Azure / Azure/azure-functions-docker
Security vulnerabilities in docker image mcr.microsoft.com/azure-functions/python:4-python3.12-appservice
- Dominant language
- Dockerfile
- Stars
- 280
- Forks
- 126
- PR merge metrics
- No merged PRs in 30d
Description
The latest image mcr.microsoft.com/azure-functions/python:4-python3.12-appservice@sha256:42ea731295b260ffbf3eb0d39a8b219ad8334ffa70b06cbb68e31ddfe292c0c6 has security issues.
Microsoft Defender for Cloud detects the following security vulnerabilities in the image:
Severity | CVE | Fix status | Packages type | Vendor | Installed version | Package Name | Fixed version
Critical | CVE-2025-55315 | Fix Available | Language | microsoft.aspnetcore.app.runtime.linux-x64 | 8.0.20.0 | microsoft.aspnetcore.app.runtime.linux-x64 | 8.0.21
Critical | CVE-2025-55315 | Fix Available | Language | microsoft.aspnetcore.server.kestrel.core | 2.2.0.0 | microsoft.aspnetcore.server.kestrel.core | 2.3.6
Medium | CVE-2025-8869 | Fix Available | Language | pip | 25.2.0.0 | pip | N/A
Medium | CVE-2025-55248 | Fix Available | Language | microsoft.netcore.app.runtime.linux-x64 | 8.0.20.0 | microsoft.netcore.app.runtime.linux-x64 | 8.0.21
Contributor guide
No contributing guide indexed for this repository
Research direction
No source file or test is named. Start by locating the Docker image definition or build entry point for the affected Azure Functions Python tag, then rebuild and scan the image against the listed CVEs; done means the reported vulnerabilities are no longer present or have documented fixes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, docker, python
- Domain
- cloud, devops, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100