Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. Exploitation of the Jackson or OpenSSL flaws could allow an attacker to execute arbitrary code inside the Kafka Connect container, potentially exfiltrating sensitive data or pivoting to connected systems. CVE-2026-54512/54513 require polymorphic typing to be enabled, and CVE-2026-28387 requires DANE TLSA usage; verifying these configurations can reduce actual exposure.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-28387 | MEDIUM6.88 | openssl-libs 1:3.5.5-3.el9_8 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45674 | MEDIUM6.8 | io.netty:netty-resolver-dns 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-47691 | MEDIUM6.8 | io.netty:netty-resolver-dns 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-11979 | MEDIUM6.63 | libxml2 2.9.13-14.el9_7 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-59900 | MEDIUM6.5 | io.netty:netty-codec-http2 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Directly Exposed |
| CVE-2026-33636 | MEDIUM6.46 | libpng 2:1.6.37-15.el9_8 fixed in 2:1.6.37-15.el9_8.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-58011 | MEDIUM6.38 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-58015 | MEDIUM6.38 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-32636 | MEDIUM6.38 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-41989 | MEDIUM6.38 | libgcrypt 1.10.0-11.el9 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6732 | MEDIUM6.38 | libxml2 2.9.13-14.el9_7 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-55831 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55833 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56745 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-56746 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.133.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-10051 | MEDIUM6.38 | org.eclipse.jetty:jetty-server 12.0.34 fixed in 12.0.36, 12.1.10 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-10051 | MEDIUM6.38 | org.eclipse.jetty:jetty-server 12.0.35 fixed in 12.0.36, 12.1.10 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-16118 | MEDIUM6.03 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54369 | MEDIUM6.03 | libacl 2.3.1-4.el9 fixed in 2.4.0-1.el9_8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-59899 | MEDIUM6 | io.netty:netty-codec-http 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Directly ExposedContext importance: MEDIUM |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1 4.16.0-9.el9 fixed in 4.16.0-10.el9_8 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | openssl-fips-provider 3.0.7-8.el9 fixed in 3.0.7-11.el9_8 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | openssl-fips-provider-so 3.0.7-8.el9 fixed in 3.0.7-11.el9_8 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-41996 | MEDIUM5.9 | openssl-libs 1:3.5.5-3.el9_8 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-56132 | MEDIUM5.87 | expat 2.5.0-6.el9_8.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | expat 2.5.0-6.el9_8.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | expat 2.5.0-6.el9_8.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | expat 2.5.0-6.el9_8.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45673 | MEDIUM5.78 | io.netty:netty-resolver-dns 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4105 | MEDIUM5.7 | systemd-libs 252-67.el9_8.2 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-59921 | MEDIUM5.7 | io.netty:netty-codec-http 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | glibc 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | glibc-common 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | glibc-minimal-langpack 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-45322 | MEDIUM5.52 | libxml2 2.9.13-14.el9_7 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | openssl-fips-provider 3.0.7-8.el9 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | openssl-fips-provider-so 3.0.7-8.el9 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | openssl-libs 1:3.5.5-3.el9_8 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54518 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-34459 | MEDIUM5.5 | libxml2 2.9.13-14.el9_7 fixed in 2.9.13-14.el9_8.1 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54370 | MEDIUM5.35 | libacl 2.3.1-4.el9 fixed in 2.4.0-1.el9_8 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54371 | MEDIUM5.35 | libattr 2.5.1-3.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-59898 | MEDIUM5.3 | io.netty:netty-codec-http 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Directly Exposed |
| CVE-2026-1757 | MEDIUM5.27 | libxml2 2.9.13-14.el9_7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | p11-kit 0.26.2-1.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | p11-kit-trust 0.26.2-1.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-64506 | MEDIUM5.18 | libpng 2:1.6.37-15.el9_8 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | expat 2.5.0-6.el9_8.1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | expat 2.5.0-6.el9_8.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | glibc 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | glibc-common 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | glibc-minimal-langpack 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-0990 | MEDIUM5.02 | libxml2 2.9.13-14.el9_7 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | MEDIUM5 | openssl-libs 1:3.5.5-3.el9_8 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-32776 | MEDIUM4.67 | expat 2.5.0-6.el9_8.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32777 | MEDIUM4.67 | expat 2.5.0-6.el9_8.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32778 | MEDIUM4.67 | expat 2.5.0-6.el9_8.