Scanner: Docker Scout
Critical vulnerabilities: 2
High vulnerabilities: 10
Medium vulnerabilities: 20
Critical
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-33186 | grpc | 1.77.0 | 1.79.3 | CVE-2026-33186: Improper Authorization |
| CVE-2025-68121 | stdlib | 1.25.5 | 1.25.7 | CVE-2025-68121 |
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-24051 | sdk | 1.38.0 | 1.40.0 | CVE-2026-24051: Untrusted Search Path |
| CVE-2026-24049 | wheel | 0.45.1 | 0.46.2 | CVE-2026-24049: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-39883 | sdk | 1.38.0 | 1.43.0 | CVE-2026-39883: Untrusted Search Path |
| CVE-2024-23342 | ecdsa | 0.19.1 | not fixed | CVE-2024-23342: Observable Discrepancy |
| CVE-2025-61726 | stdlib | 1.25.5 | 1.25.6 | CVE-2025-61726 |
| CVE-2026-25679 | stdlib | 1.25.5 | 1.25.8 | CVE-2026-25679 |
| CVE-2026-32280 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32280 |
| CVE-2026-32281 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32281 |
| CVE-2026-32283 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32283 |
| CVE-2026-33231 | nltk | 3.9.3 | not fixed | CVE-2026-33231: Missing Authentication for Critical Function |
Medium
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-25934 | v5 | 5.16.4 | 5.16.5 | CVE-2026-25934: Improper Validation of Integrity Check Value |
| CVE-2026-3219 | pip | 26.0.1 | not fixed | CVE-2026-3219: Unrestricted Upload of File with Dangerous Type |
| GHSA-3xc5-wrhm-f963 | v5 | 5.16.4 | 5.18.0 | GHSA-3xc5-wrhm-f963: Insufficiently Protected Credentials |
| CVE-2026-34165 | v5 | 5.16.4 | 5.17.1 | CVE-2026-34165: Integer Underflow (Wrap or Wraparound) |
| GHSA-rf74-v2fm-23pw | nltk | 3.9.3 | not fixed | GHSA-rf74-v2fm-23pw: Uncontrolled Recursion |
| CVE-2025-69872 | diskcache | 5.6.3 | not fixed | CVE-2025-69872: Deserialization of Untrusted Data |
| CVE-2022-42969 | py | 1.11.0 | not fixed | CVE-2022-42969 |
| CVE-2025-61730 | stdlib | 1.25.5 | 1.25.6 | CVE-2025-61730 |
| CVE-2026-33936 | ecdsa | 0.19.1 | 0.19.2 | CVE-2026-33936: Improper Handling of Length Parameter Inconsistency |
| GHSA-jj8c-mmj3-mmgv | authlib | 1.6.9 | 1.6.11 | GHSA-jj8c-mmj3-mmgv: Cross-Site Request Forgery (CSRF) |
| CVE-2026-32288 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32288 |
| CVE-2023-49092 | rsa | 0.9.10 | not fixed | CVE-2023-49092 |
| GHSA-xmrv-pmrh-hhx2 | eventstream | 1.7.3 | 1.7.8 | GHSA-xmrv-pmrh-hhx2: Improper Input Validation |
| GHSA-xmrv-pmrh-hhx2 | eventstream | 1.7.3 | 1.7.8 | GHSA-xmrv-pmrh-hhx2: Improper Input Validation |
| CVE-2026-27142 | stdlib | 1.25.5 | 1.25.8 | CVE-2026-27142 |
| CVE-2026-32289 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32289 |
| CVE-2026-33230 | nltk | 3.9.3 | 3.9.4 | CVE-2026-33230: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2026-32282 | stdlib | 1.25.5 | 1.25.9 | CVE-2026-32282 |
| CVE-2025-61728 | stdlib | 1.25.5 | 1.25.6 | CVE-2025-61728 |
| CVE-2025-71176 | pytest | 9.0.2 | 9.0.3 | CVE-2025-71176: Creation of Temporary File in Directory with Insecure Permissions |