Vulnerability Reportamazoncorretto:21-alpine3.24

amazoncorretto:21-alpine3.24
digestsha256:ca805c030d45db58e93b2276580ea141aa7d33497009ab4c6b706c587a97e9b1

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. It contains 20 low-severity findings, but none exceed a severity of 4.5, and there are no post-exploit findings. These low-risk issues are unlikely to have practical impact on images built on top of this base image. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

20 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-18798MEDIUM4.5
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-63076MEDIUM4.5
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-18798MEDIUM4.5
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-63076MEDIUM4.5
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-14456LOW3.83
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-63072LOW3.83
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-14457LOW3.83
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-54874LOW3.83
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-63074LOW3.83
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-63075LOW3.83
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-14456LOW3.83
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-63072LOW3.83
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-14457LOW3.83
libssl3
3.5.7-r0
fixed in 3.5.8-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-54874LOW3.83
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-63074LOW3.83
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-63075LOW3.83
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-63073LOW3.01
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-63073LOW3.01
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-75803NONE0
libcrypto3
3.5.7-r0
fixed in 3.5.8-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-75803NONE0
libssl3
3.5.7-r0
fixed in 3.5.8-r0
0.1%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.