Critical
Critical CVEs with known exploits, malware, or exposed secrets inside the image.



Identify known CVEs in OS packages, application dependencies, and base images before they reach production.

Detect hardcoded credentials, API keys, and malicious content hidden inside container layers.

Block images that violate security policies, contain critical vulnerabilities, or use untrusted base images.
Prioritized by severity, exploitability, and whether the vulnerable package is actually used at runtime.
Critical CVEs with known exploits, malware, or exposed secrets inside the image.
High-severity vulnerabilities in base images or application dependencies.
Medium-severity issues, outdated packages, or non-critical configuration findings.
Live output from the MadStack scanner — exact image, vulnerability, and recommended fix.

We support Docker Hub, Amazon ECR, Google Artifact Registry, Azure Container Registry, GitHub Container Registry, and private registries.
Best practice is to scan images during the CI/CD pipeline, before they are pushed to the registry, and continuously monitor images already in use.
Yes. You can define policies that automatically fail builds or block deployments when critical or high-severity vulnerabilities are found.
