Live data · updated as images are scanned
Container image security, measured
What OCImend finds in popular public images: how many vulnerabilities, how severe, how many actually matter, and how many can be fixed today. Only scans made without credentials are counted.
35public images measured
3,619known CVEs found
14%in code the app loads
27%fixable with an upgrade today
- 24 of 35 popular container images OCImend tracks carry high or critical vulnerabilities right now.
- OCImend has measured 35 public container images; they carry 3,619 known vulnerabilities, 103 per image on average.
- 14% of those CVEs are in code the image's application actually loads; the rest sit in packages it never loads.
- 27% have a fixed package available today, and 0 are known to be actively exploited.
- The most vulnerable image measured is mcr.microsoft.com/oss/go/microsoft/golang with 569 known CVEs.
- Most common base systems: Debian (13), Alpine (7), Ubuntu (7), Red Hat (3).
Most vulnerable images
| Image | CVEs | Critical | High | Fixable | Base OS |
|---|---|---|---|---|---|
| mcr.microsoft.com/oss/go/microsoft/golang | 569 | 5 | 88 | 0 | Debian |
| mariadb | 436 | 8 | 127 | 1 | Ubuntu |
| ruby | 379 | 2 | 14 | 0 | Debian |
| eclipse-temurin | 338 | 0 | 80 | 0 | Ubuntu |
| docker.io/vllm/vllm-openai | 299 | 15 | 153 | 33 | Ubuntu |
| wordpress | 290 | 4 | 18 | 0 | Debian |
| traefik | 210 | 17 | 83 | 202 | Alpine |
| php | 166 | 35 | 44 | 166 | Debian |
| docker.io/ubuntu/go | 147 | 9 | 41 | 85 | Ubuntu |
| postgres | 123 | 10 | 68 | 123 | Alpine |
Based on the latest public scan of each image. Scans made with credentials are never included. Guides · All image reports · Scan an image