a226fb4e37 fixed in 0.35.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-22868 | MEDIUM6.38 | golang.org/x/oauth2 v0.0.0-20200107190931-bf48bf16ab8d fixed in 0.27.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2021-21334 | MEDIUM6.3 | github.com/containerd/containerd v1.3.3 fixed in 1.4.4, 1.3.10 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2021-32760 | MEDIUM6.3 | github.com/containerd/containerd v1.3.3 fixed in 1.4.8, 1.5.4 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-48526 | MEDIUM6.29 | PyJWT 2.12.1 fixed in 2.13.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33186 | MEDIUM6.18 | google.golang.org/grpc v1.29.1 fixed in 1.79.3 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2021-38561 | MEDIUM6 | golang.org/x/text v0.3.2 fixed in 0.3.7 | 1.4% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2022-32149 | MEDIUM6 | golang.org/x/text v0.3.2 fixed in 0.3.8 | 1.4% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-14040 | MEDIUM6 | golang.org/x/text v0.3.2 fixed in 0.3.3 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2019-19794 | MEDIUM5.9 | github.com/miekg/dns v1.1.15 fixed in 1.1.25 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2021-31525 | MEDIUM5.9 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.0.0-20210428140749-89ef3d95e781 | 3.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-24786 | MEDIUM5.9 | google.golang.org/protobuf v1.23.0 fixed in 1.33.0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-9149 | MEDIUM5.52 | libsolv 0.7.22-1.amzn2023.0.3 fixed in 0.7.22-1.amzn2023.0.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-9150 | MEDIUM5.52 | libsolv 0.7.22-1.amzn2023.0.3 fixed in 0.7.22-1.amzn2023.0.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48710 | MEDIUM5.52 | starlette 0.49.1 fixed in 1.0.1 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2023-2253 | MEDIUM5.52 | github.com/docker/distribution v2.7.1+incompatible fixed in 2.8.2-beta.1 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-22872 | MEDIUM5.52 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.38.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-41717 | MEDIUM5.3 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.4.0 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2022-29526 | MEDIUM5.3 | golang.org/x/sys v0.0.0-20200625212154-ddb9806d33ae fixed in 0.0.0-20220412211240-33da011f77ad | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2020-15257 | MEDIUM5.2 | github.com/containerd/containerd v1.3.3 fixed in 1.3.9, 1.4.3 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-6019 | MEDIUM5.18 | python3 3.9.25-1.amzn2023.0.5 fixed in 3.9.25-1.amzn2023.0.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6019 | MEDIUM5.18 | python3-libs 3.9.25-1.amzn2023.0.5 fixed in 3.9.25-1.amzn2023.0.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-3978 | MEDIUM5.18 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.13.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-48524 | MEDIUM5.02 | PyJWT 2.12.1 fixed in 2.13.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40347 | MEDIUM5.02 | python-multipart 0.0.22 fixed in 0.0.26 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-31030 | MEDIUM4.67 | github.com/containerd/containerd v1.3.3 fixed in 1.5.13, 1.6.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-25153 | MEDIUM4.67 | github.com/containerd/containerd v1.3.3 fixed in 1.5.18, 1.6.18 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-64329 | MEDIUM4.67 | github.com/containerd/containerd v1.3.3 fixed in 1.7.29 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2020-8565 | MEDIUM4.67 | k8s.io/client-go v0.18.3 fixed in 0.19.6, 0.20.0-alpha.2, 0.18.14, 0.17.16 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-48523 | MEDIUM4.59 | PyJWT 2.12.1 fixed in 2.13.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-48525 | MEDIUM4.5 | PyJWT 2.12.1 fixed in 2.13.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45409 | MEDIUM4.5 | idna 3.7 fixed in 3.15 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-44431 | MEDIUM4.5 | urllib3 2.6.3 fixed in 2.7.