Scanner: Docker Scout
Critical vulnerabilities: 0
High vulnerabilities: 7
Medium vulnerabilities: 6
Critical
No critical vulnerabilities found.
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| GHSA-f88m-g3jw-g9cj | sharp | 0.34.5 | 0.35.0 | GHSA-f88m-g3jw-g9cj: Dependency on Vulnerable Third-Party Component |
| CVE-2026-14257 | brace-expansion | 5.0.6 | 5.0.8 | CVE-2026-14257: Uncontrolled Resource Consumption |
| CVE-2026-13149 | brace-expansion | 5.0.6 | 5.0.7 | CVE-2026-13149: Uncontrolled Resource Consumption |
| CVE-2026-64641 | next | 16.2.6 | 16.2.11 | CVE-2026-64641: Excessive Iteration |
| CVE-2026-64642 | next | 16.2.6 | 16.2.11 | CVE-2026-64642: Improper Authorization |
| CVE-2026-64645 | next | 16.2.6 | 16.2.11 | CVE-2026-64645: Server-Side Request Forgery (SSRF) |
| CVE-2026-64649 | next | 16.2.6 | 16.2.11 | CVE-2026-64649: Server-Side Request Forgery (SSRF) |
Medium
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption |
| CVE-2026-64648 | next | 16.2.6 | 16.2.11 | CVE-2026-64648: Use of Cache Containing Sensitive Information |
| CVE-2026-64643 | next | 16.2.6 | 16.2.11 | CVE-2026-64643: Insertion of Sensitive Information Into Sent Data |
| CVE-2026-64644 | next | 16.2.6 | 16.2.11 | CVE-2026-64644: Inefficient Algorithmic Complexity |
| CVE-2026-64646 | next | 16.2.6 | 16.2.11 | CVE-2026-64646: Allocation of Resources Without Limits or Throttling |
| CVE-2026-64647 | next | 16.2.6 | 16.2.11 | CVE-2026-64647: Improper Encoding or Escaping of Output |