Container CVE TriageBeta

    Most container CVEs don't matter. Konvu shows you the ones that do.

    Scanners flag every CVE in the base image. Konvu identifies which ones are exploitable in your container, with evidence your team can defend.

    Question 1

    Is it in the image?

    Every CVE in every layer, including the ones your application never touches. Your scanner already answers this one.

    Question 2

    Does anything load it?

    A base image ships an OS, a runtime and dozens of system libraries. Your service imports a fraction of them.

    Question 3

    Can an attacker reach it?

    Whether the affected service is exposed, and whether attacker-controlled input reaches the vulnerable code in the running container.

    Scanners answer the first. Konvu answers all three, and attaches the evidence for each.

    Cut base image noise

    Most container CVEs aren't exploitable in your context. Konvu filters them out with evidence.

    Focus on what's exploitable

    Identify which container CVEs are reachable from your code and whether the exploit conditions are present.

    Evidence for every decision

    Audit-ready reasoning for every exploitability verdict. No black-box scores.

    No workflow changes

    Konvu reads findings from the container scanners you already run.

    In the product

    Container findings, in the same queue as the rest

    Container CVEs are assessed the same way as dependencies and code, land in the same queue, and carry the same evidence. One process, not a separate tool for images.

    overview · assessment results
    Image surface

    Your container has hundreds of packages. Your service loads a handful.

    A base image ships an operating system, a runtime and dozens of system libraries before any of your code arrives. Your scanner enumerates all of it. Konvu resolves what the running process actually imports, which is the question that separates a container CVE from a container risk.

    Image surface for checkout-web:2026.08: 201 packages shipped, 77 loaded at runtime. python:3.11-slim base layer, 4 of 96 loaded. apt-installed libs, 2 of 31 loaded. Application deps, 71 of 74 loaded. CVE-2022-40303 in libxml2, flagged high: in the base image, no import path from the service. Decides it: the process never loads libxml2. konvu: 127 packages under your app, 6 of them load.
    Evidence-backed decisions

    A verdict that survives the next image rebuild

    Base images change weekly, so a decision made once has to be re-checkable. Every verdict records the layer, the package, the import path it looked for, and the condition that decided it, so the call can be checked again when the image changes.

    Exploitable: Unbounded multipart parsing in Werkzeug (CVE-2023-25577). The service serves requests through Werkzeug 2.2.2, which parses an unlimited number of multipart parts. POST /checkout accepts multipart form data without sign-in, so one request can tie up a worker. Present in image: yes, application layer. Loaded by the service: yes, at startup. Multipart from the internet: yes, no sign-in (decides it). checkout-web:2026.08, application layer, High, CVSS 7.5. Jira SEC-4112 opened.

    Frequently asked questions

    Ready to cut through container CVE noise?

    See how Konvu reduces your container vulnerability backlog with evidence-backed triage.