Scanner: Docker Scout
Critical vulnerabilities: 0
High vulnerabilities: 6
Medium vulnerabilities: 9
Critical
No critical vulnerabilities found.
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-14257 | brace-expansion | 5.0.7 | 5.0.8 | CVE-2026-14257: Uncontrolled Resource Consumption |
| CVE-2026-57585 | msgpack | 1.1.2 | 1.2.1 | CVE-2026-57585 |
| CVE-2026-69152 | brace-expansion | 5.0.7 | 5.0.9 | CVE-2026-69152: Uncontrolled Resource Consumption |
| GHSA-6v7p-g79w-8964 | msgpack | 1.1.2 | 1.2.1 | GHSA-6v7p-g79w-8964: Use After Free |
| CVE-2025-47273 | setuptools | 70.3.0 | 78.1.1 | CVE-2025-47273: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-69192 | ip-address | 10.2.0 | 10.3.1 | CVE-2026-69192: Improper Input Validation |
Medium
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-15157 | undici | 6.27.0 | 6.28.0 | CVE-2026-15157: Improper Neutralization of CRLF Sequences ('CRLF Injection') |
| CVE-2026-16728 | undici | 6.27.0 | 6.28.0 | CVE-2026-16728: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| CVE-2026-16729 | undici | 6.27.0 | 6.28.0 | CVE-2026-16729: Improper Neutralization of Special Elements in Output Used by a Downstream Component... |
| GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption |
| GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption |
| CVE-2023-49092 | rsa | 0.9.10 | not fixed | CVE-2023-49092 |
| CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | CVE-2026-59890: Improper Handling of Unicode Encoding |
| CVE-2026-54272 | ip-address | 10.2.0 | 10.2.1 | CVE-2026-54272: Improper Input Validation |
| CVE-2026-69198 | ip-address | 10.2.0 | 10.2.2 | CVE-2026-69198: Improper Input Validation |