Vulnerability Reportapache/zeppelin:0.12.1

apache/zeppelin:0.12.1
DIGESTsha256:ebb76b9b98f1b5457cd10c118fc6624269918a3602711a08d9f237673c0c0abb

Executive Summary

Threat Score
100/100DANGEROUS
Reputation
RELIABLE

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker can achieve remote code execution via crafted notebook templates (CVE-2025-59340), YAML parsing (CVE-2022-1471), or image upload (CVE-2023-4863), and can bypass authorization through HTTP request smuggling (CVE-2017-7657). Upgrading to patched versions (e.g., jinjava 2.8.1+, snakeyaml 2.0+, libwebp 1.3.2+) would eliminate these critical flaws. Note: Jackson deserialization issues (CVE-2019-16942, etc.) require Default Typing to be enabled, which may not be active by default in all deployments.

Vulnerabilities

Vulnerability Log

343 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-59340CRITICAL10
com.hubspot.jinjava:jinjava
2.4.0
fixed in 2.8.1, 2.7.5
2.3%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2025-59340CRITICAL10
com.hubspot.jinjava:jinjava
2.5.4
fixed in 2.8.1, 2.7.5
2.3%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2017-7657CRITICAL10
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.2.25.v20180606, 9.3.24.v20180605
16.2%
High Exploitation Risk
Directly ExposedContext importance: HIGH
CVE-2017-7658CRITICAL10
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.2.25.v20180606, 9.3.24.v20180605, 9.4.11.v20180605
21.0%
High Exploitation Risk
Directly ExposedContext importance: HIGH
CVE-2022-1471CRITICAL10
org.yaml:snakeyaml
1.15
fixed in 2.0
99.6%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2023-4863CRITICAL10
Pillow
9.2.0
fixed in 10.0.1
99.7%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2019-16942CRITICAL9.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3
5.7%
Low-Moderate Risk
Directly Exposed
CVE-2019-16943CRITICAL9.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3
4.9%
Low-Moderate Risk
Directly Exposed
CVE-2019-17267CRITICAL9.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10, 2.8.11.5
4.6%
Low-Moderate Risk
Directly Exposed
CVE-2019-17531CRITICAL9.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3
5.3%
Low-Moderate Risk
Directly Exposed
CVE-2019-20330CRITICAL9.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.2
8.6%
Low-Moderate Risk
Directly Exposed
CVE-2020-9546CRITICAL9.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
4.6%
Low-Moderate Risk
Directly Exposed
CVE-2021-4104CRITICAL9.75
log4j:log4j
1.2.17
No fix yet
81.1%
Actively Exploited
Directly Exposed
CVE-2015-2080CRITICAL9.75
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.2.9.v20150224
74.9%
Actively Exploited
Directly Exposed
CVE-2021-28165CRITICAL9.75
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.4.39, 10.0.2, 11.0.2
53.9%
Actively Exploited
Directly Exposed
CVE-2020-35728CRITICAL9.31
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8
12.5%
High Exploitation Risk
Directly Exposed
CVE-2020-36179CRITICAL9.31
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8, 2.6.7.5
20.9%
High Exploitation Risk
Directly Exposed
CVE-2020-36184CRITICAL9.31
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8
10.4%
High Exploitation Risk
Directly Exposed
CVE-2020-36188CRITICAL9.31
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8, 2.6.7.5
10.9%
High Exploitation Risk
Directly Exposed
CVE-2020-7692CRITICAL9.1
com.google.oauth-client:google-oauth-client
1.23.0
fixed in 1.31.0
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2020-7692CRITICAL9.1
com.google.oauth-client:google-oauth-client
1.30.5
fixed in 1.31.0
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2019-20444CRITICAL9.1
io.netty:netty
3.10.6.Final
fixed in 4.0.0
8.7%
Low-Moderate Risk
Directly Exposed
CVE-2023-44981CRITICAL9.1
org.apache.zookeeper:zookeeper
3.5.5
fixed in 3.7.2, 3.8.3, 3.9.1
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2023-44981CRITICAL9.1
org.apache.zookeeper:zookeeper
3.6.3
fixed in 3.7.2, 3.8.3, 3.9.1
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2020-10672HIGH8.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-10673HIGH8.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4, 2.6.7.4
8.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-10968HIGH8.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
3.6%
Low-Moderate Risk
Directly Exposed
CVE-2020-10969HIGH8.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
3.5%
Low-Moderate Risk
Directly Exposed
CVE-2020-11111HIGH8.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
3.5%
Low-Moderate Risk
Directly Exposed
CVE-2020-11112HIGH8.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
3.6%
Low-Moderate Risk
Directly Exposed
