Vulnerability Reportamazonlinux:2023.12.20260817.0

amazonlinux:latestamazonlinux:2023.12.20260817.0amazonlinux:2023
digestsha256:181f98c48832fe926f8ca3b6ffeafcce128e96e77b93d08fbe9a9bc9403ce284

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. It has no exposed vulnerabilities, and the few post-exploit-only findings are very low severity (max 2.7), presenting no practical risk in this context. Being an official image pinned by digest adds an extra layer of integrity and reproducibility for downstream builds. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

3 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45409LOW2.7
python3-pip-wheel
21.3.1-2.amzn2023.0.20
fixed in 21.3.1-2.amzn2023.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
openssl-fips-provider-latest
1:3.5.7-2.amzn2023.0.1
fixed in 1:3.5.7-2.amzn2023.0.2
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-14456LOW2.29
openssl-libs
1:3.5.7-2.amzn2023.0.1
fixed in 1:3.5.7-2.amzn2023.0.2
0.7%
Theoretical Threat
Post-Exploit

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.