Vulnerability Reportamazonlinux:2023.11.20260427.1

amazonlinux:2023.11.20260427.1
digestsha256:82085f72b15db462da227bd8a45c925c72f9d6f25965d22f1c31c47e0a803d80

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
TRUSTED

This base/runtime image carries significant vulnerabilities that any image built on it would inherit; remediate them in the final image before production. The most notable issues are medium-severity path traversal in glib (CVE-2026-58015), OpenSSL CMS forgery (CVE-2026-34182), and local privilege escalation via libacl (CVE-2026-54369), which could lead to file disclosure, integrity bypass, or local root access if targeted. Because this is a building block, the practical approach is to use it as a base only after applying available updates or verifying that affected packages are not part of the final runtime. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

91 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-58011MEDIUM6.38
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-58015MEDIUM6.38
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48863MEDIUM6.38
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-7210MEDIUM6.38
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-54369MEDIUM6.03
libacl
2.3.1-2.amzn2023.0.2
fixed in 2.4.0-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.9
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-56132MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-9149MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9150MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-11972MEDIUM5.52
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.3.1-2.amzn2023.0.2
fixed in 2.4.0-1.amzn2023.0.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-6019MEDIUM5.18
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-9669MEDIUM5.02
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34180MEDIUM5
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-0864MEDIUM4.67
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3276MEDIUM4.5
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-3446MEDIUM4.5
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-libs
1.21.3-6.amzn2023.0.1
fixed in 1.21.3-8.amzn2023.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6653LOW3
libxml2
2.10.4-1.amzn2023.0.18
fixed in 2.10.4-1.amzn2023.0.19
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6357LOW2.96
python3-pip-wheel
21.3.1-2.amzn2023.0.17
fixed in 21.3.1-2.amzn2023.0.19
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-0864LOW2.8
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-8643LOW2.8
python3-pip-wheel
21.3.1-2.amzn2023.0.17
fixed in 21.3.1-2.amzn2023.0.20
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW2.8
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3479LOW2.8
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-58016LOW2.78
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.7
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-3276LOW2.7
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3446LOW2.7
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-58014LOW2.63
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58010LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58012LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58013LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-40355LOW2.29
krb5-libs
1.21.3-6.amzn2023.0.1
fixed in 1.21.3-7.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-40356LOW2.29
krb5-libs
1.21.3-6.amzn2023.0.1
fixed in 1.21.3-7.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33811LOW2.29
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-42499LOW2.29
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-41989LOW2.29
libgcrypt
1.10.2-1.amzn2023.0.2
fixed in 1.10.2-1.amzn2023.0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW2.29
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW1.93
curl-minimal
8.17.0-1.amzn2023.0.2
fixed in 8.17.0-1.amzn2023.0.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW1.93
libcurl-minimal
8.17.0-1.amzn2023.0.2
fixed in 8.17.0-1.amzn2023.0.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9669LOW1.81
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57062LOW1.48
gnupg2-minimal
2.3.7-1.amzn2023.0.8
fixed in 2.3.7-1.amzn2023.0.9
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-53615NONE0
libblkid
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libmount
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libsmartcols
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libuuid
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-11940NONE0
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11940NONE0
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11822NONE0
sqlite-libs
3.40.0-1.amzn2023.0.7
fixed in 3.40.0-1.amzn2023.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-11824NONE0
sqlite-libs
3.40.0-1.amzn2023.0.7
fixed in 3.40.0-1.amzn2023.0.8
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.