Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker with access to the Kafka Connect REST API could exploit CVE-2025-27817 to read arbitrary files and environment variables, and CVE-2026-2332 enables HTTP request smuggling through the Jetty management interface; additional high-severity Netty flaws allow denial of service. Restricting REST API access to trusted users fully mitigates the Kafka client SSRF, but upgrading Kafka clients, Jetty, and Netty is essential to reduce the overall attack surface. The image has no post-exploitation findings above severity 3.53, but the exposed attack surface is substantial with 109 known vulnerabilities. Note that CVE-2025-27817 requires the ability to set connector configuration via the REST API, so internal-only deployments are at lower risk.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-27817 | CRITICAL10 | org.apache.kafka:kafka-clients 3.3.1 fixed in 3.9.1 | 64.7% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2026-2332 | CRITICAL9.1 | org.eclipse.jetty:jetty-http 9.4.48.v20220622 fixed in 12.1.7, 12.0.33 | 1.1% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2025-55163 | HIGH7.5 | io.grpc:grpc-netty-shaded 1.46.0 fixed in 1.75.0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-55163 | HIGH7.5 | io.netty:netty-codec-http2 4.1.78.Final fixed in 4.2.4.Final, 4.1.124.Final | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33871 | HIGH7.5 | io.netty:netty-codec-http2 4.1.78.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-27819 | HIGH7.48 | org.apache.kafka:kafka_2.13 3.3.1 fixed in 3.4.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-67030 | HIGH7.48 | org.codehaus.plexus:plexus-utils 3.3.0 fixed in 4.0.3, 3.6.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2023-22102 | HIGH7.06 | mysql:mysql-connector-java 8.0.29 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2024-47561 | HIGH7.04 | org.apache.avro:avro 1.11.0 fixed in 1.11.4 | 3.3% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.13.3 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.13.3 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-59250 | MEDIUM6.88 | com.microsoft.sqlserver:mssql-jdbc 10.2.1 fixed in 10.2.4.jre11, 11.2.4.jre11, 12.2.1.jre11, 12.6.5.jre11, 12.8.2.jre11, 12.10.2.jre11, 13.2.1.jre11 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-59250 | MEDIUM6.88 | com.microsoft.sqlserver:mssql-jdbc 10.2.1.jre8 fixed in 10.2.4.jre11, 11.2.4.jre11, 12.2.1.jre11, 12.6.5.jre11, 12.8.2.jre11, 12.10.2.jre11, 13.2.1.jre11 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-27818 | MEDIUM6.8 | org.apache.kafka:kafka_2.13 3.3.1 fixed in 3.9.1 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2023-34462 | MEDIUM6.5 | io.netty:netty-handler 4.1.78.Final fixed in 4.1.94.Final | 2.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29857 | MEDIUM6.5 | org.bouncycastle:bcprov-jdk15on 1.67 fixed in 1.78 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-8184 | MEDIUM6.5 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 12.0.9, 10.0.24, 11.0.24, 9.4.56 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-52999 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-core 2.13.3 fixed in 2.15.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-50193 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-databind 2.13.3 fixed in 2.14.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2022-3509 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.21.6 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-3510 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.21.6 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec 4.1.78.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59901 | MEDIUM6.38 | io.netty:netty-codec 4.1.78.Final fixed in 4.1.136.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.78.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-55831 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55833 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56745 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56746 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59899 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.78.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.78.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42578 | MEDIUM6.38 | io.netty:netty-handler-proxy 4.1.78.Final fixed in 4.1.133.Final, 4.2.13.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2023-31582 | MEDIUM6.38 | org.bitbucket.b_c:jose4j 0.7.9 fixed in 0.9.