Vulnerability Reportamazonlinux:2.0.20260504.0

amazonlinux:2.0.20260504.0
digestsha256:74e5c80ad36e6ef0f6fd4a55bb3cc969c05dec6b9dc27fdfa68c8e77264901f9

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. It does contain 8 exposed and 35 post-exploit low-severity findings, but the highest severity is only 5.87 (exposed) and 3.98 (post-exploit), well below the threshold for concern. Because no high-severity vulnerabilities were identified, images built on this base inherit minimal risk. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

51 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-56132MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.7
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-52858LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-52860LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-55693LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-55895LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57456LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-41411LOW3.72
vim-minimal
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.6
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6766LOW3.11
nss-tools
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6767LOW3.11
nss-tools
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6772LOW3.11
nss-tools
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python
2.7.18-1.amzn2.0.18
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python-libs
2.7.18-1.amzn2.0.18
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6653LOW3
libxml2
2.9.1-6.amzn2.5.24
fixed in 2.9.1-6.amzn2.5.25
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-58016LOW2.78
glib2
2.56.1-9.amzn2.0.13
fixed in 2.56.1-9.amzn2.0.14
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-7598LOW2.78
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-47167LOW2.7
vim-minimal
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-47162LOW2.69
vim-minimal
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python
2.7.18-1.amzn2.0.18
fixed in 2.7.18-1.amzn2.0.19
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python-libs
2.7.18-1.amzn2.0.18
fixed in 2.7.18-1.amzn2.0.19
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-58050LOW2.29
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW2.17
python
2.7.18-1.amzn2.0.18
fixed in 2.7.18-1.amzn2.0.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW2.17
python-libs
2.7.18-1.amzn2.0.18
fixed in 2.7.18-1.amzn2.0.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58051LOW1.99
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python
2.7.18-1.amzn2.0.18
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python-libs
2.7.18-1.amzn2.0.18
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6766LOW1.87
nss
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6767LOW1.87
nss
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6772LOW1.87
nss
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6766LOW1.87
nss-sysinit
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6767LOW1.87
nss-sysinit
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6772LOW1.87
nss-sysinit
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW1.8
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-42766LOW1.62
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-11850LOW1.53
krb5-libs
1.15.1-55.amzn2.2.9
fixed in 1.15.1-55.amzn2.2.10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-47162NONE0
vim-data
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-52858NONE0
vim-data
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-52860NONE0
vim-data
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-55693NONE0
vim-data
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2026-55895NONE0
vim-data
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-57456NONE0
vim-data
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2026-41411NONE0
vim-data
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.6
0.5%
Theoretical Threat
Not Applicable
CVE-2026-47167NONE0
vim-data
2:9.0.2153-1.amzn2.0.5
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
libblkid
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libmount
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libuuid
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.