Vulnerability Reportconfluentinc/cp-kafka-connect:8.0.6

confluentinc/cp-kafka-connect:8.0.6confluentinc/cp-kafka-connect:8.0.6-1-ubi9
DIGESTsha256:9b2d86633085963d84f6a5391a7e0a836354eb830471fed6927fccf86ec65430

Executive Summary

Threat Score
30/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. Most notably, CVE-2026-45674 in Netty's DNS resolver could allow DNS cache poisoning if an attacker controls a DNS server, while CVE-2026-45416 enables denial of service via TLS handshake without special configuration. CVE-2025-27113 in libxml2 may cause crashes if XML data is processed. Upgrading Netty packages to 4.1.135.Final or later and libxml2 to patched version fully resolves these issues. Note that the TLS handshake DoS is exploitable by any remote client, making it the most pressing concern, while DNS cache poisoning requires attacker-controlled infrastructure.

Vulnerabilities

Vulnerability Log

296 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45674MEDIUM6.8
io.netty:netty-resolver-dns
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-47691MEDIUM6.8
io.netty:netty-resolver-dns
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2025-27113MEDIUM6
libxml2
2.9.13-14.el9_7
No fix yet
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-44604MEDIUM5.95
rpm-libs
4.16.1.3-40.el9
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-44604MEDIUM5.95
rpm-plugin-systemd-inhibit
4.16.1.3-40.el9
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-44604MEDIUM5.95
rpm-sign-libs
4.16.1.3-40.el9
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.16.0-9.el9
No fix yet
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-41996MEDIUM5.9
openssl-libs
1:3.5.5-3.el9_8
No fix yet
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.5.0-6.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22185MEDIUM5.78
openldap
2.6.8-4.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45673MEDIUM5.78
io.netty:netty-resolver-dns
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4105MEDIUM5.7
systemd-libs
252-67.el9_8.2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4105MEDIUM5.7
systemd-pam
252-67.el9_8.2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-5915MEDIUM5.61
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-5918MEDIUM5.61
libarchive
3.5.3-9.el9_7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-common
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4426MEDIUM5.52
libarchive
3.5.3-9.el9_7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9149MEDIUM5.52
libsolv
0.7.24-5.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9150MEDIUM5.52
libsolv
0.7.24-5.el9_8
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-45322MEDIUM5.52
libxml2
2.9.13-14.el9_7
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-fips-provider
3.0.7-8.el9
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-fips-provider-so
3.0.7-8.el9
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-libs
1:3.5.5-3.el9_8
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM5.5
io.netty:netty-handler
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2024-34459MEDIUM5.5
libxml2
2.9.13-14.el9_7
No fix yet
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-1757MEDIUM5.27
libxml2
2.9.13-14.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-64506MEDIUM5.18
libpng
2:1.6.37-15.el9_8
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6732MEDIUM5.1
libxml2
2.9.13-14.el9_7
No fix yet
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-48043MEDIUM5.1
io.netty:netty-codec-http2
4.1.133.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-50010MEDIUM5.1
io.netty:netty-handler
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-50219MEDIUM5.02
expat
2.5.0-6.el9_8.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc
2.34-270.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.34-270.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.34-270.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-0990MEDIUM5.02
libxml2
2.9.13-14.el9_7
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-fips-provider
3.0.7-8.el9
fixed in 3.0.7-11.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-fips-provider-so
3.0.7-8.el9
fixed in 3.0.7-11.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-5916MEDIUM4.76
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
expat
2.5.0-6.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
expat
2.5.0-6.el9_8.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
expat
2.5.0-6.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-66382MEDIUM4.67
expat
2.5.0-6.el9_8.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-60753MEDIUM4.67
libarchive
3.5.3-9.el9_7
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5745MEDIUM4.67
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-1632MEDIUM4.67
libarchive
3.5.3-9.el9_7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libgcc
11.5.0-14.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc
11.5.0-14.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libgomp
11.5.0-14.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgomp
11.5.0-14.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libstdc++
11.5.0-14.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libstdc++
11.5.0-14.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-0232MEDIUM4.67
sqlite-libs
3.34.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.11-40.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-1489MEDIUM4.59
glib2
2.68.4-19.el9_8.1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-30571MEDIUM4.5
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
xz-libs
5.2.5-8.el9_0
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42250MEDIUM4.25
bzip2-libs
1.0.8-11.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.34-270.el9_8
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.34-270.el9_8
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.34-270.el9_8
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-libs
1.21.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-pkinit
1.21.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-5917MEDIUM4.25
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
libkadm5
1.21.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-28164MEDIUM4.25
libpng
2:1.6.37-15.el9_8
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM4.17
expat
2.5.0-6.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libfdisk
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