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-10543 | MEDIUM4.5 | github.com/eclipse/paho.mqtt.golang v1.2.1-0.20200121105743-0d940dd29fd2 fixed in 1.5.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-47914 | MEDIUM4.5 | golang.org/x/crypto v0.0.0-20200510223506-06a226fb4e37 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58181 | MEDIUM4.5 | golang.org/x/crypto v0.0.0-20200510223506-06a226fb4e37 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-22870 | LOW3.74 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.36.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48522 | LOW3.57 | PyJWT 2.12.1 fixed in 2.13.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2022-23648 | LOW3.1 | github.com/containerd/containerd v1.3.3 fixed in 1.4.13, 1.5.10, 1.6.1 | 27.4% High Exploitation Risk | Post-Exploit |
| CVE-2026-6357 | LOW2.96 | pip 26.0.1 fixed in 26.1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-45337 | LOW2.95 | golang.org/x/crypto v0.0.0-20200510223506-06a226fb4e37 fixed in 0.31.0 | 3.1% Low-Moderate Risk | Post-Exploit |
| CVE-2023-48795 | LOW2.76 | golang.org/x/crypto v0.0.0-20200510223506-06a226fb4e37 fixed in 0.17.0, 0.0.0-20231218163308-9d2ee975ef9f | 93.3% Actively Exploited | Post-Exploit |
| CVE-2026-48863 | LOW2.7 | libsolv 0.7.22-1.amzn2023.0.3 fixed in 0.7.22-1.amzn2023.0.4 | — | Post-Exploit |
| CVE-2020-29652 | LOW2.7 | golang.org/x/crypto v0.0.0-20200510223506-06a226fb4e37 fixed in 0.0.0-20201216223049-8b5274cf687f | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2022-27191 | LOW2.7 | golang.org/x/crypto v0.0.0-20200510223506-06a226fb4e37 fixed in 0.0.0-20220314234659-1baeb1ce4c0b | 3.9% Low-Moderate Risk | Post-Exploit |
| CVE-2021-33194 | LOW2.7 | golang.org/x/net v0.0.0-20200202094626-16171245cfb2 fixed in 0.0.0-20210520170846-37e1c6afe023 | 7.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3219 | LOW2.55 | pip 26.0.1 fixed in 26.1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2020-8559 | LOW2.45 | k8s.io/apimachinery v0.18.3 fixed in 0.16.13, 0.17.9, 0.18.7 | 6.1% Low-Moderate Risk | Post-Exploit |
| CVE-2021-41103 | LOW2.39 | github.com/containerd/containerd v1.3.3 fixed in 1.4.11, 1.5.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2021-22133 | LOW2.04 | go.elastic.co/apm v1.8.1-0.20200909061013-2aef45b9cf4b fixed in 1.11.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-68121 | NONE0 | stdlib v1.14.12 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-24538 | NONE0 | stdlib v1.14.12 fixed in 1.19.8, 1.20.3 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-24540 | NONE0 | stdlib v1.14.12 fixed in 1.19.9, 1.20.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2024-24790 | NONE0 | stdlib v1.14.12 fixed in 1.21.11, 1.22.4 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2022-23806 | NONE0 | stdlib v1.14.12 fixed in 1.16.14, 1.17.7 | 3.0% Low-Moderate Risk | Not Applicable |
| CVE-2022-30580 | NONE0 | stdlib v1.14.12 fixed in 1.17.11, 1.18.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-29403 | NONE0 | stdlib v1.14.12 fixed in 1.19.10, 1.20.5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2021-27918 | NONE0 | stdlib v1.14.12 fixed in 1.15.9, 1.16.1 | 2.5% Low-Moderate Risk | Not Applicable |
| CVE-2021-33196 | NONE0 | stdlib v1.14.12 fixed in 1.15.13, 1.16.5 | 3.5% Low-Moderate Risk | Not Applicable |
| CVE-2021-33198 | NONE0 | stdlib v1.14.12 fixed in 1.15.13, 1.16.5 | 3.4% Low-Moderate Risk | Not Applicable |
| CVE-2021-39293 | NONE0 | stdlib v1.14.12 fixed in 1.16.8, 1.17.1 | 6.9% Low-Moderate Risk | Not Applicable |
| CVE-2021-41771 | NONE0 | stdlib v1.14.12 fixed in 1.16.10, 1.17.3 | 4.4% Low-Moderate Risk | Not Applicable |
| CVE-2021-41772 | NONE0 | stdlib v1.14.12 fixed in 1.16.10, 1.17.3 | 3.1% Low-Moderate Risk | Not Applicable |
| CVE-2021-44716 | NONE0 | stdlib v1.14.12 fixed in 1.16.12, 1.17.5 | 4.0% Low-Moderate Risk | Not Applicable |
