Last scanned:
This base/runtime image is a reasonable foundation, but it ships vulnerabilities worth remediating in the images built on top of it. The only elevated item is CVE-2026-63072 in openssl-libs and openssl-fips-provider-latest, where a crafted CMS message can trigger a small out-of-bounds heap write that corrupts memory and typically crashes the decrypting process, a denial-of-service impact at severity 6.0. Reachability is conditional: this code path is only exercised if a downstream image actually calls OpenSSL CMS decryption on attacker-supplied messages, which a plain Java runtime does not do by default. The 31 post-exploit-only findings inherited alongside it all remain below the 6.0 threshold, so they do not change the picture. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-63072 | MEDIUM6 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-63072 | MEDIUM6 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-56404 | MEDIUM5.87 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-66046 | MEDIUM5.1 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-50219 | MEDIUM5.02 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-14457 | MEDIUM4.5 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-18798 | MEDIUM4.5 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54874 | MEDIUM4.5 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63076 | MEDIUM4.5 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-14457 | MEDIUM4.5 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-18798 | MEDIUM4.5 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54874 | MEDIUM4.5 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63076 | MEDIUM4.5 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63074 | LOW3.83 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | LOW3.83 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-63074 | LOW3.83 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-63075 | LOW3.83 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-8927 | LOW3.82 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9079 | LOW3.82 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9079 | LOW3.82 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-56131 | LOW3.82 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-9547 | LOW3.77 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-63073 | LOW3.54 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-63073 | LOW3.54 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-11856 | LOW3.31 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW3.31 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-75803 | LOW3.15 | openssl-fips-provider-latest 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-75803 | LOW3.15 | openssl-libs 1:3.5.7-2.amzn2023.0.2 fixed in 1:3.5.8-1.amzn2023.0.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-8925 | LOW2.92 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-8925 | LOW2.92 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8458 | LOW2.48 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8458 | LOW2.48 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-76957 | LOW2.39 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-11586 | LOW2.29 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW2.29 | curl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11586 | LOW2.29 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW2.29 | libcurl-minimal 8.17.0-1.amzn2023.0.3 fixed in 8.21.0-5.amzn2023.0.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-56408 | NONE0 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | expat 2.6.3-1.amzn2023.0.6 fixed in 2.8.3-1.amzn2023.0.1 | 0.1% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.