CVE-2020-11113HIGH8.8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
6.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-47561HIGH8.8
org.apache.avro:avro
1.11.2
fixed in 1.11.4
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-4759HIGH8.8
org.eclipse.jgit:org.eclipse.jgit
4.5.4.201711221230-r
fixed in 6.6.1.202309021850-r, 5.13.3.202401111512-r
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2022-39286HIGH8.8
jupyter_core
4.11.1
fixed in 4.11.2
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2019-12086HIGH8.62
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.9, 2.8.11.4, 2.7.9.6, 2.6.7.3
21.9%
High Exploitation Risk
Directly Exposed
CVE-2019-14439HIGH8.62
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6, 2.6.7.3
10.8%
High Exploitation Risk
Directly Exposed
CVE-2020-25649HIGH8.62
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.6.7.4, 2.9.10.7, 2.10.5.1
17.6%
High Exploitation Risk
Directly Exposed
CVE-2019-12402HIGH8.62
org.apache.commons:commons-compress
1.18
fixed in 1.19
16.2%
High Exploitation Risk
Directly Exposed
CVE-2021-35515HIGH8.62
org.apache.commons:commons-compress
1.18
fixed in 1.21
11.9%
High Exploitation Risk
Directly Exposed
CVE-2021-35516HIGH8.62
org.apache.commons:commons-compress
1.18
fixed in 1.21
12.7%
High Exploitation Risk
Directly Exposed
CVE-2021-35517HIGH8.62
org.apache.commons:commons-compress
1.18
fixed in 1.21
10.9%
High Exploitation Risk
Directly Exposed
CVE-2021-36090HIGH8.62
org.apache.commons:commons-compress
1.18
fixed in 1.21
13.3%
High Exploitation Risk
Directly Exposed
CVE-2019-10172HIGH8.62
org.codehaus.jackson:jackson-mapper-asl
1.9.13
No fix yet
17.0%
High Exploitation Risk
Directly Exposed
CVE-2021-33813HIGH8.62
org.jdom:jdom
1.1
No fix yet
19.4%
High Exploitation Risk
Directly Exposed
CVE-2017-18640HIGH8.62
org.yaml:snakeyaml
1.15
fixed in 1.26
26.7%
High Exploitation Risk
Directly Exposed
CVE-2026-27727HIGH8.33
com.mchange:mchange-commons-java
0.2.15
fixed in 0.4.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41409HIGH8.33
org.apache.mina:mina-core
2.0.7
fixed in 2.0.28, 2.1.11, 2.2.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41635HIGH8.33
org.apache.mina:mina-core
2.0.7
fixed in 2.0.28, 2.1.11, 2.2.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-66034HIGH8.33
fonttools
4.38.0
fixed in 4.60.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2020-10650HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2020-11619HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
3.6%
Low-Moderate Risk
Directly Exposed
CVE-2020-11620HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2020-14060HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.5
8.5%
Low-Moderate Risk
Directly Exposed
CVE-2020-14061HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.5
4.4%
Low-Moderate Risk
Directly Exposed
CVE-2020-14062HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.5
8.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-14195HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.5
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2020-24616HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.6
9.3%
Low-Moderate Risk
Directly Exposed
CVE-2020-24750HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.6.7.5, 2.9.10.6
7.3%
Low-Moderate Risk
Directly Exposed
CVE-2020-35490HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8
7.7%
Low-Moderate Risk
Directly Exposed
CVE-2020-35491HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8
9.5%
Low-Moderate Risk
Directly Exposed
CVE-2020-36180HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8, 2.6.7.5
5.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-36181HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8, 2.6.7.5
5.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-36182HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8, 2.6.7.5
5.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-36183HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8, 2.6.7.5
4.9%
Low-Moderate Risk
Directly Exposed
CVE-2020-36185HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8
5.2%
Low-Moderate Risk
Directly Exposed
CVE-2020-36186HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8
5.2%
Low-Moderate Risk
Directly Exposed
CVE-2020-36187HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8
5.2%
Low-Moderate Risk
Directly Exposed
CVE-2020-36189HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.8, 2.6.7.5
4.9%
Low-Moderate Risk
Directly Exposed
CVE-2021-20190HIGH8.1
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.7, 2.6.7.5
7.5%
Low-Moderate Risk
Directly Exposed
CVE-2019-7611HIGH8.1
org.elasticsearch:elasticsearch
2.4.3
fixed in 5.6.15, 6.6.1
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-50447HIGH8.1
