Vulnerability Reportamazoncorretto:27

amazoncorretto:27.0.0-al2023amazoncorretto:27.0.0amazoncorretto:27-jdkamazoncorretto:27-al2023-jdkamazoncorretto:27-al2023amazoncorretto:27
digestsha256:0e4efd9e1cea5ff517e97e23c526a626fbf57ca272d12ff26c6b8e402832f9f3

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
TRUSTED

This base/runtime image is a reasonable foundation, but it ships vulnerabilities worth remediating in the images built on top of it. The only elevated item is CVE-2026-63072 in openssl-libs and openssl-fips-provider-latest, where a crafted CMS message can trigger a small out-of-bounds heap write that corrupts memory and typically crashes the decrypting process, a denial-of-service impact at severity 6.0. Reachability is conditional: this code path is only exercised if a downstream image actually calls OpenSSL CMS decryption on attacker-supplied messages, which a plain Java runtime does not do by default. The 31 post-exploit-only findings inherited alongside it all remain below the 6.0 threshold, so they do not change the picture. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

59 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-63072MEDIUM6
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-63072MEDIUM6
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-56404MEDIUM5.87
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-66046MEDIUM5.1
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-50219MEDIUM5.02
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-14457MEDIUM4.5
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-18798MEDIUM4.5
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-54874MEDIUM4.5
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-63076MEDIUM4.5
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-14457MEDIUM4.5
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-18798MEDIUM4.5
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-54874MEDIUM4.5
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-63076MEDIUM4.5
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2026-63074LOW3.83
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-63075LOW3.83
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-63074LOW3.83
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-63075LOW3.83
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-8927LOW3.82
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9079LOW3.82
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-56131LOW3.82
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-9547LOW3.77
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-63073LOW3.54
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-63073LOW3.54
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-11856LOW3.31
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-75803LOW3.15
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-75803LOW3.15
openssl-libs
1:3.5.7-2.amzn2023.0.2
fixed in 1:3.5.8-1.amzn2023.0.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-8925LOW2.92
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-8925LOW2.92
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-8286LOW2.48
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8458LOW2.48
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8286LOW2.48
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8458LOW2.48
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-76957LOW2.39
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW2.29
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW2.29
curl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW2.29
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW2.29
libcurl-minimal
8.17.0-1.amzn2023.0.3
fixed in 8.21.0-5.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-56408NONE0
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
expat
2.6.3-1.amzn2023.0.6
fixed in 2.8.3-1.amzn2023.0.1
0.1%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.