1:3.5.5-3.el9_8
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-9681LOW3.9
curl-minimal
7.76.1-40.el9
No fix yet
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-9681LOW3.9
libcurl-minimal
7.76.1-40.el9
No fix yet
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-5773LOW3.82
curl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
libcurl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW3.82
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW3.82
openssl
1:3.5.5-3.el9_8
No fix yet
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW3.82
openssl
1:3.5.5-3.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW3.82
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW3.82
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW3.82
python3
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python3
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW3.82
python3
3.9.25-7.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW3.82
python3-libs
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python3-libs
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW3.82
python3-libs
3.9.25-7.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-44432LOW3.82
urllib3
2.6.3
fixed in 2.7.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW3.77
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-64505LOW3.74
libpng
2:1.6.37-15.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34757LOW3.74
libpng
2:1.6.37-15.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-29040LOW3.74
tpm2-tss
3.2.3-1.el9
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-31879LOW3.66
wget
1.21.1-8.el9_4
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2023-4156LOW3.62
gawk
5.1.0-6.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2005-2541LOW3.6
tar
2:1.34-11.el9
No fix yet
4.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-44604LOW3.57
python3-rpm
4.16.1.3-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-44604LOW3.57
rpm
4.16.1.3-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1484LOW3.57
glib2
2.68.4-19.el9_8.1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-11053LOW3.54
curl-minimal
7.76.1-40.el9
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-11053LOW3.54
libcurl-minimal
7.76.1-40.el9
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-41996LOW3.54
openssl
1:3.5.5-3.el9_8
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-13034LOW3.47
curl-minimal
7.76.1-40.el9
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-13034LOW3.47
libcurl-minimal
7.76.1-40.el9
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2021-3572LOW3.42
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-epoll
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-kqueue
4.1.133.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3784LOW3.31
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl-minimal
7.76.1-40.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl-minimal
7.76.1-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
libcurl-minimal
7.76.1-40.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
libcurl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl-minimal
7.76.1-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW3.31
openssl
1:3.5.5-3.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-33056LOW3.31
tar
2:1.34-11.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
curl-minimal
7.76.1-40.el9
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
libcurl-minimal
7.76.1-40.el9
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34181LOW3.21
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5958LOW3.21
sed
4.8-10.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-41080LOW3.15
expat
2.5.0-6.el9_8.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-3360LOW3.15
glib2
2.68.4-19.el9_8.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-7039LOW3.15
glib2
2.68.4-19.el9_8.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0988LOW3.15
glib2
2.68.4-19.el9_8.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0989LOW3.15
libxml2
2.9.13-14.el9_7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6019LOW3.11
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-50181LOW3.11
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-50182LOW3.11
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW3.1
openssl-libs
1:3.5.5-3.el9_8
No fix yet
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-5713LOW3.06
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5713LOW3.06
python3
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5713LOW3.06
python3-libs
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42764LOW3.01
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-32284LOW3.01
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
openssl
1:3.5.5-3.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
openssl-libs
1:3.5.5-3.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6357LOW2.96
pip
26.0.1
fixed in 26.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-3783LOW2.91
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3783LOW2.91
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-24883LOW2.8
gnupg2
2.3.3-5.el9_7
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-13837LOW2.8
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42308LOW2.8
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-13837LOW2.8
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42308LOW2.8
python3
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-13837LOW2.8
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42308LOW2.8
python3-libs
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-25645LOW2.8
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.8
tar
2:1.34-11.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25645LOW2.8
requests
2.32.5
fixed in 2.33.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-41990LOW2.8
libgcrypt
1.10.0-11.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-70873LOW2.8
sqlite-libs
3.34.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45445LOW2.78
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl-minimal
7.76.1-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
libcurl-minimal
7.76.1-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
libcurl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-12781LOW2.7
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3276LOW2.7
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-12781LOW2.7
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3276LOW2.7
