Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Two medium-severity vulnerabilities (CVE-2026-55200 and CVE-2026-33630) could allow remote code execution or denial of service if the Zabbix server connects to untrusted SSH servers or receives crafted DNS responses. The container has 19 exposed-surface vulnerabilities in total, but none exceed a severity of 7.0, and the threat score of 25 indicates manageable risk. Considering that the image is from a verified publisher and is pinned by digest, the overall risk is acceptable with standard security practices.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-55200 | MEDIUM6.64 | libssh2 1.11.1-r2 fixed in 1.11.1-r3 | 2.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33630 | MEDIUM6 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-15370 | MEDIUM5.7 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-8286 | MEDIUM5.5 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-8925 | MEDIUM5.5 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-11352 | MEDIUM5.1 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-11586 | MEDIUM5.1 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-12064 | MEDIUM5.1 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-8927 | MEDIUM5.1 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-8932 | MEDIUM5.1 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-9079 | MEDIUM5.1 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-55199 | MEDIUM5.1 | libssh2 1.11.1-r2 fixed in 1.11.1-r3 | 0.9% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-59845 | MEDIUM4.5 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-59847 | MEDIUM4.02 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-9545 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9546 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59850 | LOW3.65 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59848 | LOW3.6 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-11564 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-59846 | LOW3.31 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-59842 | LOW3.15 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59851 | LOW2.69 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59849 | LOW2.63 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-8926 | LOW2.45 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-59843 | LOW1.99 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-59844 | LOW1.99 | libssh 0.12.0-r0 fixed in 0.12.1-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8458 | NONE0 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.3% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.