| CVE-2022-23772 | NONE0 | stdlib v1.14.12 fixed in 1.16.14, 1.17.7 | 2.8% Low-Moderate Risk | Not Applicable |
| CVE-2022-24675 | NONE0 | stdlib v1.14.12 fixed in 1.17.9, 1.18.1 | 5.3% Low-Moderate Risk | Not Applicable |
| CVE-2022-24921 | NONE0 | stdlib v1.14.12 fixed in 1.16.15, 1.17.8 | 3.2% Low-Moderate Risk | Not Applicable |
| CVE-2022-27664 | NONE0 | stdlib v1.14.12 fixed in 1.18.6, 1.19.1 | 2.4% Low-Moderate Risk | Not Applicable |
| CVE-2022-28131 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2022-28327 | NONE0 | stdlib v1.14.12 fixed in 1.17.9, 1.18.1 | 3.9% Low-Moderate Risk | Not Applicable |
| CVE-2022-2879 | NONE0 | stdlib v1.14.12 fixed in 1.18.7, 1.19.2 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-2880 | NONE0 | stdlib v1.14.12 fixed in 1.18.7, 1.19.2 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2022-29804 | NONE0 | stdlib v1.14.12 fixed in 1.17.11, 1.18.3 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2022-30630 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30631 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30632 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30633 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30634 | NONE0 | stdlib v1.14.12 fixed in 1.17.11, 1.18.3 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30635 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2022-32189 | NONE0 | stdlib v1.14.12 fixed in 1.17.13, 1.18.5 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2022-41715 | NONE0 | stdlib v1.14.12 fixed in 1.18.7, 1.19.2 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2022-41716 | NONE0 | stdlib v1.14.12 fixed in 1.18.8, 1.19.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2022-41720 | NONE0 | stdlib v1.14.12 fixed in 1.18.9, 1.19.4 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2022-41722 | NONE0 | stdlib v1.14.12 fixed in 1.19.6, 1.20.1 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2022-41723 | NONE0 | stdlib v1.14.12 fixed in 1.19.6, 1.20.1 | 4.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-41724 | NONE0 | stdlib v1.14.12 fixed in 1.19.6, 1.20.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2022-41725 | NONE0 | stdlib v1.14.12 fixed in 1.19.6, 1.20.1 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2023-24534 | NONE0 | stdlib v1.14.12 fixed in 1.19.8, 1.20.3 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2023-24536 | NONE0 | stdlib v1.14.12 fixed in 1.19.8, 1.20.3 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2023-24537 | NONE0 | stdlib v1.14.12 fixed in 1.19.8, 1.20.3 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2023-39325 | NONE0 | stdlib v1.14.12 fixed in 1.20.10, 1.21.3 | 3.8% Low-Moderate Risk | Not Applicable |
| CVE-2023-45283 | NONE0 | stdlib v1.14.12 fixed in 1.20.11, 1.21.4, 1.20.12, 1.21.5 | 2.8% Low-Moderate Risk | Not Applicable |
| CVE-2023-45287 | NONE0 | stdlib v1.14.12 fixed in 1.20.0 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-45288 | NONE0 | stdlib v1.14.12 fixed in 1.21.9, 1.22.2 | 92.0% Actively Exploited | Not Applicable |
| CVE-2024-34156 | NONE0 | stdlib v1.14.12 fixed in 1.22.7, 1.23.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-61726 | NONE0 | stdlib v1.14.12 fixed in 1.24.12, 1.25.6 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-61729 | NONE0 | stdlib v1.14.12 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25679 | NONE0 | stdlib v1.14.12 fixed in 1.25.8, 1.26.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-32280 | NONE0 | stdlib v1.14.12 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32281 | NONE0 | stdlib v1.14.12 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-32283 | NONE0 | stdlib v1.14.12 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-33811 | NONE0 | stdlib v1.14.12 fixed in 1.25.10, 1.26.3 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-33814 | NONE0 | stdlib v1.14.12 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-39820 | NONE0 | stdlib v1.14.12 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39836 | NONE0 | stdlib v1.14.12 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-58183 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61728 | NONE0 | stdlib v1.14.12 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2021-33195 | NONE0 | stdlib v1.14.12 fixed in 1.15.13, 1.16.5 | 3.1% Low-Moderate Risk | Not Applicable |