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-12781LOW2.7
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3276LOW2.7
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-44431LOW2.7
urllib3
2.6.3
fixed in 2.7.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2024-7264LOW2.69
curl-minimal
7.76.1-40.el9
No fix yet
16.2%
High Exploitation Risk
Post-Exploit
CVE-2024-7264LOW2.69
libcurl-minimal
7.76.1-40.el9
No fix yet
16.2%
High Exploitation Risk
Post-Exploit
CVE-2025-4516LOW2.6
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-4516LOW2.6
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-4516LOW2.6
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-11850LOW2.55
krb5-workstation
1.21.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW2.55
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3219LOW2.55
pip
26.0.1
fixed in 26.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
curl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
libcurl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl
1:3.5.5-3.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl-libs
1:3.5.5-3.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-0992LOW2.46
libxml2
2.9.13-14.el9_7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-14017LOW2.45
curl-minimal
7.76.1-40.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl-minimal
7.76.1-40.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python3
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python3-libs
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
curl-minimal
7.76.1-40.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg2
2.3.3-5.el9_7
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-30258LOW2.4
gnupg2
2.3.3-5.el9_7
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
libcurl-minimal
7.76.1-40.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-13176LOW2.4
openssl
1:3.5.5-3.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-64118LOW2.4
tar
2:1.34-11.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux-core
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.24-5.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1485LOW2.38
glib2
2.68.4-19.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-10524LOW2.34
wget
1.21.1-8.el9_4
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2023-32636LOW2.29
glib2
2.68.4-19.el9_8.1
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-41989LOW2.29
libgcrypt
1.10.0-11.el9
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.29
openssl-libs
1:3.5.5-3.el9_8
No fix yet
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
openssl-libs
1:3.5.5-3.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2022-41409LOW2.29
pcre2
10.40-6.el9
No fix yet
1.0%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1502LOW2.29
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1502LOW2.29
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1502LOW2.29
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl-libs
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.32-40.el9
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2023-45803LOW2.14
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-24515LOW2.12
expat
2.5.0-6.el9_8.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-6170LOW2.12
libxml2
2.9.13-14.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW1.89
openssl
1:3.5.5-3.el9_8
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW1.86
openssl
1:3.5.5-3.el9_8
No fix yet
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-3219LOW1.68
gnupg2
2.3.3-5.el9_7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2023-39804LOW1.68
tar
2:1.34-11.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-11961LOW1.61
libpcap
14:1.10.0-4.el9
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-1795LOW1.58
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-1795LOW1.58
python3
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-1795LOW1.58
python3-libs
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2022-41409NONE0
pcre2-syntax
10.40-6.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2026-44604NONE0
rpm-build-libs
4.16.1.3-40.el9
No fix yet
0.5%
Theoretical Threat
Not Applicable
CVE-2026-4105NONE0
systemd
252-67.el9_8.2
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-4105NONE0
systemd-rpm-macros
252-67.el9_8.2
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
ncurses-base
6.2-12.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.2-12.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2025-1371NONE0
elfutils-default-yama-scope
0.194-1.el9
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2025-1377NONE0
elfutils-default-yama-scope
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2025-1371NONE0
elfutils-libelf
0.194-1.el9
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2025-1377NONE0
elfutils-libelf
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2025-1371NONE0
elfutils-libs
0.194-1.el9
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2025-1377NONE0
elfutils-libs
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
freetype
2.10.4-10.el9_5
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22693NONE0
harfbuzz
2.7.4-10.el9
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-54411NONE0
pam
1.5.1-28.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2025-1376NONE0
elfutils-default-yama-scope
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2025-1376NONE0
elfutils-libelf
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2025-1376NONE0
elfutils-libs
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-25068NONE0
alsa-lib
1.2.15.3-1.el9
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2024-25260NONE0
elfutils-default-yama-scope
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2024-25260NONE0
elfutils-libelf
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2024-25260NONE0
elfutils-libs
0.194-1.el9
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22020NONE0
libpng
2:1.6.37-15.el9_8
No fix yet
Not Applicable
CVE-2026-33117NONE0
com.azure:azure-security-keyvault-keys
4.9.2
fixed in 4.10.6
0.5%
Theoretical Threat
Not Applicable
GHSA-2r2c-cx56-8933NONE0
org.jline:jline-remote-telnet
3.25.1
fixed in 4.2.1
Not Applicable
GHSA-47qp-hqvx-6r3fNONE0
org.jline:jline-remote-telnet
3.25.1
fixed in 4.2.1
Not Applicable
GHSA-537c-gmf6-5ccfNONE0
cryptography
46.0.7
fixed in 48.0.1
Not Applicable
GHSA-qp9x-wp8f-qgjjNONE0
tuf
6.0.0
fixed in 7.0.0
Not Applicable