Security scan reports critical and high CVEs in latest Docker image
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 34.7k
- Forks
- 2.7k
- Avg merge
- 1d 18h
- Merged PRs (30d)
- 187
Description
Hi Qdrant team,
First of all, thank you for maintaining Qdrant and the official Docker images. We ran a vulnerability scan against the latest qdrant/qdrant Docker image and the scan reported 4 critical and 41 high vulnerabilities.
We understand that some scanner findings may depend on the scanner database, image layer metadata, package reachability, or whether an upstream distro fix is already available. Could you please help confirm whether these findings are already known, and whether there is a plan to refresh/rebuild the image with the relevant patched dependencies? If there is already a planned fix, an approximate timeline would be very helpful for our internal planning.
To keep this issue readable, I am listing the critical findings first since they are the highest priority for us:
CVE-2026-57433CVE-2026-13221CVE-2026-12087CVE-2026-34182
The scan also reports many high-severity findings, but I am not listing all of them here yet because the list is quite long. I can provide a screenshot or additional scan details if that would be useful.
Would it be possible to prioritize the critical findings first, and then address the high-severity items in a later image refresh if needed?
Thanks again for your work on Qdrant, and please let me know if there is a better place or format for reporting this kind of image vulnerability information.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the latest qdrant/qdrant Docker image scan and the four listed critical CVEs, then compare the findings with image metadata and available upstream fixes. Done means the findings are confirmed and documented, or the image is refreshed so the affected vulnerabilities are addressed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker
- Domain
- infrastructure, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 40/100