Last scanned:
This base/runtime image is a clean foundation for building production images. It has a small number of low-severity vulnerabilities that pose negligible practical risk in a typical containerized environment. The image is officially published and pinned by digest, ensuring supply chain integrity. No immediate remediation is required. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-54370 | MEDIUM5.35 | libacl 2.3.1-2.amzn2023.0.2 fixed in 2.4.0-1.amzn2023.0.1 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-0864 | MEDIUM4.67 | python3-libs 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-0864 | LOW2.8 | python3 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-58016 | LOW2.78 | glib2 2.82.2-769.amzn2023 fixed in 2.82.2-770.amzn2023 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-3276 | LOW2.7 | python3 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-58014 | LOW2.63 | glib2 2.82.2-769.amzn2023 fixed in 2.82.2-770.amzn2023 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-58010 | LOW2.51 | glib2 2.82.2-769.amzn2023 fixed in 2.82.2-770.amzn2023 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-58012 | LOW2.51 | glib2 2.82.2-769.amzn2023 fixed in 2.82.2-770.amzn2023 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-58013 | LOW2.51 | glib2 2.82.2-769.amzn2023 fixed in 2.82.2-770.amzn2023 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-58011 | LOW2.29 | glib2 2.82.2-769.amzn2023 fixed in 2.82.2-770.amzn2023 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-58015 | LOW2.29 | glib2 2.82.2-769.amzn2023 fixed in 2.82.2-770.amzn2023 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-54369 | LOW2.17 | libacl 2.3.1-2.amzn2023.0.2 fixed in 2.4.0-1.amzn2023.0.1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-11972 | LOW1.99 | python3 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11972 | LOW1.99 | python3-libs 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9669 | LOW1.81 | python3 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9669 | LOW1.81 | python3-libs 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-3276 | LOW1.62 | python3-libs 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-11850 | LOW1.53 | krb5-libs 1.21.3-7.amzn2023.0.1 fixed in 1.21.3-8.amzn2023.0.1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-11940 | NONE0 | python3 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-11940 | NONE0 | python3-libs 3.9.25-1.amzn2023.0.7 fixed in 3.9.25-1.amzn2023.0.8 | 0.6% Theoretical Threat | Not Applicable |
Want to check another image? Run a full scan with the Docker Security Scanner.