Vulnerability Reportwordpress:7.0.0-php8.5-fpm-alpine

wordpress:7.0.0-php8.5-fpm-alpine
digestsha256:2cdb8abe6155ba37ac0ee55950a44cbe6f818eab88a8df97cc2266ae3aeb0d35

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker who can spoof DNS responses could exploit CVE-2026-33630 to cause a use-after-free, leading to memory corruption and container crash (denial of service). The vulnerability is in c-ares, a core DNS resolution library, making it remotely exploitable with no authentication. Although no post-exploit issues exist, the single high-severity finding warrants caution; consider restricting outbound DNS queries to trusted resolvers.

Vulnerabilities

Vulnerability Log

1 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33630HIGH7.5
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Directly ExposedContext importance: HIGH

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.