home / Etcd / readystack/etcd:v3.7.2-CE-ubuntu24.04-r1 readystack/etcd:v3.7.2-CE-ubuntu24.04-r1 docker pull readystack/etcd:v3.7.2-CE-ubuntu24.04-r1 click to select
Image metadata PULL COUNT
—
repository-level (not per-tag)
RUNS AS
non-root
image config.User
LAST PUSHED
17d ago
2026-09-22 21:07:33
MANIFEST DIGEST
sha256:a0679768b769…
from registry manifest
Latest scan 2026-10-09 23:49:35 UTC · today OPEN CVES BY SEVERITY
Grype DB 2026-10-09T06:32:32.000Z
· rubric cerodeo-v1
RUBRIC BREAKDOWN (5 signals that moved the score) -20 · High CVEs (fixable) +10 · Runs as non-root +10 · Rebuilt in last 90 days +5 · Cosign signature +2 · readme_has_example
Raw data
Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or
massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.
Reproduce this score yourself
We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB.
Run the script below on any host with skopeo, syft,
grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.
curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh
./verify-score.sh readystack/etcd:v3.7.2-CE-ubuntu24.04-r1 \
--rubric cerodeo-v1 \
--grype-db 2026-10-09T06:32:32.000Z
All open CVEs (140) sorted by severity, then CVSS score CVE ID SEV CVSS PACKAGE FIX
CVE-2026-84782 HIGH — openssl 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-84782 HIGH — libssl3t64 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2024-10041 MEDIUM — libpam-runtime 1.5.3-5ubuntu5.7 no fix available CVE-2024-10041 MEDIUM — libpam-modules-bin 1.5.3-5ubuntu5.7 no fix available CVE-2024-10041 MEDIUM — libpam-modules 1.5.3-5ubuntu5.7 no fix available CVE-2026-76642 MEDIUM — libsmartcols1 2.39.3-9ubuntu6.6 no fix available CVE-2026-78408 MEDIUM — libsmartcols1 2.39.3-9ubuntu6.6 no fix available CVE-2026-78409 MEDIUM — libsmartcols1 2.39.3-9ubuntu6.6 no fix available CVE-2026-78410 MEDIUM — libsmartcols1 2.39.3-9ubuntu6.6 no fix available CVE-2026-82560 MEDIUM — perl-base 5.38.2-3.2ubuntu0.6 no fix available CVE-2026-85091 MEDIUM — zlib1g 1:1.3.dfsg-3.1ubuntu2.2 no fix available CVE-2026-86145 MEDIUM — libpcre2-8-0 10.42-4ubuntu2.1 no fix available CVE-2026-89156 MEDIUM — libpcre2-8-0 10.42-4ubuntu2.1 no fix available CVE-2026-89157 MEDIUM — libpcre2-8-0 10.42-4ubuntu2.1 no fix available CVE-2026-89158 MEDIUM — libpcre2-8-0 10.42-4ubuntu2.1 no fix available CVE-2026-89160 MEDIUM — libpcre2-8-0 10.42-4ubuntu2.1 no fix available CVE-2026-89161 MEDIUM — libpcre2-8-0 10.42-4ubuntu2.1 no fix available CVE-2026-89162 MEDIUM — libpcre2-8-0 10.42-4ubuntu2.1 no fix available GHSA-8wmf-6v46-5gfg LOW 2.0 go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 fixed in 1.45.0 GHSA-8wmf-6v46-5gfg LOW 2.0 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 fixed in 1.45.0 CVE-2026-35189 LOW — libssl3t64 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-35189 LOW — openssl 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-54872 LOW — libssl3t64 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-54872 LOW — openssl 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-75805 LOW — libssl3t64 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-75805 LOW — openssl 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-75806 LOW — openssl 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-75806 LOW — libssl3t64 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-77696 LOW — openssl 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 CVE-2026-77696 LOW — libssl3t64 3.0.13-0ubuntu3.15 fixed in 3.0.13-0ubuntu3.16 GO-2026-5932 UNKNOWN — golang.org/x/crypto v0.57.0 no fix available GO-2026-5932 UNKNOWN — golang.org/x/crypto v0.57.0 no fix available GO-2026-6603 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6603 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6603 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6610 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6610 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6610 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6611 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6611 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6611 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6612 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6612 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6612 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6617 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6617 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0 GO-2026-6617 UNKNOWN — golang.org/x/net v0.59.0 fixed in 0.60.0
Scan history 1 total · first today SCANNED AT GRADE SCORE CRIT HIGH MED GRYPE DB
today A 100 0 2 60 2026-10-09T06:32:32.000Z
Methodology:
This image is re-matched against the fresh Grype vulnerability DB every hour. Snapshot rows marked
(same SBOM) reuse the prior scan's content via a pointer — about
90% of hourly cycles do. New CVE disclosures land in a new content row and bump the grade on the next match.
Full rubric at /about/grades ; for publishers wanting to
raise their grade, see /about/for-publishers .