Pillow
9.2.0
fixed in 10.2.0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2019-14540HIGH8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10, 2.8.11.5, 2.6.7.3
10.7%
High Exploitation Risk
Directly ExposedContext importance: MEDIUM
CVE-2020-8840HIGH8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.3
26.6%
High Exploitation Risk
Directly ExposedContext importance: MEDIUM
CVE-2020-9547HIGH8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7
18.7%
High Exploitation Risk
Directly ExposedContext importance: MEDIUM
CVE-2020-9548HIGH8
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7
18.3%
High Exploitation Risk
Directly ExposedContext importance: MEDIUM
CVE-2019-14379HIGH7.84
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6
8.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2019-16335HIGH7.84
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10, 2.8.11.5, 2.6.7.3
4.9%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2019-14892HIGH7.84
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.6.7.3, 2.8.11.5, 2.9.10
5.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2019-14893HIGH7.84
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.10
4.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2019-10202HIGH7.84
org.codehaus.jackson:jackson-mapper-asl
1.9.13
No fix yet
5.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-42584HIGH7.73
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2332HIGH7.73
org.eclipse.jetty:jetty-http
11.0.24
fixed in 12.1.7, 12.0.33
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2332HIGH7.73
org.eclipse.jetty:jetty-http
9.4.54.v20240208
fixed in 12.1.7, 12.0.33
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58782HIGH7.7
org.apache.jackrabbit:jackrabbit-jcr-commons
1.6.5
fixed in 2.22.2
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2020-36518HIGH7.5
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.13.2.1, 2.12.6.1
4.9%
Low-Moderate Risk
Directly Exposed
CVE-2022-42003HIGH7.5
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.12.7.1, 2.13.4.2
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2022-42004HIGH7.5
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.12.7.1, 2.13.4
2.7%
Low-Moderate Risk
Directly Exposed
CVE-2024-7254HIGH7.5
com.google.protobuf:protobuf-java
3.21.7
fixed in 3.25.5, 4.27.5, 4.28.2
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2023-46120HIGH7.5
com.rabbitmq:amqp-client
5.5.3
fixed in 5.18.0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-3635HIGH7.5
com.squareup.okio:okio
1.15.0
fixed in 3.4.0, 1.17.6
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-3635HIGH7.5
com.squareup.okio:okio
1.17.3
fixed in 3.4.0, 1.17.6
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2021-37136HIGH7.5
io.netty:netty
3.10.6.Final
fixed in 4.0.0
5.7%
Low-Moderate Risk
Directly Exposed
CVE-2021-37137HIGH7.5
io.netty:netty
3.10.6.Final
fixed in 4.0.0
6.3%
Low-Moderate Risk
Directly Exposed
CVE-2021-37136HIGH7.5
io.netty:netty-codec
4.1.51.Final
fixed in 4.1.68.Final
5.7%
Low-Moderate Risk
Directly Exposed
CVE-2021-37137HIGH7.5
io.netty:netty-codec
4.1.51.Final
fixed in 4.1.68.Final
6.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-26464HIGH7.5
log4j:log4j
1.2.17
fixed in 2.0
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2023-39410HIGH7.5
org.apache.avro:avro
1.11.2
fixed in 1.11.3
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2015-3250HIGH7.5
org.apache.directory.api:api-ldap-model
1.0.0-M20
fixed in 1.0.0-M31
5.1%
Low-Moderate Risk
Directly Exposed
CVE-2021-39239HIGH7.5
org.apache.jena:jena-core
3.12.0
fixed in 4.2.0
4.0%
Low-Moderate Risk
Directly Exposed
CVE-2019-0231HIGH7.5
org.apache.mina:mina-core
2.0.7
fixed in 2.0.21, 2.1.1
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2020-13949HIGH7.5
org.apache.thrift:libthrift
0.13.0
fixed in 0.14.0
6.8%
Low-Moderate Risk
Directly Exposed
CVE-2017-7656HIGH7.5
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.3.24.v20180605, 9.4.11.v20180605
6.4%
Low-Moderate Risk
Directly Exposed
CVE-2017-9735HIGH7.5
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.4.6.v20170531, 9.3.20.v20170531, 9.2.22.v20170606
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2023-31418HIGH7.5
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.13, 8.9.0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-37714HIGH7.5
org.jsoup:jsoup
1.10.3
fixed in 1.14.2
6.9%
Low-Moderate Risk
Directly Exposed
CVE-2021-37714HIGH7.5
org.jsoup:jsoup
1.11.3
fixed in 1.14.2
6.9%
Low-Moderate Risk
Directly Exposed
CVE-2021-37714HIGH7.5
org.jsoup:jsoup
1.8.1
fixed in 1.14.2
6.9%
Low-Moderate Risk
Directly Exposed
CVE-2022-25857HIGH7.5
org.yaml:snakeyaml
