home / Couchdb / couchdb:3.4.3-nouveau docker pull couchdb:3.4.3-nouveau click to select
Image metadata PULL COUNT
—
repository-level (not per-tag)
RUNS AS
root
image config.User
LAST PUSHED
4d ago
2026-10-06 01:41:58
MANIFEST DIGEST
sha256:8c9773278a44…
from registry manifest
Latest scan 2026-10-09 23:47:03 UTC · today OPEN CVES BY SEVERITY
Grype DB 2026-10-09T06:32:32.000Z
· rubric cerodeo-v1
RUBRIC BREAKDOWN (8 signals that moved the score) -125 · Critical CVEs (fixable) -160 · High CVEs (fixable) -45 · Medium CVEs (fixable) -32 · Critical CVEs (no fix) -234 · High CVEs (no fix) +10 · Rebuilt in last 90 days +3 · Multi-arch +2 · readme_has_example
Raw data
Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or
massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.
Reproduce this score yourself
We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB.
Run the script below on any host with skopeo, syft,
grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.
curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh
./verify-score.sh couchdb:3.4.3-nouveau \
--rubric cerodeo-v1 \
--grype-db 2026-10-09T06:32:32.000Z
All open CVEs (472) sorted by severity, then CVSS score CVE ID SEV CVSS PACKAGE FIX
CVE-2026-5450 CRITICAL 9.8 libc-bin 2.36-9+deb12u14 no fix available CVE-2026-5450 CRITICAL 9.8 libc6 2.36-9+deb12u14 no fix available CVE-2026-57433 CRITICAL 9.8 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-8376 CRITICAL 9.8 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2025-7458 CRITICAL 9.1 libsqlite3-0 3.40.1-2+deb12u2 no fix available CVE-2026-12087 CRITICAL 9.1 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-13221 CRITICAL 9.1 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-42496 CRITICAL 9.1 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-58016 CRITICAL 9.1 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-58014 HIGH 8.6 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-11822 HIGH 8.5 libsqlite3-0 3.40.1-2+deb12u2 no fix available CVE-2026-11824 HIGH 8.5 libsqlite3-0 3.40.1-2+deb12u2 no fix available CVE-2026-76642 HIGH 8.5 libsmartcols1 2.38.1-5+deb12u3 no fix available CVE-2026-76642 HIGH 8.5 util-linux-extra 2.38.1-5+deb12u3 no fix available CVE-2026-57432 HIGH 8.4 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-58010 HIGH 8.2 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-58012 HIGH 8.2 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-58013 HIGH 8.2 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-78408 HIGH 7.9 libsmartcols1 2.38.1-5+deb12u3 no fix available CVE-2026-78408 HIGH 7.9 util-linux-extra 2.38.1-5+deb12u3 no fix available CVE-2026-48962 HIGH 7.8 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-78410 HIGH 7.8 util-linux-extra 2.38.1-5+deb12u3 no fix available CVE-2026-78410 HIGH 7.8 libsmartcols1 2.38.1-5+deb12u3 no fix available CVE-2026-95619 HIGH 7.7 gcc-12-base 12.2.0-14+deb12u1 no fix available CVE-2023-2953 HIGH 7.5 libldap-2.5-0 2.5.13+dfsg-5 no fix available CVE-2026-107161 HIGH 7.5 libsasl2-modules-db 2.1.28+dfsg-10 no fix available CVE-2026-42497 HIGH 7.5 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-48959 HIGH 7.5 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-58011 HIGH 7.5 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-58015 HIGH 7.5 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-9538 HIGH 7.5 perl-base 5.36.0-7+deb12u3 no fix available CVE-2026-16118 HIGH 7.1 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-7017 HIGH 7.1 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-78409 HIGH 7.0 libsmartcols1 2.38.1-5+deb12u3 no fix available CVE-2026-78409 HIGH 7.0 util-linux-extra 2.38.1-5+deb12u3 no fix available CVE-2025-7709 MEDIUM 6.9 libsqlite3-0 3.40.1-2+deb12u2 no fix available CVE-2026-54411 MEDIUM 6.9 libpam-modules-bin 1.5.2-6+deb12u2 no fix available CVE-2026-54411 MEDIUM 6.9 libpam-runtime 1.5.2-6+deb12u2 no fix available CVE-2026-54411 MEDIUM 6.9 libpam-modules 