Scanner: Docker Scout
Critical vulnerabilities: 13
High vulnerabilities: 44
Medium vulnerabilities: 45
Critical
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-33186 | grpc | 1.77.0 | 1.79.3 | CVE-2026-33186: Improper Authorization |
| CVE-2026-39830 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39830: Improper Restriction of Operations within the Bounds of a Memory Buffer |
| CVE-2026-39831 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39831: Missing Authorization |
| CVE-2026-39832 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39832: Improper Preservation of Permissions |
| CVE-2026-39833 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39833: Missing Authorization |
| CVE-2026-39834 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39834: Integer Overflow or Wraparound |
| CVE-2026-42508 | crypto | 0.45.0 | 0.52.0 | CVE-2026-42508: Improper Certificate Validation |
| CVE-2026-63374 | anyio | 4.11.0 | 4.14.2 | CVE-2026-63374: Improper Certificate Validation |
| CVE-2026-45833 | chromadb | 0.5.20 | not fixed | CVE-2026-45833: Improper Control of Generation of Code ('Code Injection') |
| CVE-2026-39821 | net | 0.47.0 | 0.55.0 | CVE-2026-39821 |
| CVE-2026-39821 | net | 0.47.0 | 0.55.0 | CVE-2026-39821 |
| CVE-2025-68121 | stdlib | 1.25.5 | 1.25.7 | CVE-2025-68121 |
| CVE-2026-46595 | crypto | 0.45.0 | 0.52.0 | CVE-2026-46595: Incorrect Implementation of Authentication Algorithm |
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-84445 | grpc | 1.77.0 | 1.82.2 | CVE-2026-84445: Improper Validation of Array Index |
| CVE-2026-24051 | sdk | 1.38.0 | 1.40.0 | CVE-2026-24051: Untrusted Search Path |
| CVE-2026-45022 | v5 | 5.16.4 | 5.19.0 | CVE-2026-45022: Incorrect Behavior Order: Validate Before Canonicalize |
| CVE-2026-71556 | v5 | 5.16.4 | 5.19.2 | CVE-2026-71556: Improper Link Resolution Before File Access ('Link Following') |
| CVE-2026-87818 | gitpython | 3.1.59 | 3.1.60 | CVE-2026-87818 |
| CVE-2026-39883 | sdk | 1.38.0 | 1.43.0 | CVE-2026-39883: Untrusted Search Path |
| CVE-2025-61726 | stdlib | 1.25.5 | 1.25.6 | CVE-2025-61726 |
| CVE-2026-25679 | stdlib | 1.25.5 | 1.25.8 | CVE-2026-25679 |
| CVE-2026-29181 | otel | 1.38.0 | 1.41.0 | CVE-2026-29181: Uncontrolled Resource Consumption |
| CVE-2026-32280 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32280 |
| CVE-2026-32281 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32281 |
| CVE-2026-32283 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32283 |
| CVE-2026-33811 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-33811 |
| CVE-2026-33814 | net | 0.47.0 | 1.25.10 | CVE-2026-33814 |
| CVE-2026-33814 | net | 0.47.0 | 1.25.10 | CVE-2026-33814 |
| CVE-2026-33818 | stdlib | 1.25.5 | 1.25.13 | CVE-2026-33818 |
| CVE-2026-39820 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-39820 |
| CVE-2026-39829 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39829: Improper Validation of Specified Quantity in Input |
| CVE-2026-39836 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-39836 |