1.15
fixed in 1.31
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2022-45199HIGH7.5
Pillow
9.2.0
fixed in 9.3.0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-44271HIGH7.5
Pillow
9.2.0
fixed in 10.0.0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-45139HIGH7.5
fonttools
4.38.0
fixed in 4.43.0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-3651HIGH7.5
idna
3.4
fixed in 3.7
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-52804HIGH7.5
tornado
6.2
fixed in 6.4.2
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-67030HIGH7.48
org.codehaus.plexus:plexus-utils
3.2.1
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-56201HIGH7.48
Jinja2
3.1.4
fixed in 3.1.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-27516HIGH7.48
Jinja2
3.1.4
fixed in 3.1.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-12797HIGH7.4
cryptography
42.0.2
fixed in 44.0.1
2.4%
Low-Moderate Risk
Directly Exposed
CVE-2023-24816HIGH7
ipython
7.33.0
fixed in 8.10.0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.51.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.75.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.87.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-27830MEDIUM6.8
com.mchange:c3p0
0.9.5.4
fixed in 0.12.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2019-12384MEDIUM6.79
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3
45.2%
High Exploitation Risk
Directly Exposed
CVE-2019-12814MEDIUM6.79
com.fasterxml.jackson.core:jackson-databind
2.9.8
fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3
11.0%
High Exploitation Risk
Directly Exposed
CVE-2016-5725MEDIUM6.79
com.jcraft:jsch
0.1.53
fixed in 0.1.54
24.1%
High Exploitation Risk
Directly Exposed
CVE-2021-21295MEDIUM6.79
io.netty:netty
3.10.6.Final
fixed in 4.0.0
18.9%
High Exploitation Risk
Directly Exposed
CVE-2025-54920MEDIUM6.7
org.apache.spark:spark-core_2.12
3.5.3
fixed in 3.5.7
5.3%
Low-Moderate Risk
Directly Exposed
CVE-2020-12668MEDIUM6.5
com.hubspot.jinjava:jinjava
2.4.0
fixed in 2.5.4
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2021-37533MEDIUM6.5
commons-net:commons-net
3.3
fixed in 3.9.0
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2021-43797MEDIUM6.5
io.netty:netty
3.10.6.Final
fixed in 4.0.0
2.7%
Low-Moderate Risk
Directly Exposed
CVE-2023-34462MEDIUM6.5
io.netty:netty-handler
4.1.51.Final
fixed in 4.1.94.Final
2.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-34462MEDIUM6.5
io.netty:netty-handler
4.1.75.Final
fixed in 4.1.94.Final
2.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-34462MEDIUM6.5
io.netty:netty-handler
4.1.87.Final
fixed in 4.1.94.Final
2.5%
Low-Moderate Risk
Directly Exposed
CVE-2021-41973MEDIUM6.5
org.apache.mina:mina-core
2.0.7
fixed in 2.1.5, 2.0.22
4.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-8184MEDIUM6.5
org.eclipse.jetty:jetty-server
9.4.54.v20240208
fixed in 12.0.9, 10.0.24, 11.0.24, 9.4.56
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-7019MEDIUM6.5
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.9.0, 6.8.12
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-22144MEDIUM6.5
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.17, 7.13.3
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2022-38749MEDIUM6.5
org.yaml:snakeyaml
1.15
fixed in 1.31
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2022-38751MEDIUM6.5
org.yaml:snakeyaml
1.15
fixed in 1.31
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2022-38752MEDIUM6.5
org.yaml:snakeyaml
1.15
fixed in 1.32
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2022-41854MEDIUM6.5
org.yaml:snakeyaml
1.15
fixed in 1.32
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2025-52999MEDIUM6.38
com.fasterxml.jackson.core:jackson-core
2.9.8
fixed in 2.15.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2021-0341MEDIUM6.38
com.squareup.okhttp3:okhttp
3.12.12
fixed in 4.9.2
0.9%
Theoretical Threat
Directly Exposed
CVE-2021-0341MEDIUM6.38
com.squareup.okhttp3:okhttp
3.13.1
fixed in 4.9.2
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.51.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.75.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.87.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-58056MEDIUM6.38
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-55163MEDIUM6.38
io.netty:netty-codec-http2
4.1.87.Final
fixed in 4.2.4.Final, 4.1.124.Final
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33871MEDIUM6.38
io.netty:netty-codec-http2
4.1.87.Final
