A Multi-Scanner Census of the Linux Operating-System Base Images of Docker Hub

Resumo


Most container images build on an operating-system (OS) base image, yet the security posture of these bases is usually characterized with a single scanner. We present a recent multi-scanner census of Docker Hub’s Linux OS base images: 5,606 unique amd64 images across 20 distributions, scanned with 14 open-source tools. The vulnerability count per image varies by an order of magnitude across distributions and scales with image age more than with package count (standardized β ≈ 0.44 vs. 0.15), while image size points the other way and popularity explains almost nothing; about one in twelve historically published images can no longer be pulled by a current Docker Engine. The four package-vulnerability engines show pairwise agreement of at most 0.36 (Jaccard), and raw secret and malware detection rates above 80% do not survive manual validation: none of 1,100 sampled detections per axis was a true positive.

Referências

Boles, B. et al. (2024). Deciphering discrepancies: A comparative analysis of Docker image security. In SCAM. IEEE.

Bufalino, J. et al. (2025). SBOMproof: Beyond alleged SBOM compliance for supply chain security of container images. arXiv:2510.05798.

Dahlmanns, M. et al. (2023). Secrets revealed in container images: An internet-wide study on occurrence and impact. In ASIA CCS ’23, pages 797–811. ACM.

Haque, M. U. et al. (2022). Well begun is half done: An empirical study of exploitability and impact of base-image vulnerabilities. In SANER, pages 1066–1077. IEEE.

Ibrahim, M. H. et al. (2020). Too many images on DockerHub! how different are images for the same system? Empirical Softw. Eng., 25(5):4250–4281.

Kapelinski, C. and Kreutz, D. (2026a). CryptoCensus: Cryptographic posture and postquantum readiness of Docker Hub. In WTICG/SBSeg 2026. SBC.

Kapelinski, C. and Kreutz, D. (2026b). A uniform random-sample security measurement of Docker Hub images. In SBSeg 2026. SBC.

Kapelinski, C., Machado, B., and Kreutz, D. (2026). Vulnerabilities, secrets and misconfiguration in the highest-exposure Docker Hub images. arXiv preprint arXiv:2608.02669.

Liu, P. et al. (2020). Understanding the security risks of Docker Hub. In Computer Security – ESORICS 2020, pages 257–276. Springer.

Mills, A. et al. (2023). Longitudinal risk-based security assessment of Docker software container images. Comput. Secur., 135:103478.

Shi, H. et al. (2025). Dr. Docker: A large-scale security measurement of Docker image ecosystem. In WWW ’25. ACM.

Shu, R. et al. (2017). A study of security vulnerabilities on Docker Hub. In CODASPY ’17, pages 269–280. ACM.

Wist, K. et al. (2021). Vulnerability analysis of 2500 Docker Hub images. In Advances in Security, Networks, and Internet of Things, pages 307–327. Springer.

Zerouali, A. et al. (2019). On the relation between outdated Docker containers, severity vulnerabilities, and bugs. In SANER 2019, pages 491–501. IEEE.

Zerouali, A. et al. (2021). A multi-dimensional analysis of technical lag in Debian-based Docker images. Empirical Softw. Eng., 26(2):19.

Zhou, L., Dacier, M., and Konstantinou, C. (2026). A reality check on SBOM-based vulnerability management: An empirical study and a path forward. In CODASPY ’26. ACM.
Publicado
01/09/2026
KAPELINSKI, Cristhian; KREUTZ, Diego. A Multi-Scanner Census of the Linux Operating-System Base Images of Docker Hub. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1429-1435. DOI: https://doi.org/10.5753/sbseg.2026.28913.