Vulnerability Reportzabbix/zabbix-server-pgsql:7.4-alpine-latest

digestsha256:f0b32ff79570f26fa1139019a1021bd4a1e8c80189c49257706650d9a044e58a

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
TRUSTED

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Two medium-severity vulnerabilities (CVE-2026-55200 and CVE-2026-33630) could allow remote code execution or denial of service if the Zabbix server connects to untrusted SSH servers or receives crafted DNS responses. The container has 19 exposed-surface vulnerabilities in total, but none exceed a severity of 7.0, and the threat score of 25 indicates manageable risk. Considering that the image is from a verified publisher and is pinned by digest, the overall risk is acceptable with standard security practices.

Vulnerabilities

Vulnerability Log

32 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-55200MEDIUM6.64
libssh2
1.11.1-r2
fixed in 1.11.1-r3
2.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-33630MEDIUM6
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Directly ExposedContext importance: MEDIUM
CVE-2026-15370MEDIUM5.7
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-8286MEDIUM5.5
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-8925MEDIUM5.5
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-11352MEDIUM5.1
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-11586MEDIUM5.1
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-12064MEDIUM5.1
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-8927MEDIUM5.1
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-8932MEDIUM5.1
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-9079MEDIUM5.1
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-55199MEDIUM5.1
libssh2
1.11.1-r2
fixed in 1.11.1-r3
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-59845MEDIUM4.5
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-59847MEDIUM4.02
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-9545LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59850LOW3.65
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59848LOW3.6
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-11564LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-59846LOW3.31
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-59842LOW3.15
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59851LOW2.69
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59849LOW2.63
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-8926LOW2.45
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-59843LOW1.99
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-59844LOW1.99
libssh
0.12.0-r0
fixed in 0.12.1-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8458NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.3%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.