fixed in 4.1.132.Final, 4.2.11.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.87.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.87.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.51.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.51.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.75.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.75.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.87.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.87.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42578MEDIUM6.38
io.netty:netty-handler-proxy
4.1.87.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34479MEDIUM6.38
org.apache.logging.log4j:log4j-1.2-api
2.20.0
fixed in 2.25.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34480MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-34480MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.20.0
fixed in 2.25.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk18on
1.80
fixed in 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5598MEDIUM6.38
org.bouncycastle:bcprov-jdk18on
1.80.2
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-23444MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 8.13.0, 7.17.23
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-43709MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.21, 8.13.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-52979MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.25, 8.16.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-21634MEDIUM6.38
software.amazon.ion:ion-java
1.0.2
fixed in 1.10.5
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-6176MEDIUM6.38
Brotli
1.0.9
fixed in 1.2.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-69534MEDIUM6.38
Markdown
3.6
fixed in 3.8.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-26130MEDIUM6.38
cryptography
42.0.2
fixed in 42.0.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-33953MEDIUM6.38
grpcio
1.48.1
fixed in 1.53.2, 1.54.3, 1.55.2, 1.56.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0994MEDIUM6.38
protobuf
4.21.8
fixed in 6.33.5, 5.29.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47287MEDIUM6.38
tornado
6.2
fixed in 6.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-31958MEDIUM6.38
tornado
6.2
fixed in 6.5.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-66418MEDIUM6.38
urllib3
2.1.0
fixed in 2.6.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-66471MEDIUM6.38
urllib3
2.1.0
fixed in 2.6.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-21441MEDIUM6.38
urllib3
2.1.0
fixed in 2.6.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-66418MEDIUM6.38
urllib3
2.2.1
fixed in 2.6.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-66471MEDIUM6.38
urllib3
2.2.1
fixed in 2.6.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-21441MEDIUM6.38
urllib3
2.2.1
fixed in 2.6.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-12383MEDIUM6.29
org.glassfish.jersey.core:jersey-client
3.1.9
fixed in 2.46, 3.0.17, 3.1.10
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-22573MEDIUM6.21
com.google.oauth-client:google-oauth-client
1.23.0
fixed in 1.33.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-22573MEDIUM6.21
com.google.oauth-client:google-oauth-client
1.30.5
fixed in 1.33.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-43869MEDIUM6.21
org.apache.thrift:libthrift
0.13.0
fixed in 0.23.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-34062MEDIUM6.21
tqdm
4.65.0
fixed in 4.66.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-13009MEDIUM6.12
org.eclipse.jetty:jetty-server
9.4.54.v20240208
fixed in 9.4.57.v20241219
0.4%
Theoretical Threat
Directly Exposed
CVE-2019-10241MEDIUM6.1
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.2.27.v20190403, 9.3.26.v20190403, 9.4.16.v20190411
9.6%
Low-Moderate Risk
Directly Exposed
CVE-2022-36033MEDIUM6.1
org.jsoup:jsoup
1.10.3
fixed in 1.15.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2022-36033MEDIUM6.1
org.jsoup:jsoup
1.11.3
fixed in 1.15.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2015-6748MEDIUM6.1
org.jsoup:jsoup
1.8.1
fixed in 1.8.3
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2022-36033MEDIUM6.1
org.jsoup:jsoup
1.8.1
fixed in 1.15.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2023-28370MEDIUM6.1
tornado
6.2
fixed in 6.3.2
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
18.0
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
19.0
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
20.0
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
24.1.1-jre
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
25.0-jre
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
31.1-android
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-4802MEDIUM5.95
libc-bin
2.31-0ubuntu9.17
fixed in 2.31-0ubuntu9.18
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-4802MEDIUM5.95