| CVE-2026-41602 | thrift | 0.22.0 | 0.23.0 | CVE-2026-41602: Integer Overflow or Wraparound |
| CVE-2026-42499 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-42499 |
| CVE-2026-42504 | stdlib | 1.25.5 | 1.25.11 | CVE-2026-42504 |
| CVE-2026-46597 | crypto | 0.45.0 | 0.52.0 | CVE-2026-46597: Incorrect Type Conversion or Cast |
| CVE-2026-46600 | net | 0.47.0 | 0.56.0 | CVE-2026-46600 |
| CVE-2026-56853 | stdlib | 1.25.5 | 1.25.13 | CVE-2026-56853 |
| CVE-2026-56854 | crypto | 0.45.0 | 0.55.0 | CVE-2026-56854 |
| CVE-2026-56855 | crypto | 0.45.0 | 0.56.0 | CVE-2026-56855 |
| CVE-2026-56859 | stdlib | 1.25.5 | 1.25.13 | CVE-2026-56859 |
| CVE-2026-56862 | stdlib | 1.25.5 | 1.25.13 | CVE-2026-56862 |
| CVE-2026-57585 | msgpack | 1.1.2 | 1.2.1 | CVE-2026-57585 |
| CVE-2026-78662 | crypto | 0.45.0 | 0.56.0 | CVE-2026-78662 |
| CVE-2026-87819 | gitpython | 3.1.59 | 3.1.60 | CVE-2026-87819 |
| GHSA-6v7p-g79w-8964 | msgpack | 1.1.2 | 1.2.1 | GHSA-6v7p-g79w-8964: Use After Free |
| CVE-2025-47273 | setuptools | 70.3.0 | 78.1.1 | CVE-2025-47273: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-39822 | stdlib | 1.25.5 | 1.25.12 | CVE-2026-39822 |
| CVE-2026-44973 | v5 | 5.6.2 | 5.9.0 | CVE-2026-44973: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-81726 | nltk | 3.10.3 | not fixed | CVE-2026-81726: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-85091 | zlib | 1.3.2-r5 | 1.3.3-r0 | CVE-2026-85091 |
| CVE-2026-43871 | thrift | 0.22.0 | 0.24.0 | CVE-2026-43871: Loop with Unreachable Exit Condition ('Infinite Loop') |
| CVE-2026-84304 | grpc | 1.77.0 | 1.83.1 | CVE-2026-84304: Uncontrolled Resource Consumption |
| CVE-2026-87817 | gitpython | 3.1.59 | 3.1.60 | CVE-2026-87817 |
| CVE-2026-45830 | chromadb | 0.5.20 | not fixed | CVE-2026-45830: Incorrect Privilege Assignment |
| CVE-2026-45831 | chromadb | 0.5.20 | not fixed | CVE-2026-45831: Incorrect Authorization |
| GHSA-hrxh-6v49-42gf | grpc | 1.77.0 | 1.82.1 | GHSA-hrxh-6v49-42gf: Uncaught Exception |
Medium
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-25934 | v5 | 5.16.4 | 5.16.5 | CVE-2026-25934: Improper Validation of Integrity Check Value |
| CVE-2026-41506 | v5 | 5.16.4 | 5.18.0 | CVE-2026-41506: Insufficiently Protected Credentials |
| CVE-2026-84310 | pypdf | 6.15.0 | 6.16.1 | CVE-2026-84310: Asymmetric Resource Consumption (Amplification) |
| CVE-2026-84311 | pypdf | 6.15.0 | 6.16.1 | CVE-2026-84311: Excessive Iteration |
| CVE-2026-34165 | v5 | 5.16.4 | 5.17.1 | CVE-2026-34165: Integer Underflow (Wrap or Wraparound) |
| CVE-2026-16599 | wget | 1.25.0-r16 | 1.25.0-r17 | CVE-2026-16599 |
| CVE-2025-69872 | diskcache | 5.6.3 | not fixed | CVE-2025-69872: Deserialization of Untrusted Data |
| CVE-2025-61730 | stdlib | 1.25.5 | 1.25.6 | CVE-2025-61730 |
| CVE-2026-39825 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-39825 |
| CVE-2026-39835 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39835: Improper Certificate Validation |
