Vulnerability Reportapache/kafka:latest

apache/kafka:latestapache/kafka:4.3.1apache/kafka:4.3.1-rc2
digestsha256:77e3df9054047a88b520d0cc46e16696d3b22022e1d580aeccd2632df6532837

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. While the vulnerability scan reports 23 exposed surface findings and 12 post-exploit findings, none reach a severity of 6.0, and the maximum exposed severity is 5.87, so they pose minimal practical risk. The image comes from the popular and reliable Apache community, is pinned by digest, and has a pre-calculated threat score of 0, confirming a minimal threat posture. These low-severity findings are not expected to impact confidentiality, integrity, or availability in a typical deployment.

Vulnerabilities

Vulnerability Log

35 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-56132MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56404MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-50219MEDIUM5.02
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-41080LOW3.15
libexpat
2.7.5-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2100LOW2.7
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit-trust
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-54512LOW2.48
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-54513LOW2.48
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-45186LOW2.29
libexpat
2.7.5-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-10051LOW2.29
org.eclipse.jetty:jetty-server
12.0.34
fixed in 12.0.36, 12.1.10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-54518LOW1.99
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.21.4
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-59888LOW1.99
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-54514LOW1.62
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-54515LOW1.62
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-54516LOW1.62
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.21.4, 3.1.4
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-54517LOW1.62
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.21.4, 3.1.4
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-56131NONE0
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56408NONE0
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-59949NONE0
at.yawk.lz4:lz4-java
1.10.2
fixed in 1.11.1
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.21.2
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
CVE-2026-59889NONE0
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.21.5, 2.18.9, 2.22.1
0.3%
Theoretical Threat
Not Applicable
GHSA-mhm7-754m-9p8wNONE0
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.18.9, 2.21.5
Not Applicable
CVE-2026-10050NONE0
org.eclipse.jetty:jetty-security
12.0.34
fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10
Not Applicable
CVE-2026-6790NONE0
org.eclipse.jetty:jetty-server
12.0.34
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable
CVE-2026-8384NONE0
org.eclipse.jetty:jetty-util
12.0.34
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable
CVE-2026-56740NONE0
org.jline:jline-remote-telnet
3.30.4
fixed in 4.2.1
0.5%
Theoretical Threat
Not Applicable
CVE-2026-56741NONE0
org.jline:jline-remote-telnet
3.30.4
fixed in 4.2.1
0.5%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.