libc6
2.31-0ubuntu9.17
fixed in 2.31-0ubuntu9.18
0.4%
Theoretical Threat
Directly Exposed
CVE-2018-10237MEDIUM5.9
com.google.guava:guava
18.0
fixed in 24.1.1-android
5.1%
Low-Moderate Risk
Directly Exposed
CVE-2018-10237MEDIUM5.9
com.google.guava:guava
19.0
fixed in 24.1.1-android
5.1%
Low-Moderate Risk
Directly Exposed
CVE-2018-10237MEDIUM5.9
com.google.guava:guava
20.0
fixed in 24.1.1-android
5.1%
Low-Moderate Risk
Directly Exposed
CVE-2021-21409MEDIUM5.9
io.netty:netty
3.10.6.Final
fixed in 4.0.0
4.9%
Low-Moderate Risk
Directly Exposed
CVE-2019-7614MEDIUM5.9
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.2, 7.2.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-23944MEDIUM5.61
org.apache.zookeeper:zookeeper
3.6.3
fixed in 3.8.4, 3.9.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk18on
1.80.2
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-11143MEDIUM5.52
org.eclipse.jetty:jetty-http
11.0.24
fixed in 12.0.31, 12.1.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-11143MEDIUM5.52
org.eclipse.jetty:jetty-http
9.4.54.v20240208
fixed in 12.0.31, 12.1.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-49921MEDIUM5.52
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.16, 8.11.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-26007MEDIUM5.52
cryptography
42.0.2
fixed in 46.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-37891MEDIUM5.52
urllib3
2.1.0
fixed in 1.26.19, 2.2.2
1.0%
Theoretical Threat
Directly Exposed
CVE-2024-37891MEDIUM5.52
urllib3
2.2.1
fixed in 1.26.19, 2.2.2
1.0%
Theoretical Threat
Directly Exposed
CVE-2021-21290MEDIUM5.5
io.netty:netty
3.10.6.Final
fixed in 4.0.0
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2021-27807MEDIUM5.5
org.apache.pdfbox:pdfbox
2.0.16
fixed in 2.0.23
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-27906MEDIUM5.5
org.apache.pdfbox:pdfbox
2.0.16
fixed in 2.0.23
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2021-31811MEDIUM5.5
org.apache.pdfbox:pdfbox
2.0.16
fixed in 2.0.24
3.4%
Low-Moderate Risk
Directly Exposed
CVE-2021-31812MEDIUM5.5
org.apache.pdfbox:pdfbox
2.0.16
fixed in 2.0.24
3.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-56326MEDIUM5.35
Jinja2
3.1.4
fixed in 3.1.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2018-18893MEDIUM5.3
com.hubspot.jinjava:jinjava
2.4.0
fixed in 2.4.6
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2024-29025MEDIUM5.3
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.1.108.Final
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2020-13956MEDIUM5.3
org.apache.httpcomponents:httpclient
4.5
fixed in 4.5.13, 5.0.3
8.7%
Low-Moderate Risk
Directly Exposed
CVE-2019-10247MEDIUM5.3
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.2.28.v20190418, 9.3.27.v20190418, 9.4.17.v20190418
5.8%
Low-Moderate Risk
Directly Exposed
CVE-2023-26048MEDIUM5.3
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.4.51.v20230217, 10.0.14, 11.0.14
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-26049MEDIUM5.3
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.4.51.v20230217, 10.0.14, 11.0.14, 12.0.0.beta0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-4949MEDIUM5.3
org.eclipse.jgit:org.eclipse.jgit
4.5.4.201711221230-r
fixed in 7.2.1.202505142326-r, 7.1.1.202505221757-r, 7.0.1.202505221510-r, 6.10.1.202505221210-r, 6.0.0.202111291000-r, 5.13.4.202507202350-r
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2021-22135MEDIUM5.3
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.11.2, 6.8.15
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-22137MEDIUM5.3
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.11.2, 6.8.15
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2021-33430MEDIUM5.3
numpy
1.19.5
fixed in 1.21
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2021-34141MEDIUM5.3
numpy
1.19.5
fixed in 1.22
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-5569MEDIUM5.27
zipp
3.15.0
fixed in 3.19.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2018-3824MEDIUM5.18
org.elasticsearch:elasticsearch
2.4.3
fixed in 5.6.9, 6.2.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-23528MEDIUM5.18
distributed
2021.10.0
fixed in 2026.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-50181MEDIUM5.18
urllib3
2.1.0
fixed in 2.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-50181MEDIUM5.18
urllib3
2.2.1
fixed in 2.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-50182MEDIUM5.18
urllib3
2.2.1
fixed in 2.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34477MEDIUM5.02
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34477MEDIUM5.02
org.apache.logging.log4j:log4j-core
2.20.0
fixed in 2.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-28219MEDIUM5.02