| CVE-2023-24539 | NONE0 | stdlib v1.14.12 fixed in 1.19.9, 1.20.4 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2023-29400 | NONE0 | stdlib v1.14.12 fixed in 1.19.9, 1.20.4 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-47907 | NONE0 | stdlib v1.14.12 fixed in 1.23.12, 1.24.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-4673 | NONE0 | stdlib v1.14.12 fixed in 1.23.10, 1.24.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2021-3114 | NONE0 | stdlib v1.14.12 fixed in 1.14.14, 1.15.7 | 2.6% Low-Moderate Risk | Not Applicable |
| CVE-2021-34558 | NONE0 | stdlib v1.14.12 fixed in 1.15.14, 1.16.6 | 7.0% Low-Moderate Risk | Not Applicable |
| CVE-2022-1705 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2022-32148 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2023-29406 | NONE0 | stdlib v1.14.12 fixed in 1.19.11, 1.20.6 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2024-24785 | NONE0 | stdlib v1.14.12 fixed in 1.21.8, 1.22.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-47906 | NONE0 | stdlib v1.14.12 fixed in 1.23.12, 1.24.6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61727 | NONE0 | stdlib v1.14.12 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-32282 | NONE0 | stdlib v1.14.12 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-39318 | NONE0 | stdlib v1.14.12 fixed in 1.20.8, 1.21.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-39319 | NONE0 | stdlib v1.14.12 fixed in 1.20.8, 1.21.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-32289 | NONE0 | stdlib v1.14.12 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2021-31525 | NONE0 | stdlib v1.14.12 fixed in 1.15.12, 1.16.4 | 3.7% Low-Moderate Risk | Not Applicable |
| CVE-2021-36221 | NONE0 | stdlib v1.14.12 fixed in 1.15.15, 1.16.7 | 3.1% Low-Moderate Risk | Not Applicable |
| CVE-2024-24783 | NONE0 | stdlib v1.14.12 fixed in 1.21.8, 1.22.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2024-24791 | NONE0 | stdlib v1.14.12 fixed in 1.21.12, 1.22.5 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2024-34155 | NONE0 | stdlib v1.14.12 fixed in 1.22.7, 1.23.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2024-34158 | NONE0 | stdlib v1.14.12 fixed in 1.22.7, 1.23.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2024-45336 | NONE0 | stdlib v1.14.12 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2022-1962 | NONE0 | stdlib v1.14.12 fixed in 1.17.12, 1.18.4 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2024-24789 | NONE0 | stdlib v1.14.12 fixed in 1.21.11, 1.22.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32288 | NONE0 | stdlib v1.14.12 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-24784 | NONE0 | stdlib v1.14.12 fixed in 1.21.8, 1.22.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-22871 | NONE0 | stdlib v1.14.12 fixed in 1.23.8, 1.24.2 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-27142 | NONE0 | stdlib v1.14.12 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39826 | NONE0 | stdlib v1.14.12 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2021-33197 | NONE0 | stdlib v1.14.12 fixed in 1.15.13, 1.16.5 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2022-29526 | NONE0 | stdlib v1.14.12 fixed in 1.17.10, 1.18.2 | 2.1% Low-Moderate Risk | Not Applicable |
| CVE-2022-41717 | NONE0 | stdlib v1.14.12 fixed in 1.18.9, 1.19.4 | 5.6% Low-Moderate Risk | Not Applicable |
