Scanner: Docker Scout
Critical vulnerabilities: 2
High vulnerabilities: 32
Critical
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-33186 | grpc | 1.77.0 | 1.79.3 | CVE-2026-33186: Improper Authorization |
| CVE-2025-68121 | stdlib | 1.25.5 | 1.25.7 | CVE-2025-68121 |
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2025-45768 | pyjwt | 2.12.1 | not fixed | CVE-2025-45768 |
| CVE-2026-24051 | sdk | 1.38.0 | 1.40.0 | CVE-2026-24051: Untrusted Search Path |
| CVE-2026-45022 | v5 | 5.16.4 | 5.19.0 | CVE-2026-45022: Incorrect Behavior Order: Validate Before Canonicalize |
| CVE-2026-24049 | wheel | 0.45.1 | 0.46.2 | CVE-2026-24049: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-45134 | langsmith | 0.7.31 | 0.8.0 | CVE-2026-45134: Deserialization of Untrusted Data |
| CVE-2026-39883 | sdk | 1.38.0 | 1.43.0 | CVE-2026-39883: Untrusted Search Path |
| CVE-2024-34997 | joblib | 1.5.2 | not fixed | CVE-2024-34997 |
| CVE-2025-61726 | stdlib | 1.25.5 | 1.25.6 | CVE-2025-61726 |
| CVE-2025-69534 | markdown | 3.10.2 | not fixed | CVE-2025-69534 |
| CVE-2026-0846 | nltk | 3.9.4 | not fixed | CVE-2026-0846 |
| CVE-2026-25679 | stdlib | 1.25.5 | 1.25.8 | CVE-2026-25679 |
| CVE-2026-29181 | otel | 1.38.0 | 1.41.0 | CVE-2026-29181: Uncontrolled Resource Consumption |
| CVE-2026-32280 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32280 |
| CVE-2026-32281 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32281 |
| CVE-2026-32283 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32283 |
| CVE-2026-33811 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-33811 |
| CVE-2026-33814 | net | 0.47.0 | 0.53.0 | CVE-2026-33814 |
| CVE-2026-33814 | net | 0.47.0 | 0.53.0 | CVE-2026-33814 |
| CVE-2026-39820 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-39820 |
| CVE-2026-39836 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-39836 |
| CVE-2026-41602 | thrift | 0.22.0 | 0.23.0 | CVE-2026-41602: Integer Overflow or Wraparound |
| CVE-2026-42499 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-42499 |
| CVE-2025-14920 | transformers | 5.3.0 | not fixed | CVE-2025-14920 |
| CVE-2025-14921 | transformers | 5.3.0 | not fixed | CVE-2025-14921 |
| CVE-2025-14924 | transformers | 5.3.0 | not fixed | CVE-2025-14924 |
| CVE-2025-14926 | transformers | 5.3.0 | not fixed | CVE-2025-14926 |
| CVE-2025-14927 | transformers | 5.3.0 | not fixed | CVE-2025-14927 |
| CVE-2025-14928 | transformers | 5.3.0 | not fixed | CVE-2025-14928 |
| CVE-2025-14929 | transformers | 5.3.0 | not fixed | CVE-2025-14929 |
| CVE-2025-14930 | transformers | 5.3.0 | not fixed | CVE-2025-14930 |
| CVE-2026-44973 | v5 | 5.6.2 | 5.9.0 | CVE-2026-44973: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-44660 | ujson | 5.12.0 | 5.12.1 | CVE-2026-44660: Missing Release of Memory after Effective Lifetime |