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-29371 | MEDIUM6.38 | org.bitbucket.b_c:jose4j 0.7.9 fixed in 0.9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-51775 | MEDIUM6.38 | org.bitbucket.b_c:jose4j 0.7.9 fixed in 0.9.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk15on 1.67 fixed in 1.84 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-9823 | MEDIUM6.38 | org.eclipse.jetty:jetty-servlets 9.4.48.v20220622 fixed in 9.4.54, 10.0.18, 11.0.18 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-66566 | MEDIUM6.38 | org.lz4:lz4-java 1.8.0 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42198 | MEDIUM6.38 | org.postgresql:postgresql 42.5.0 fixed in 42.7.11 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-56128 | MEDIUM6.29 | org.apache.kafka:kafka_2.13 3.3.1 fixed in 3.7.2, 3.8.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-13009 | MEDIUM6.12 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 9.4.57.v20241219 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 30.1.1-jre fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 31.1-jre fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-35554 | MEDIUM5.78 | org.apache.kafka:kafka-clients 3.3.1 fixed in 3.9.2, 4.0.2, 4.1.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-23944 | MEDIUM5.61 | org.apache.zookeeper:zookeeper 3.6.3 fixed in 3.8.4, 3.9.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59900 | MEDIUM5.52 | io.netty:netty-codec-http2 4.1.78.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-11143 | MEDIUM5.52 | org.eclipse.jetty:jetty-http 9.4.48.v20220622 fixed in 12.0.31, 12.1.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-5236 | MEDIUM5.52 | org.infinispan.protostream:protostream 4.5.0.Final fixed in 4.6.2.Final | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | org.lz4:lz4-java 1.8.0 fixed in 1.8.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-29025 | MEDIUM5.3 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.1.108.Final | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-31141 | MEDIUM5.3 | org.apache.kafka:kafka-clients 3.3.1 fixed in 3.7.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-40167 | MEDIUM5.3 | org.eclipse.jetty:jetty-http 9.4.48.v20220622 fixed in 9.4.52, 10.0.16, 11.0.16, 12.0.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26048 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 9.4.51.v20230217, 10.0.14, 11.0.14 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26049 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 9.4.51.v20230217, 10.0.14, 11.0.14, 12.0.0.beta0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-1419 | MEDIUM5.02 | io.debezium:debezium-connector-mysql 2.1.0.Final fixed in 2.3.0.Alpha1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-1419 | MEDIUM5.02 | io.debezium:debezium-connector-sqlserver 2.1.0.Final fixed in 2.3.0.Alpha1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-1419 | MEDIUM5.02 | io.debezium:debezium-core 2.1.0.Final fixed in 2.3.0.Alpha1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-41909 | MEDIUM5.02 | org.apache.sshd:sshd-common 2.7.0 fixed in 2.12.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-30171 | MEDIUM5.02 | org.bouncycastle:bcprov-jdk15on 1.67 fixed in 1.78 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-59921 | MEDIUM4.84 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-47535 | MEDIUM4.67 | io.netty:netty-common 4.1.78.Final fixed in 4.1.115.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-25193 | MEDIUM4.67 | io.netty:netty-common 4.1.78.Final fixed in 4.1.118.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-25710 | MEDIUM4.67 | org.apache.commons:commons-compress 1.21 fixed in 1.26.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-26308 | MEDIUM4.67 | org.apache.commons:commons-compress 1.21 fixed in 1.26.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2023-33202 | MEDIUM4.67 | org.bouncycastle:bcprov-jdk15on 1.67 fixed in 1.70 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-41946 | MEDIUM4.67 | org.postgresql:postgresql 42.5.0 fixed in 42.2.27, 42.3.8, 42.4.3, 42.5.