Vulnerability Reportalpine/java:22-jdk

alpine/java:22-jdkalpine/java:22alpine/java:22.0.2-jdkalpine/java:22.0.2
digestsha256:f1537f450ab5c45a07a3323cbbdc2e4388d70b01940cf2acecea67faa3b36229

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
UNVERIFIED

This base/runtime image carries significant vulnerabilities that any image built on it would inherit; remediate them in the final image before production. The most concerning is CVE-2026-28387 (use-after-free in OpenSSL DANE TLSA authentication), which could permit arbitrary code execution in an uncommon configuration, and CVE-2026-25210 (libexpat integer overflow) could cause information disclosure and data integrity issues with local access. While 57 exposed vulnerabilities are present, none exceed 6.88 severity, and the majority are conditional on non-default features (e.g., DANE TLSA, untgz utility) or local access, limiting the practical exposure for a jshell runtime. The final image should disable such optional modules if possible to mitigate these risks. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

110 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-28387MEDIUM6.88
libcrypto3
3.3.1-r3
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libssl3
3.3.1-r3
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-25210MEDIUM6.63
libexpat
2.6.2-r0
fixed in 2.7.4-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22801MEDIUM6.63
libpng
1.6.43-r0
fixed in 1.6.54-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40200MEDIUM6.63
musl
1.2.5-r0
fixed in 1.2.5-r3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22184MEDIUM6.63
zlib
1.3.1-r1
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33636MEDIUM6.46
libpng
1.6.43-r0
fixed in 1.6.56-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-45186MEDIUM6.38
libexpat
2.6.2-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-64720MEDIUM6.03
libpng
1.6.43-r0
fixed in 1.6.53-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-65018MEDIUM6.03
libpng
1.6.43-r0
fixed in 1.6.53-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-66293MEDIUM6.03
libpng
1.6.43-r0
fixed in 1.6.53-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22695MEDIUM6.03
libpng
1.6.43-r0
fixed in 1.6.54-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-26519MEDIUM5.95
musl
1.2.5-r0
fixed in 1.2.5-r1
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-9231MEDIUM5.9
libcrypto3
3.3.1-r3
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libcrypto3
3.3.1-r3
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-50602MEDIUM5.9
libexpat
2.6.2-r0
fixed in 2.6.4-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-9231MEDIUM5.9
libssl3
3.3.1-r3
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libssl3
3.3.1-r3
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.19.0-r2
fixed in 4.21.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-9230MEDIUM5.6
libcrypto3
3.3.1-r3
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-9230MEDIUM5.6
libssl3
3.3.1-r3
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-59375MEDIUM5.3
libexpat
2.6.2-r0
fixed in 2.7.2-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-12133MEDIUM5.3
libtasn1
4.19.0-r2
fixed in 4.20.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-64506MEDIUM5.18
libpng
1.6.43-r0
fixed in 1.6.53-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
libexpat
2.6.2-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
libexpat
2.6.2-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
libexpat
2.6.2-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r0
fixed in 1.2.5-r2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r1
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
libssl3
3.3.1-r3
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
openssl
3.3.1-r3
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2024-13176MEDIUM4
libcrypto3
3.3.1-r3
fixed in 3.3.2-r2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libssl3
3.3.1-r3
fixed in 3.3.2-r2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40200LOW3.98
musl-utils
1.2.5-r0
fixed in 1.2.5-r3
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69419LOW3.77
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-64505LOW3.74
libpng
1.6.43-r0
fixed in 1.6.53-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34757LOW3.74
libpng
1.6.43-r0
fixed in 1.6.57-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-9143LOW3.7
libcrypto3
3.3.1-r3
fixed in 3.3.2-r1
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2024-9143LOW3.7
libssl3
3.3.1-r3
fixed in 3.3.2-r1
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2025-26519LOW3.57
musl-utils
1.2.5-r0
fixed in 1.2.5-r1
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-9231LOW3.54
openssl
3.3.1-r3
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-31790LOW3.54
openssl
3.3.1-r3
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2024-45491LOW3.53
libexpat
2.6.2-r0
fixed in 2.6.3-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-45492LOW3.53
libexpat
2.6.2-r0
fixed in 2.6.3-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-6119LOW3.51
libcrypto3
3.3.1-r3
fixed in 3.3.2-r0
66.6%
Actively Exploited
Post-Exploit
CVE-2024-6119LOW3.51
libssl3
3.3.1-r3
fixed in 3.3.2-r0
66.6%
Actively Exploited
Post-Exploit
CVE-2024-6119LOW3.51
openssl
3.3.1-r3
fixed in 3.3.2-r0
66.6%
Actively Exploited
Post-Exploit
CVE-2025-69418LOW3.4
libcrypto3
3.3.1-r3
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libssl3
3.3.1-r3
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-9230LOW3.36
openssl
3.3.1-r3
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-41080LOW3.15
libexpat
2.6.2-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-9232LOW3.1
libcrypto3
3.3.1-r3
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-9232LOW3.1
libssl3
3.3.1-r3
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-15468LOW3.01
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-66199LOW3.01
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69420LOW3.01
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-22796LOW3.01
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libcrypto3
3.3.1-r3
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.3.1-r3
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
openssl
3.3.1-r3
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6042LOW2.8
musl-utils
1.2.5-r0
fixed in 1.2.5-r2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22795LOW2.8
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.7
libcrypto3
3.3.1-r3
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libcrypto3
3.3.1-r3
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libcrypto3
3.3.1-r3
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-45490LOW2.7
libexpat
2.6.2-r0
fixed in 2.6.3-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-8176LOW2.7
libexpat
2.6.2-r0
fixed in 2.7.0-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-33416LOW2.7
libpng
1.6.43-r0
fixed in 1.6.56-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28388LOW2.7
libssl3
3.3.1-r3
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libssl3
3.3.1-r3
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libssl3
3.3.1-r3
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28388LOW2.7
openssl
3.3.1-r3
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
openssl
3.3.1-r3
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl
3.3.1-r3
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-12797LOW2.66
libcrypto3
3.3.1-r3
fixed in 3.3.3-r0
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-12797LOW2.66
libssl3
3.3.1-r3
fixed in 3.3.3-r0
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-12797LOW2.66
openssl
3.3.1-r3
fixed in 3.3.3-r0
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-25646LOW2.48
libpng
1.6.43-r0
fixed in 1.6.55-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl
3.3.1-r3
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2024-13176LOW2.4
openssl
3.3.1-r3
fixed in 3.3.2-r2
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-68160LOW2.4
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-0840LOW2.29
binutils
2.42-r0
fixed in 2.42-r1
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2024-9143LOW2.22
openssl
3.3.1-r3
fixed in 3.3.2-r1
5.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-24515LOW2.12
libexpat
2.6.2-r0
fixed in 2.7.4-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW2.04
openssl
3.3.1-r3
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW1.86
openssl
3.3.1-r3
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-46394LOW1.68
busybox
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox-binsh
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
ssl_client
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-58251NONE0
busybox
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox-binsh
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
ssl_client
1.36.1-r29
fixed in 1.36.1-r31
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.