Pillow
9.2.0
fixed in 10.3.0
1.0%
Theoretical Threat
Directly Exposed
CVE-2020-7021MEDIUM4.9
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.14, 7.10.0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-35195MEDIUM4.76
requests
2.31.0
fixed in 2.32.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-47535MEDIUM4.67
io.netty:netty-common
4.1.51.Final
fixed in 4.1.115.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-25193MEDIUM4.67
io.netty:netty-common
4.1.51.Final
fixed in 4.1.118.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-47535MEDIUM4.67
io.netty:netty-common
4.1.75.Final
fixed in 4.1.115.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-25193MEDIUM4.67
io.netty:netty-common
4.1.75.Final
fixed in 4.1.118.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-47535MEDIUM4.67
io.netty:netty-common
4.1.87.Final
fixed in 4.1.115.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-25193MEDIUM4.67
io.netty:netty-common
4.1.87.Final
fixed in 4.1.118.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-25710MEDIUM4.67
org.apache.commons:commons-compress
1.18
fixed in 1.26.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-25710MEDIUM4.67
org.apache.commons:commons-compress
1.21
fixed in 1.26.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-26308MEDIUM4.67
org.apache.commons:commons-compress
1.21
fixed in 1.26.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2023-42503MEDIUM4.67
org.apache.commons:commons-compress
1.23.0
fixed in 1.24.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-25710MEDIUM4.67
org.apache.commons:commons-compress
1.23.0
fixed in 1.26.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-26308MEDIUM4.67
org.apache.commons:commons-compress
1.23.0
fixed in 1.26.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2022-38750MEDIUM4.67
org.yaml:snakeyaml
1.15
fixed in 1.31
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42308MEDIUM4.67
Pillow
9.2.0
fixed in 12.2.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42310MEDIUM4.67
Pillow
9.2.0
fixed in 12.2.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-25645MEDIUM4.67
requests
2.31.0
fixed in 2.33.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-25645MEDIUM4.67
requests
2.32.2
fixed in 2.33.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-21883MEDIUM4.59
bokeh
2.4.3
fixed in 3.8.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2019-17571MEDIUM4.58
log4j:log4j
1.2.17
No fix yet
69.1%
Actively Exploited
Post-Exploit
CVE-2022-23305MEDIUM4.58
log4j:log4j
1.2.17
No fix yet
67.5%
Actively Exploited
Post-Exploit
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.87.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.87.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.87.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-6763MEDIUM4.5
org.eclipse.jetty:jetty-http
11.0.24
fixed in 12.0.12
1.0%
Theoretical Threat
Directly Exposed
CVE-2024-6763MEDIUM4.5
org.eclipse.jetty:jetty-http
8.2.0.v20160908
fixed in 12.0.12
1.0%
Theoretical Threat
Directly Exposed
CVE-2024-6763MEDIUM4.5
org.eclipse.jetty:jetty-http
9.4.54.v20240208
fixed in 12.0.12
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-34073MEDIUM4.5
cryptography
42.0.2
fixed in 46.0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45409MEDIUM4.5
idna
3.10
fixed in 3.15
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45409MEDIUM4.5
idna
3.4
fixed in 3.15
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-4565MEDIUM4.5
protobuf
4.21.8
fixed in 4.25.8, 5.29.5, 6.31.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-47081MEDIUM4.5
requests
2.31.0
fixed in 2.32.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-47081MEDIUM4.5
requests
2.32.2
fixed in 2.32.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-35536MEDIUM4.5
tornado
6.2
fixed in 6.5.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-44431MEDIUM4.5
urllib3
2.1.0
fixed in 2.7.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44431MEDIUM4.5
urllib3
2.2.1
fixed in 2.7.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2022-23307MEDIUM4.12
log4j:log4j
1.2.17
No fix yet
52.5%
Actively Exploited
Post-Exploit
CVE-2022-23302MEDIUM4.12
log4j:log4j
1.2.17
No fix yet
61.8%
Actively Exploited
Post-Exploit
CVE-2025-68161MEDIUM4.08
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-68161MEDIUM4.08
org.apache.logging.log4j:log4j-core
2.20.0
fixed in 2.25.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-52046MEDIUM4.06
org.apache.mina:mina-core
2.0.7
fixed in 2.2.4, 2.1.10, 2.0.27
23.9%
High Exploitation Risk
Post-Exploit
CVE-2019-20445LOW3.77
io.netty:netty
3.10.6.Final
fixed in 4.0.0
13.5%
High Exploitation Risk
Post-Exploit
CVE-2025-49128LOW3.4
