Last scanned:
This image is safe for production use. While the vulnerability scan reports 23 exposed surface findings and 12 post-exploit findings, none reach a severity of 6.0, and the maximum exposed severity is 5.87, so they pose minimal practical risk. The image comes from the popular and reliable Apache community, is pinned by digest, and has a pre-calculated threat score of 0, confirming a minimal threat posture. These low-severity findings are not expected to impact confidentiality, integrity, or availability in a typical deployment.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-56132 | MEDIUM5.87 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56404 | MEDIUM5.87 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56407 | MEDIUM5.87 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-41080 | LOW3.15 | libexpat 2.7.5-r0 fixed in 2.8.1-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-2100 | LOW2.7 | p11-kit 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-2100 | LOW2.7 | p11-kit-trust 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-54512 | LOW2.48 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-54513 | LOW2.48 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-45186 | LOW2.29 | libexpat 2.7.5-r0 fixed in 2.8.1-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-10051 | LOW2.29 | org.eclipse.jetty:jetty-server 12.0.34 fixed in 12.0.36, 12.1.10 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-54518 | LOW1.99 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-59888 | LOW1.99 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-54514 | LOW1.62 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-54515 | LOW1.62 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-54516 | LOW1.62 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4, 3.1.4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-54517 | LOW1.62 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4, 3.1.4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-56131 | NONE0 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56408 | NONE0 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat 2.7.5-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-59949 | NONE0 | at.yawk.lz4:lz4-java 1.10.2 fixed in 1.11.1 | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.21.2 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| CVE-2026-59889 | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.5, 2.18.9, 2.22.1 | 0.3% Theoretical Threat | Not Applicable |
| GHSA-mhm7-754m-9p8w | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.9, 2.21.5 | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty:jetty-security 12.0.34 fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-6790 | NONE0 | org.eclipse.jetty:jetty-server 12.0.34 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-8384 | NONE0 | org.eclipse.jetty:jetty-util 12.0.34 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-56740 | NONE0 | org.jline:jline-remote-telnet 3.30.4 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-56741 | NONE0 | org.jline:jline-remote-telnet 3.30.4 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.