Vulnerability Reportamazoncorretto:8

amazoncorretto:latestamazoncorretto:8u492-al2-genericamazoncorretto:8u492-al2amazoncorretto:8u492amazoncorretto:8-al2-jdkamazoncorretto:8-al2-generic-jdkamazoncorretto:8-al2-genericamazoncorretto:8-al2-fullamazoncorretto:8
DIGESTsha256:200af6d10d5a656a6bd997ac88bcd83be91f45f55d0b92656f57f0625f9ae25b

Executive Summary

SAFE

This base/runtime image is a clean foundation for building production images. It contains one low-severity post-exploit vulnerability (severity 2.78) that requires local access and poses no practical risk in typical deployments. The image is officially maintained and pinned by digest, guaranteeing consistency. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Threat Score
0/100
SAFE
Reputation
TRUSTED
Docker Official

Vulnerabilities

Vulnerability Log

1 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-7598LOW2.78
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.7
0.4%
Theoretical Threat
Post-Exploit