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-66382 | MEDIUM4.67 | expat 2.5.0-6.el9_8.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2021-46195 | MEDIUM4.67 | libgcc 11.5.0-14.el9 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libgcc 11.5.0-14.el9 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2021-46195 | MEDIUM4.67 | libstdc++ 11.5.0-14.el9 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libstdc++ 11.5.0-14.el9 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-0232 | MEDIUM4.67 | sqlite-libs 3.34.1-10.el9_8 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.2.11-40.el9 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-1489 | MEDIUM4.59 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-28388 | MEDIUM4.5 | openssl-libs 1:3.5.5-3.el9_8 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-59901 | MEDIUM4.5 | io.netty:netty-codec 4.1.133.Final fixed in 4.1.136.Final | — | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | freetype 2.10.4-10.el9_5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-15588 | MEDIUM4.5 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22693 | MEDIUM4.5 | harfbuzz 2.7.4-10.el9 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libblkid 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libmount 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libuuid 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | xz-libs 5.2.5-8.el9_0 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54516 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4, 3.1.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54517 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.4, 3.1.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42250 | MEDIUM4.25 | bzip2-libs 1.0.8-11.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | glibc 2.34-270.el9_8 fixed in 2.34-272.el9_8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | glibc 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | glibc-common 2.34-270.el9_8 fixed in 2.34-272.el9_8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | glibc-common 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | glibc-minimal-langpack 2.34-270.el9_8 fixed in 2.34-272.el9_8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | glibc-minimal-langpack 2.34-270.el9_8 fixed in 2.34-274.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-28164 | MEDIUM4.25 | libpng 2:1.6.37-15.el9_8 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libblkid 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid 2.37.4-25.el9 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | openssl-libs 1:3.5.5-3.el9_8 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-64505 | LOW3.74 | libpng 2:1.6.37-15.el9_8 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34757 | LOW3.74 | libpng 2:1.6.37-15.el9_8 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-1484 | LOW3.57 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-kqueue 4.1.133.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-11972 | LOW3.31 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5958 | LOW3.21 | sed 4.8-10.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41080 | LOW3.15 | expat 2.5.0-6.el9_8.1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-3360 | LOW3.15 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-7039 | LOW3.15 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0988 | LOW3.15 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0989 | LOW3.15 | libxml2 2.9.13-14.el9_7 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56391 | LOW3.11 | coreutils 8.32-40.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-56391 | LOW3.11 | coreutils-common 8.32-40.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-6019 | LOW3.11 | python3 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-6019 | LOW3.11 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-50181 | LOW3.11 | python3-pip-wheel 21.3.1-2.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-50182 | LOW3.11 | python3-pip-wheel 21.3.1-2.el9_8 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW3.1 | openssl-libs 1:3.5.5-3.el9_8 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-5713 | LOW3.06 | python3 3.9.25-7.el9_8 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-5713 | LOW3.06 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-32284 | LOW3.01 | python3-pip-wheel 21.3.1-2.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6653 | LOW3 | libxml2 2.9.13-14.el9_7 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-13837 | LOW2.8 | python3 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42308 | LOW2.8 | python3 3.9.25-7.el9_8 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-13837 | LOW2.8 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42308 | LOW2.8 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-25645 | LOW2.8 | python3-pip-wheel 21.3.1-2.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-41990 | LOW2.8 | libgcrypt 1.10.0-11.el9 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-70873 | LOW2.8 | sqlite-libs 3.34.1-10.el9_8 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-58016 | LOW2.78 | glib2 2.68.4-19.el9_8.1 fixed in 2.68.4-19.el9_8.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-33416 | LOW2.7 | libpng 2:1.6.37-15.el9_8 fixed in 2:1.6.37-15.el9_8.2 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-27113 | LOW2.7 | libxml2 2.9.13-14.el9_7 No fix yet | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | openssl-libs 1:3.5.5-3.el9_8 fixed in 1:3.5.5-4.el9_8 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | openssl-libs 1:3.5.5-3.el9_8 No fix yet | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2022-41409 | LOW2.7 | pcre2 10.40-6.el9 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2022-41409 | LOW2.7 | pcre2-syntax 10.40-6.el9 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-12781 | LOW2.7 | python3 3.9.25-7.