| CVE-2026-42505 | stdlib | 1.25.5 | 1.25.12 | CVE-2026-42505 |
| CVE-2026-42507 | stdlib | 1.25.5 | 1.25.11 | CVE-2026-42507 |
| CVE-2026-46598 | crypto | 0.45.0 | 0.52.0 | CVE-2026-46598: Improper Validation of Array Index |
| CVE-2026-85999 | soupsieve | 2.8.4 | 2.9.0 | CVE-2026-85999: Inefficient Regular Expression Complexity |
| CVE-2026-86000 | soupsieve | 2.8.4 | 2.9.0 | CVE-2026-86000: Inefficient Regular Expression Complexity |
| GHSA-2mjx-qc3c-rqvc | rustls | 0.23.43 | 0.23.45 | GHSA-2mjx-qc3c-rqvc |
| CVE-2026-45571 | v5 | 5.16.4 | 5.19.1 | CVE-2026-45571: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-32288 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32288 |
| CVE-2023-49092 | rsa | 0.9.10 | not fixed | CVE-2023-49092 |
| CVE-2026-56860 | stdlib | 1.25.5 | 1.25.13 | CVE-2026-56860 |
| GHSA-xmrv-pmrh-hhx2 | eventstream | 1.7.3 | 1.97.3 | GHSA-xmrv-pmrh-hhx2: Improper Input Validation |
| GHSA-xmrv-pmrh-hhx2 | eventstream | 1.7.3 | 1.97.3 | GHSA-xmrv-pmrh-hhx2: Improper Input Validation |
| CVE-2026-25681 | net | 0.47.0 | 0.55.0 | CVE-2026-25681 |
| CVE-2026-27136 | net | 0.47.0 | 0.55.0 | CVE-2026-27136 |
| CVE-2026-27142 | stdlib | 1.25.5 | 1.25.8 | CVE-2026-27142 |
| CVE-2026-32289 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32289 |
| CVE-2026-39823 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-39823 |
| CVE-2026-39826 | stdlib | 1.25.5 | 1.25.10 | CVE-2026-39826 |
| CVE-2026-42502 | net | 0.47.0 | 0.55.0 | CVE-2026-42502 |
| CVE-2026-42506 | net | 0.47.0 | 0.55.0 | CVE-2026-42506 |
| CVE-2026-56858 | stdlib | 1.25.5 | 1.25.13 | CVE-2026-56858 |
| CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | CVE-2026-59890: Improper Handling of Unicode Encoding |
| CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | CVE-2026-59890: Improper Handling of Unicode Encoding |
| CVE-2026-39828 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39828: Improper Preservation of Permissions |
| CVE-2026-71557 | v5 | 5.16.4 | 5.19.2 | CVE-2026-71557: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-84303 | grpc | 1.77.0 | 1.83.1 | CVE-2026-84303: Improper Handling of Case Sensitivity |
| CVE-2026-32282 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32282 |
| CVE-2025-61728 | stdlib | 1.25.5 | 1.25.6 | CVE-2025-61728 |
| CVE-2026-25680 | net | 0.47.0 | 0.55.0 | CVE-2026-25680: Uncontrolled Resource Consumption |
| CVE-2026-27145 | stdlib | 1.25.5 | 1.25.11 | CVE-2026-27145 |
| CVE-2026-39827 | crypto | 0.45.0 | 0.52.0 | CVE-2026-39827: Improper Enforcement of Message Integrity During Transmission in a Communication Cha... |
| CVE-2026-44740 | v5 | 5.6.2 | 5.9.0 | CVE-2026-44740: Uncontrolled Recursion |
| GHSA-w5pp-99ch-qj29 | v5 | 5.16.4 | 5.19.1 | GHSA-w5pp-99ch-qj29: Uncontrolled Resource Consumption |
| CVE-2026-64847 | anyio | 4.11.0 | 4.14.2 | CVE-2026-64847: Allocation of Resources Without Limits or Throttling |
| CVE-2026-84309 | pypdf | 6.15.0 | 6.16.0 | CVE-2026-84309: Loop with Unreachable Exit Condition ('Infinite Loop') |