Scanner: Docker Scout
Critical vulnerabilities: 1
High vulnerabilities: 8
Medium vulnerabilities: 12
Critical
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-63374 | anyio | 4.11.0 | 4.14.2 | CVE-2026-63374: Improper Certificate Validation |
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-87818 | gitpython | 3.1.59 | 3.1.60 | CVE-2026-87818 |
| CVE-2026-57585 | msgpack | 1.1.2 | 1.2.1 | CVE-2026-57585 |
| CVE-2026-87819 | gitpython | 3.1.59 | 3.1.60 | CVE-2026-87819 |
| GHSA-6v7p-g79w-8964 | msgpack | 1.1.2 | 1.2.1 | GHSA-6v7p-g79w-8964: Use After Free |
| CVE-2025-47273 | setuptools | 70.3.0 | 78.1.1 | CVE-2025-47273: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-81726 | nltk | 3.10.3 | not fixed | CVE-2026-81726: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-85091 | zlib | 1.3.2-r5 | 1.3.3-r0 | CVE-2026-85091 |
| CVE-2026-87817 | gitpython | 3.1.59 | 3.1.60 | CVE-2026-87817 |
Medium
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-84310 | pypdf | 6.15.0 | 6.16.1 | CVE-2026-84310: Asymmetric Resource Consumption (Amplification) |
| CVE-2026-84311 | pypdf | 6.15.0 | 6.16.1 | CVE-2026-84311: Excessive Iteration |
| CVE-2026-16599 | wget | 1.25.0-r16 | 1.25.0-r17 | CVE-2026-16599 |
| CVE-2025-69872 | diskcache | 5.6.3 | not fixed | CVE-2025-69872: Deserialization of Untrusted Data |
| CVE-2026-85999 | soupsieve | 2.8.4 | 2.9.0 | CVE-2026-85999: Inefficient Regular Expression Complexity |
| CVE-2026-86000 | soupsieve | 2.8.4 | 2.9.0 | CVE-2026-86000: Inefficient Regular Expression Complexity |
| GHSA-2mjx-qc3c-rqvc | rustls | 0.23.43 | 0.23.45 | GHSA-2mjx-qc3c-rqvc |
| CVE-2023-49092 | rsa | 0.9.10 | not fixed | CVE-2023-49092 |
| CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | CVE-2026-59890: Improper Handling of Unicode Encoding |
| CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | CVE-2026-59890: Improper Handling of Unicode Encoding |
| CVE-2026-64847 | anyio | 4.11.0 | 4.14.2 | CVE-2026-64847: Allocation of Resources Without Limits or Throttling |
| CVE-2026-84309 | pypdf | 6.15.0 | 6.16.0 | CVE-2026-84309: Loop with Unreachable Exit Condition ('Infinite Loop') |