com.fasterxml.jackson.core:jackson-core
2.9.8
fixed in 2.13.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-epoll
4.1.96.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-kqueue
4.1.96.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-6345LOW3.17
setuptools
59.8.0
fixed in 70.0.0
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2025-47273LOW3.17
setuptools
59.8.0
fixed in 78.1.1
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-6345LOW3.17
setuptools
68.2.2
fixed in 70.0.0
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2025-47273LOW3.17
setuptools
68.2.2
fixed in 78.1.1
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2021-34428LOW2.98
org.eclipse.jetty:jetty-server
8.2.0.v20160908
fixed in 9.4.41, 10.0.3, 11.0.3
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-6357LOW2.96
pip
23.3.1
fixed in 26.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-6357LOW2.96
pip
24.0
fixed in 26.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-24049LOW2.8
wheel
0.41.2
fixed in 0.46.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-24049LOW2.8
wheel
0.42.0
fixed in 0.46.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2020-8908LOW2.8
com.google.guava:guava
18.0
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2020-8908LOW2.8
com.google.guava:guava
19.0
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2020-8908LOW2.8
com.google.guava:guava
20.0
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2020-8908LOW2.8
com.google.guava:guava
24.1.1-jre
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2020-8908LOW2.8
com.google.guava:guava
25.0-jre
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2020-8908LOW2.8
com.google.guava:guava
31.1-android
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-4539LOW2.8
Pygments
2.17.2
fixed in 2.20.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8869LOW2.7
pip
23.3.1
fixed in 25.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-8869LOW2.7
pip
24.0
fixed in 25.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2020-7020LOW2.63
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.13, 7.9.2
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-3219LOW2.55
pip
23.3.1
fixed in 26.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3219LOW2.55
pip
24.0
fixed in 26.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2022-2047LOW2.29
org.eclipse.jetty:jetty-http
8.2.0.v20160908
fixed in 9.4.47, 10.0.10, 11.0.10
0.9%
Theoretical Threat
Directly Exposed
CVE-2022-40897LOW2.12
setuptools
59.8.0
fixed in 65.5.1
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-23901LOW2.12
org.apache.shiro:shiro-core
1.13.0
fixed in 2.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-1703LOW1.99
pip
23.3.1
fixed in 26.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-1703LOW1.99
pip
24.0
fixed in 26.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-48924NONE0
commons-lang:commons-lang
2.6
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.18.3
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.9.8
fixed in 2.21.1, 2.18.6
Not Applicable
CVE-2026-25526NONE0
com.hubspot.jinjava:jinjava
2.4.0
fixed in 2.8.3, 2.7.6
0.9%
Theoretical Threat
Not Applicable
CVE-2026-25526NONE0
com.hubspot.jinjava:jinjava
2.5.4
fixed in 2.8.3, 2.7.6
0.9%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.51.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.75.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.87.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
GHSA-xpw8-rcwv-8f8pNONE0
io.netty:netty-codec-http2
4.1.87.Final
fixed in 4.1.100.Final
Not Applicable
CVE-2026-45205NONE0
org.apache.commons:commons-configuration2
2.10.1
fixed in 2.15.0
0.5%
Theoretical Threat
Not Applicable
GHSA-gj48-438w-jh9vNONE0
bleach
6.1.0
fixed in 6.4.0
Not Applicable
GHSA-8rfp-98v4-mmr6NONE0
bleach
6.1.0
fixed in 6.4.0
Not Applicable
GHSA-537c-gmf6-5ccfNONE0
cryptography
42.0.2
fixed in 48.0.1
Not Applicable
GHSA-h4gh-qq45-vh27NONE0
cryptography
42.0.2
fixed in 43.0.1
Not Applicable
CVE-2026-33310NONE0
intake
0.7.0
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2025-30167NONE0
jupyter_core
4.11.1
fixed in 5.8.1
0.1%
Theoretical Threat
Not Applicable
CVE-2026-49853NONE0
tornado
6.2
fixed in 6.5.6
Not Applicable
CVE-2026-49855NONE0
tornado
6.2
fixed in 6.5.6
Not Applicable
GHSA-753j-mpmx-qq6gNONE0
tornado
6.2
fixed in 6.4.1
Not Applicable
GHSA-78cv-mqj4-43f7NONE0
tornado
6.2
fixed in 6.5.5
Not Applicable
GHSA-pw6j-qg29-8w7fNONE0
tornado
6.2
fixed in 6.5.7
Not Applicable
GHSA-qppv-j76h-2rpxNONE0
tornado
6.2
fixed in 6.3.3
Not Applicable
GHSA-w235-7p84-xx57NONE0
tornado
6.2
fixed in 6.4.1
Not Applicable
CVE-2026-49854NONE0
tornado
6.2
fixed in 6.5.6
Not Applicable