Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker who can spoof DNS responses could exploit CVE-2026-33630 to cause a use-after-free, leading to memory corruption and container crash (denial of service). The vulnerability is in c-ares, a core DNS resolution library, making it remotely exploitable with no authentication. Although no post-exploit issues exist, the single high-severity finding warrants caution; consider restricting outbound DNS queries to trusted resolvers.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-33630 | HIGH7.5 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | — | Directly ExposedContext importance: HIGH |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.