Vulnerability Reportamazonlinux:2.0.20260515.0

amazonlinux:2.0.20260515.0
DIGESTsha256:22d5bff62c7d84c3f7b39e2697fd04a2262c1c97d55a028f4a8f233493b906eb

Executive Summary

SAFE

This base/runtime image is a clean foundation for building production images. It contains some low-severity post-exploit-only findings, but these are not exploitable from the network and do not affect the safety of images built on top. The official publisher and immutable digest further reduce risk. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Threat Score
0/100
SAFE
Reputation
TRUSTED
Docker Official

Vulnerabilities

Vulnerability Log

10 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-7598LOW2.78
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.7
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6766LOW1.87
nss
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6767LOW1.87
nss
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6772LOW1.87
nss
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6766LOW1.87
nss-sysinit
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6767LOW1.87
nss-sysinit
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6772LOW1.87
nss-sysinit
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6766LOW1.87
nss-tools
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6767LOW1.87
nss-tools
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6772LOW1.87
nss-tools
3.90.0-2.amzn2.0.2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit