A Uniform Random-Sample Security Measurement of Docker Hub Images

Resumo


Registry-scale security measurements of Docker Hub define their samples by repository class, category, popularity, or estimated reach. Their findings therefore describe selected subsets rather than the registry-wide posture of a typical scannable latest image. We estimate that posture from 2,879 such images obtained by uniformly sampling 12.7 million repositories. Six open-source scanners match the pipeline used on our exposure-ranked sample, where exposure is the number of pulls reached directly or through reused layers. 94.4% of random images carry a critical vulnerability, compared with 93.4% of exposure-ranked images. Tool choice strongly affects the reported posture: 70.5% of image–CVE pairs appear in only one of three scanners. TruffleHog reports secrets in 82.4% of images, but hand-labeling shows that 99.5% of these detections are false positives. Exposure-based prioritization identifies vulnerabilities likely to affect more users, but the selected images are not more vulnerable than typical scannable latest images.

Referências

Baltes, S. and Ralph, P. (2022). Sampling in software engineering research: A critical review and guidelines. EMSE, 27(4):94.

Churakova, Y., Ekstedt, M., and Schmid, L. (2026). Vexed by VEX tools: Consistency evaluation of container vulnerability scanners. In FPS 2025, volume 16402, pages 139–156.

Dahlmanns, M. et al. (2023). Secrets revealed in container images: An internet-wide study on occurrence and impact. In ASIA CCS ’23, pages 797–811.

Haque, M. U. and Babar, M. A. (2022). Well begun is half done: An empirical study of exploitability and impact of base-image vulnerabilities. In SANER 2022, pages 1066–1077.

Ibrahim, M. H., Sayagh, M., and Hassan, A. E. (2020). Too many images on Docker Hub! How different are images for the same system? EMSE, 25(5):4250–4281.

Kapelinski, C. and Kreutz, D. (2026a). CryptoCensus: Cryptographic posture and post-quantum readiness of Docker Hub. In WTICG/SBSeg.

Kapelinski, C. and Kreutz, D. (2026b). A multi-scanner census of the Linux operating-system base images of Docker Hub. In SBSeg.

Kapelinski, C., Machado, B., and Kreutz, D. (2026). Vulnerabilities, secrets and misconfiguration in the highest-exposure Docker Hub images. arXiv preprint arXiv:2608.02669.

Kaur, B. et al. (2021). An analysis of security vulnerabilities in container images for scientific data analysis. GigaScience, 10(6):giab025.

Liu, P. et al. (2020). Understanding the security risks of Docker Hub. In ESORICS 2020, volume 12308, pages 257–276.

Mills, A., White, J., and Legg, P. (2023). Longitudinal risk-based security assessment of docker software container images. Computers & Security, 135:103478.

O’Donoghue, E. et al. (2024). Impacts of software bill of materials (SBOM) generation on vulnerability detection. In SCORED ’24, pages 67–76.

Shi, H. et al. (2025). Dr. Docker: A large-scale security measurement of Docker image ecosystem. In WWW ’25, pages 2813–2823. ACM.

Shu, R., Gu, X., and Enck, W. (2017). A study of security vulnerabilities on Docker Hub. In CODASPY, pages 269–280.

Wilson, E. B. (1927). Probable inference, the law of succession, and statistical inference. JASA, 22(158):209–212.

Wist, K., Helsem, M., and Gligoroski, D. (2021). Vulnerability analysis of 2500 Docker Hub images. In Advances in Security, Networks, and Internet of Things, pages 307–327.

Zerouali, A. et al. (2019). On the relation between outdated Docker containers, severity vulnerabilities, and bugs. In SANER 2019, pages 491–501.
Publicado
01/09/2026
KAPELINSKI, Cristhian; KREUTZ, Diego. A Uniform Random-Sample Security Measurement of Docker Hub Images. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1422-1428. DOI: https://doi.org/10.5753/sbseg.2026.28933.