1.5.2-6+deb12u2 no fix available CVE-2026-16742 MEDIUM 6.7 libsystemd0 252.39-1~deb12u2 no fix available CVE-2026-16742 MEDIUM 6.7 libsystemd-shared 252.39-1~deb12u2 no fix available CVE-2026-6791 MEDIUM 6.6 libc-bin 2.36-9+deb12u14 no fix available CVE-2023-5388 MEDIUM 6.5 libnss3 2:3.87.1-1+deb12u4 no fix available CVE-2024-7531 MEDIUM 6.5 libnss3 2:3.87.1-1+deb12u4 no fix available CVE-2025-68468 MEDIUM 6.5 libavahi-common3 0.8-10+deb12u1 no fix available CVE-2025-68468 MEDIUM 6.5 libavahi-common-data 0.8-10+deb12u1 no fix available CVE-2025-68468 MEDIUM 6.5 libavahi-client3 0.8-10+deb12u1 no fix available CVE-2025-68471 MEDIUM 6.5 libavahi-client3 0.8-10+deb12u1 no fix available CVE-2025-68471 MEDIUM 6.5 libavahi-common-data 0.8-10+deb12u1 no fix available CVE-2025-68471 MEDIUM 6.5 libavahi-common3 0.8-10+deb12u1 no fix available CVE-2026-24401 MEDIUM 6.5 libavahi-client3 0.8-10+deb12u1 no fix available CVE-2026-24401 MEDIUM 6.5 libavahi-common3 0.8-10+deb12u1 no fix available CVE-2026-24401 MEDIUM 6.5 libavahi-common-data 0.8-10+deb12u1 no fix available CVE-2026-6238 MEDIUM 6.5 libc-bin 2.36-9+deb12u14 no fix available CVE-2026-7010 MEDIUM 6.5 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2025-15649 MEDIUM 5.5 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2025-59529 MEDIUM 5.5 libavahi-common-data 0.8-10+deb12u1 no fix available CVE-2025-59529 MEDIUM 5.5 libavahi-common3 0.8-10+deb12u1 no fix available CVE-2025-59529 MEDIUM 5.5 libavahi-client3 0.8-10+deb12u1 no fix available CVE-2025-68276 MEDIUM 5.5 libavahi-common-data 0.8-10+deb12u1 no fix available CVE-2025-68276 MEDIUM 5.5 libavahi-common3 0.8-10+deb12u1 no fix available CVE-2025-68276 MEDIUM 5.5 libavahi-client3 0.8-10+deb12u1 no fix available CVE-2026-15059 MEDIUM 5.5 libsystemd0 252.39-1~deb12u2 no fix available CVE-2026-15059 MEDIUM 5.5 libsystemd-shared 252.39-1~deb12u2 no fix available CVE-2026-34933 MEDIUM 5.5 libavahi-common-data 0.8-10+deb12u1 no fix available CVE-2026-34933 MEDIUM 5.5 libavahi-client3 0.8-10+deb12u1 no fix available CVE-2026-34933 MEDIUM 5.5 libavahi-common3 0.8-10+deb12u1 no fix available CVE-2026-50812 MEDIUM 5.5 libsqlite3-0 3.40.1-2+deb12u2 no fix available CVE-2026-50813 MEDIUM 5.5 libsqlite3-0 3.40.1-2+deb12u2 no fix available CVE-2026-5704 MEDIUM 5.5 tar 1.34+dfsg-1.2+deb12u1 no fix available CVE-2026-95512 MEDIUM 5.5 libfreetype6 2.12.1+dfsg-5+deb12u4 no fix available CVE-2024-52615 MEDIUM 5.3 libavahi-client3 0.8-10+deb12u1 no fix available CVE-2024-52615 MEDIUM 5.3 libavahi-common3 0.8-10+deb12u1 no fix available CVE-2024-52615 MEDIUM 5.3 libavahi-common-data 0.8-10+deb12u1 no fix available CVE-2024-52616 MEDIUM 5.3 libavahi-common3 0.8-10+deb12u1 no fix available CVE-2024-52616 MEDIUM 5.3 libavahi-client3 0.8-10+deb12u1 no fix available CVE-2024-52616 MEDIUM 5.3 libavahi-common-data 0.8-10+deb12u1 no fix available CVE-2026-13595 MEDIUM 5.3 bsdutils 1:2.38.1-5+deb12u3 no fix available CVE-2026-13595 MEDIUM 5.3 util-linux-extra 2.38.1-5+deb12u3 no fix available CVE-2026-13595 MEDIUM 5.3 util-linux 2.38.1-5+deb12u3 no fix available CVE-2026-13595 MEDIUM 5.3 libsmartcols1 2.38.1-5+deb12u3 no fix available CVE-2026-15588 MEDIUM 5.3 libglib2.0-0 2.74.6-2+deb12u9 no fix available CVE-2026-19487 MEDIUM 5.3 perl-base 5.36.0-7+deb12u3 fixed in 5.36.0-7+deb12u4 CVE-2026-3184 MEDIUM 5.3 libsmartcols1 2.38.1-5+deb12u3 no fix available CVE-2026-3184 MEDIUM 5.3 libfdisk1 2.38.1-5+deb12u3 no fix available
Scan history 1 total · first today SCANNED AT GRADE SCORE CRIT HIGH MED GRYPE DB
today F 0 9 94 177 2026-10-09T06:32:32.000Z
Methodology:
This image is re-matched against the fresh Grype vulnerability DB every hour. Snapshot rows marked
(same SBOM) reuse the prior scan's content via a pointer — about
90% of hourly cycles do. New CVE disclosures land in a new content row and bump the grade on the next match.
Full rubric at /about/grades ; for publishers wanting to
raise their grade, see /about/for-publishers .