Vulnerability Reportalmalinux:9.8-minimal

almalinux:9.8-minimal-20260602almalinux:9.8-minimalalmalinux:9-minimal
digestsha256:b0d6d72e3fc19c51119e3dbeee5a7211eba934d8dcf7d3ecddadf96b681645ed

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. It exposes 15 packages with a maximum severity of 5.5, and post-exploit findings are similarly low (max 2.92). No critical or high-severity vulnerabilities are present, and the image is obtained from the official Docker Hub source, making it suitable for further hardening in downstream images. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

36 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2024-34459MEDIUM5.5
libxml2
2.9.13-14.el9_7
fixed in 2.9.13-14.el9_8.1
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.34-270.el9_8
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.34-270.el9_8
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.34-270.el9_8
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45447LOW2.92
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-58016LOW2.78
glib2
2.68.4-19.el9_8.1
fixed in 2.68.4-19.el9_8.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.7
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-3.el9_8
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.24-4.el9
fixed in 0.7.24-6.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-54369LOW2.17
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-13151LOW2.12
libtasn1
4.16.0-9.el9
fixed in 4.16.0-10.el9_8
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-42764LOW2.12
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-6170LOW2.12
libxml2
2.9.13-14.el9_7
fixed in 2.9.13-14.el9_8.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6238LOW1.99
glibc
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
glibc-common
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
glibc-minimal-langpack
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
glibc
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
glibc-common
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
glibc-minimal-langpack
2.34-270.el9_8
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW1.81
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW1.81
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW1.8
openssl-libs
1:3.5.5-2.el9_8
fixed in 1:3.5.5-4.el9_8
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-5278NONE0
coreutils-single
8.32-40.el9
fixed in 8.32-41.el9_8
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.