| CVE-2023-24532 | NONE0 | stdlib v1.14.12 fixed in 1.19.7, 1.20.2 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-29409 | NONE0 | stdlib v1.14.12 fixed in 1.19.12, 1.20.7, 1.21.0-rc.4 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-39326 | NONE0 | stdlib v1.14.12 fixed in 1.20.12, 1.21.5 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2023-45284 | NONE0 | stdlib v1.14.12 fixed in 1.20.11, 1.21.4 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2023-45289 | NONE0 | stdlib v1.14.12 fixed in 1.21.8, 1.22.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2023-45290 | NONE0 | stdlib v1.14.12 fixed in 1.21.8, 1.22.1 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-22866 | NONE0 | stdlib v1.14.12 fixed in 1.22.12, 1.23.6, 1.24.0-rc.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-22873 | NONE0 | stdlib v1.14.12 fixed in 1.23.9, 1.24.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-47912 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58185 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-58187 | NONE0 | stdlib v1.14.12 fixed in 1.24.9, 1.25.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58188 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-58189 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61723 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61724 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61725 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61730 | NONE0 | stdlib v1.14.12 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-58186 | NONE0 | stdlib v1.14.12 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2021-44717 | NONE0 | stdlib v1.14.12 fixed in 1.16.12, 1.17.5 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2025-22870 | NONE0 | stdlib v1.14.12 fixed in 1.23.7, 1.24.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-45341 | NONE0 | stdlib v1.14.12 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2022-30629 | NONE0 | stdlib v1.14.12 fixed in 1.17.11, 1.18.3 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-27139 | NONE0 | stdlib v1.14.12 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Not Applicable |
| GHSA-537c-gmf6-5ccf | NONE0 | cryptography 46.0.6 fixed in 48.0.1 | — | Not Applicable |
| CVE-2026-42561 | NONE0 | python-multipart 0.0.22 fixed in 0.0.27 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-53539 | NONE0 | python-multipart 0.0.22 fixed in 0.0.30 | — | Not Applicable |
| CVE-2026-53537 | NONE0 | python-multipart 0.0.22 fixed in 0.0.30 | — | Not Applicable |
| CVE-2026-53538 | NONE0 | python-multipart 0.0.22 fixed in 0.0.30 | — | Not Applicable |
| CVE-2026-53540 | NONE0 | python-multipart 0.0.22 fixed in 0.0.31 | — | Not Applicable |
| CVE-2026-48818 | NONE0 | starlette 0.49.1 fixed in 1.1.0 | — | Not Applicable |
| CVE-2026-54283 | NONE0 | starlette 0.49.1 fixed in 1.3.1 | — | Not Applicable |
| CVE-2026-48817 | NONE0 | starlette 0.49.1 fixed in 1.1.0 | — | Not Applicable |
| CVE-2026-54282 | NONE0 | starlette 0.49.1 fixed in 1.3.0 | — | Not Applicable |
| GHSA-7ww5-4wqc-m92c | NONE0 | github.com/containerd/containerd v1.3.3 fixed in 1.6.26, 1.7.11 | — | Not Applicable |
| GHSA-5j5w-g665-5m35 | NONE0 | github.com/containerd/containerd v1.3.3 fixed in 1.4.12, 1.5.8 | — | Not Applicable |
| GHSA-c9cp-9c75-9v8c | NONE0 | github.com/containerd/containerd v1.3.3 fixed in 1.5.11, 1.6.2 | — | Not Applicable |
| GHSA-qq97-vm5h-rrhg | NONE0 | github.com/docker/distribution v2.7.1+incompatible fixed in 2.8.0 | — | Not Applicable |
| GHSA-77vh-xpmg-72qh | NONE0 | github.com/opencontainers/image-spec v1.0.2-0.20190823105129-775207bd45b6 fixed in 1.0.2 | — | Not Applicable |
| GHSA-m425-mq94-257g | NONE0 | google.golang.org/grpc v1.29.1 fixed in 1.56.3, 1.57.1, 1.58.3 | — | Not Applicable |
| CVE-2026-39823 | NONE0 | stdlib v1.14.12 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.14.12 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.14.12 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.14.12 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-0913 | NONE0 | stdlib v1.14.12 fixed in 1.23.10, 1.24.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.14.12 fixed in 1.25.11, 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.14.12 fixed in 1.25.11, 1.26.4 | 0.3% Theoretical Threat | Not Applicable |