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-3276 | LOW2.7 | python3 3.9.25-7.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-12781 | LOW2.7 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-3276 | LOW2.7 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-45409 | LOW2.7 | python3-pip-wheel 21.3.1-2.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-58014 | LOW2.63 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-4516 | LOW2.6 | python3 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-4516 | LOW2.6 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-58010 | LOW2.51 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-58012 | LOW2.51 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-58013 | LOW2.51 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-0992 | LOW2.46 | libxml2 2.9.13-14.el9_7 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-15282 | LOW2.45 | python3 3.9.25-7.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-0672 | LOW2.45 | python3 3.9.25-7.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-15282 | LOW2.45 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-0672 | LOW2.45 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-1485 | LOW2.38 | glib2 2.68.4-19.el9_8.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-15308 | LOW2.29 | python3 3.9.25-7.el9_8 fixed in 3.9.25-7.el9_8.2 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-3644 | LOW2.29 | python3 3.9.25-7.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4224 | LOW2.29 | python3 3.9.25-7.el9_8 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-7210 | LOW2.29 | python3 3.9.25-7.el9_8 No fix yet | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-15308 | LOW2.29 | python3-libs 3.9.25-7.el9_8 fixed in 3.9.25-7.el9_8.2 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-3644 | LOW2.29 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4224 | LOW2.29 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-7210 | LOW2.29 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-11468 | LOW2.29 | python3 3.9.25-7.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-1502 | LOW2.29 | python3 3.9.25-7.el9_8 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-11468 | LOW2.29 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-1502 | LOW2.29 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-5278 | LOW2.24 | coreutils 8.32-40.el9 fixed in 8.32-41.el9_8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-56392 | LOW2.24 | coreutils 8.32-40.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-56392 | LOW2.24 | coreutils-common 8.32-40.el9 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2023-45803 | LOW2.14 | python3-pip-wheel 21.3.1-2.el9_8 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-24515 | LOW2.12 | expat 2.5.0-6.el9_8.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-6170 | LOW2.12 | libxml2 2.9.13-14.el9_7 fixed in 2.9.13-14.el9_8.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2021-3572 | LOW2.05 | python3-pip-wheel 21.3.1-2.el9_8 No fix yet | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11972 | LOW1.99 | python3 3.9.25-7.el9_8 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-13462 | LOW1.68 | python3 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-2297 | LOW1.68 | python3 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-3479 | LOW1.68 | python3 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-13462 | LOW1.68 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-2297 | LOW1.68 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-3479 | LOW1.68 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-1795 | LOW1.58 | python3 3.9.25-7.el9_8 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-1795 | LOW1.58 | python3-libs 3.9.25-7.el9_8 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | NONE0 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-base 6.2-12.20210508.el9 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-libs 6.2-12.20210508.el9 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-42505 | NONE0 | stdlib v1.26.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-25068 | NONE0 | alsa-lib 1.2.15.3-1.el9 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-22020 | NONE0 | libpng 2:1.6.37-15.el9_8 No fix yet | — | Not Applicable |
| CVE-2026-59949 | NONE0 | at.yawk.lz4:lz4-java 1.10.2 fixed in 1.11.1 | — | Not Applicable |
| CVE-2026-33117 | NONE0 | com.azure:azure-security-keyvault-keys 4.9.2 fixed in 4.10.6 | 0.5% Theoretical Threat | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.21.2 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| CVE-2026-59889 | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.21.5, 2.18.9, 2.22.1 | 0.3% Theoretical Threat | Not Applicable |
| GHSA-mhm7-754m-9p8w | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.21.2 fixed in 2.18.9, 2.21.5 | — | Not Applicable |
| GHSA-mfg7-5gfp-c4w3 | NONE0 | io.netty:netty-codec-dns 4.1.133.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty:jetty-security 12.0.34 fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty:jetty-security 12.0.35 fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-6790 | NONE0 | org.eclipse.jetty:jetty-server 12.0.34 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-8384 | NONE0 | org.eclipse.jetty:jetty-util 12.0.34 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-56740 | NONE0 | org.jline:jline-remote-telnet 3.30.4 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-56741 | NONE0 | org.jline:jline-remote-telnet 3.30.4 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.