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2022-42003 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.13.3 fixed in 2.12.7.1, 2.13.4.2 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42004 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.13.3 fixed in 2.12.7.1, 2.13.4 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.13.3 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.13.3 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59898 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk15on 1.67 fixed in 1.79 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-33201 | MEDIUM4.5 | org.bouncycastle:bcprov-jdk15on 1.67 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-34447 | MEDIUM4.5 | org.bouncycastle:bcprov-jdk15on 1.67 fixed in 1.78 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-6763 | MEDIUM4.5 | org.eclipse.jetty:jetty-http 9.4.48.v20220622 fixed in 12.0.12 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2023-35887 | MEDIUM4.3 | org.apache.sshd:sshd-common 2.7.0 fixed in 2.9.3 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.12.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.8.1 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2022-45047 | LOW3.53 | org.apache.sshd:sshd-common 2.7.0 fixed in 2.9.2 | 3.6% Low-Moderate Risk | Post-Exploit |
| CVE-2024-1597 | LOW3.53 | org.postgresql:postgresql 42.5.0 fixed in 42.2.28, 42.3.9, 42.4.4, 42.5.5, 42.6.1, 42.7.2 | 4.8% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.1.82.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-44981 | LOW3.28 | org.apache.zookeeper:zookeeper 3.6.3 fixed in 3.7.2, 3.8.3, 3.9.1 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2022-25647 | LOW3.1 | com.google.code.gson:gson 2.8.6 fixed in 2.8.9 | 12.2% High Exploitation Risk | Post-Exploit |
| CVE-2023-36479 | LOW3.1 | org.eclipse.jetty:jetty-servlets 9.4.48.v20220622 fixed in 9.4.52, 10.0.16, 11.0.16 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42581 | LOW3 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 30.1.1-jre fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 31.1-jre fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42584 | LOW2.78 | io.netty:netty-codec-http 4.1.78.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2024-7254 | LOW2.7 | com.google.protobuf:protobuf-java 3.19.6 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Post-Exploit |
| CVE-2024-7254 | LOW2.7 | com.google.protobuf:protobuf-java 3.21.6 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Post-Exploit |
| CVE-2022-3171 | LOW2.7 | com.google.protobuf:protobuf-java 3.21.6 fixed in 3.21.7, 3.20.3, 3.19.6, 3.16.3 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2023-39410 | LOW2.7 | org.apache.avro:avro 1.11.0 fixed in 1.11.3 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2022-45688 | LOW2.7 | org.json:json 20220320 fixed in 20230227 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-5072 | LOW2.7 | org.json:json 20220320 fixed in 20231013 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2023-34455 | LOW2.7 | org.xerial.snappy:snappy-java 1.1.8.4 fixed in 1.1.10.1 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2023-43642 | LOW2.7 | org.xerial.snappy:snappy-java 1.1.8.4 fixed in 1.1.10.4 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-34453 | LOW2.7 | org.xerial.snappy:snappy-java 1.1.8.4 fixed in 1.1.10.1 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-34454 | LOW2.7 | org.xerial.snappy:snappy-java 1.1.8.4 fixed in 1.1.10.1 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-5384 | LOW2.29 | org.infinispan:infinispan-client-hotrod 14.0.2.Final fixed in 15.0.0.Dev07, 14.0.25.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-5384 | LOW2.29 | org.infinispan:infinispan-commons 14.0.2.Final fixed in 15.0.0.Dev07, 14.0.25.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-5384 | LOW2.29 | org.infinispan:infinispan-core 14.0.2.Final fixed in 15.0.0.Dev07, 14.0.25.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2022-36944 | NONE0 | org.scala-lang:scala-library 2.13.8 fixed in 2.13.9 | 8.8% Low-Moderate Risk | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.13.3 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.13.3 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-xpw8-rcwv-8f8p | NONE0 | io.netty:netty-codec-http2 4.1.78.Final fixed in 4.1.100.Final | — | Not Applicable |
| CVE-2026-33558 | NONE0 | org.apache.kafka:kafka-clients 3.3.1 fixed in 3.9.2, 4.0.1 | 0.6% Theoretical Threat | Not Applicable |
| GHSA-jgvc-jfgh-rjvv | NONE0 | org.bitbucket.b_c:jose4j 0.7.9 fixed in 0.9.3 | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty:jetty-security 9.4.48.v20220622 fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-6790 | NONE0 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-56740 | NONE0 | org.jline:jline-remote-telnet 3.21.0 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-56741 | NONE0 | org.jline:jline-remote-telnet 3.21.0 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-59949 | NONE0 | org.lz4:lz4-java 1.8.0 No fix yet | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.