Vulnerability Reportamazoncorretto:25

amazoncorretto:25.0.3-al2023amazoncorretto:25.0.3amazoncorretto:25-jdkamazoncorretto:25-al2023-jdkamazoncorretto:25-al2023amazoncorretto:25
DIGESTsha256:b0a9deb21c7c9b9c71c0a479d66040132e34d6b8adb2e9c1572af0d67689d0c4

Executive Summary

SAFE

This base/runtime image is a clean foundation for building production images. It has no exposed vulnerabilities, and the 6 post-exploit-only findings are all low severity (max CVSS 2.7), meaning they require local access or have minimal impact. The image is trusted as an official Docker image and pinned by digest, ensuring integrity. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Threat Score
0/100
SAFE
Reputation
TRUSTED
Docker Official

Vulnerabilities

Vulnerability Log

6 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-48863LOW2.7
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9149LOW1.99
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9150LOW1.99
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit