Scanner: Docker Scout
Critical vulnerabilities: 2
High vulnerabilities: 22
Medium vulnerabilities: 14
Critical
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-59873 | tar | 6.2.1 | 7.5.19 | CVE-2026-59873: Allocation of Resources Without Limits or Throttling |
| CVE-2026-59873 | tar | 6.2.1 | 7.5.19 | CVE-2026-59873: Allocation of Resources Without Limits or Throttling |
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-26960 | tar | 6.2.1 | 7.5.8 | CVE-2026-26960: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-26960 | tar | 6.2.1 | 7.5.8 | CVE-2026-26960: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2025-64756 | glob | 10.4.5 | 11.1.0 | CVE-2025-64756: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec... |
| CVE-2026-14257 | brace-expansion | 2.0.2 | 5.0.8 | CVE-2026-14257: Uncontrolled Resource Consumption |
| CVE-2026-27903 | minimatch | 9.0.5 | 9.0.7 | CVE-2026-27903: Inefficient Algorithmic Complexity |
| CVE-2026-27904 | minimatch | 9.0.5 | 9.0.7 | CVE-2026-27904: Inefficient Regular Expression Complexity |
| CVE-2026-33671 | picomatch | 4.0.2 | 4.0.4 | CVE-2026-33671: Inefficient Regular Expression Complexity |
| CVE-2026-48815 | sigstore | 3.1.0 | 4.1.1 | CVE-2026-48815: Improper Verification of Cryptographic Signature |
| CVE-2026-13149 | brace-expansion | 2.0.2 | 2.1.2 | CVE-2026-13149: Uncontrolled Resource Consumption |
| CVE-2026-23745 | tar | 6.2.1 | 7.5.3 | CVE-2026-23745: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-23745 | tar | 6.2.1 | 7.5.3 | CVE-2026-23745: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-24842 | tar | 6.2.1 | 7.5.7 | CVE-2026-24842: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-24842 | tar | 6.2.1 | 7.5.7 | CVE-2026-24842: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-29786 | tar | 6.2.1 | 7.5.10 | CVE-2026-29786: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-29786 | tar | 6.2.1 | 7.5.10 | CVE-2026-29786: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-31802 | tar | 6.2.1 | 7.5.11 | CVE-2026-31802: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-31802 | tar | 6.2.1 | 7.5.11 | CVE-2026-31802: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-26996 | minimatch | 9.0.5 | 10.2.1 | CVE-2026-26996: Inefficient Regular Expression Complexity |
| CVE-2026-59874 | tar | 6.2.1 | 7.5.18 | CVE-2026-59874: Loop with Unreachable Exit Condition ('Infinite Loop') |
| CVE-2026-59874 | tar | 6.2.1 | 7.5.18 | CVE-2026-59874: Loop with Unreachable Exit Condition ('Infinite Loop') |
| CVE-2026-23950 | tar | 6.2.1 | 7.5.4 | CVE-2026-23950: Improper Handling of Unicode Encoding |
| CVE-2026-23950 | tar | 6.2.1 | 7.5.4 | CVE-2026-23950: Improper Handling of Unicode Encoding |
Medium
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-33672 | picomatch | 4.0.2 | 4.0.4 | CVE-2026-33672: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollut... |
| CVE-2026-42338 | ip-address | 9.0.5 | 10.1.1 | CVE-2026-42338: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2026-59871 | tar | 6.2.1 | 7.5.18 | CVE-2026-59871: Incorrect Type Conversion or Cast |
| CVE-2026-59871 | tar | 6.2.1 | 7.5.18 | CVE-2026-59871: Incorrect Type Conversion or Cast |
| CVE-2026-59875 | tar | 6.2.1 | 7.5.17 | CVE-2026-59875: Uncaught Exception |
| CVE-2026-59875 | tar | 6.2.1 | 7.5.17 | CVE-2026-59875: Uncaught Exception |
| GHSA-r292-9mhp-454m | tar | 6.2.1 | 7.5.21 | GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption |
| GHSA-r292-9mhp-454m | tar | 6.2.1 | 7.5.21 | GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption |
| GHSA-r292-9mhp-454m | tar | 6.2.1 | 7.5.21 | GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption |
| CVE-2026-48758 | core | 2.0.0 | 3.2.1 | CVE-2026-48758: Improper Verification of Cryptographic Signature |
| CVE-2023-49092 | rsa | 0.9.10 | not fixed | CVE-2023-49092 |
| CVE-2026-33750 | brace-expansion | 2.0.2 | 5.0.5 | CVE-2026-33750: Uncontrolled Resource Consumption |
| CVE-2026-53655 | tar | 6.2.1 | 7.5.16 | CVE-2026-53655: Interpretation Conflict |
| CVE-2026-53655 | tar | 6.2.1 | 7.5.16 | CVE-2026-53655: Interpretation Conflict |