Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker with access to the Kafka Connect REST API could read sensitive files and environment variables, bypass access controls via HTTP request smuggling, and potentially execute arbitrary code through crafted Avro schemas. Upgrading to Apache Kafka 4.0.0 and explicitly configuring allowed OAuthBearer URLs would eliminate CVE-2025-27817; note that CVE-2024-47561 only applies if the Avro converter is enabled.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-27817 | CRITICAL10 | org.apache.kafka:kafka-clients 3.8.0 fixed in 3.9.1 | 64.7% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2026-2332 | CRITICAL9.1 | org.eclipse.jetty:jetty-http 9.4.54.v20240208 fixed in 12.1.7, 12.0.33 | 1.1% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2024-47561 | HIGH7.04 | org.apache.avro:avro 1.11.3 fixed in 1.11.4 | 3.3% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.16.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-27830 | MEDIUM6.8 | com.mchange:c3p0 0.9.5.5 fixed in 0.12.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-27818 | MEDIUM6.8 | org.apache.kafka:kafka_2.13 3.8.0 fixed in 3.9.1 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2024-8184 | MEDIUM6.5 | org.eclipse.jetty:jetty-server 9.4.54.v20240208 fixed in 12.0.9, 10.0.24, 11.0.24, 9.4.56 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-55223 | MEDIUM6.38 | com.mchange:c3p0 0.9.5.5 fixed in 0.14.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec 4.1.110.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59901 | MEDIUM6.38 | io.netty:netty-codec 4.1.110.Final fixed in 4.1.136.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.110.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-55831 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55833 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56745 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56746 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59899 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.110.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.110.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.110.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.110.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42578 | MEDIUM6.38 | io.netty:netty-handler-proxy 4.1.110.Final fixed in 4.1.133.Final, 4.2.13.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2024-29371 | MEDIUM6.38 | org.bitbucket.b_c:jose4j 0.9.4 fixed in 0.9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-66566 | MEDIUM6.38 | org.lz4:lz4-java 1.8.0 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42198 | MEDIUM6.38 | org.postgresql:postgresql 42.6.1 fixed in 42.7.11 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-56128 | MEDIUM6.29 | org.apache.kafka:kafka_2.13 3.8.0 fixed in 3.7.2, 3.8.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-24281 | MEDIUM6.29 | org.apache.zookeeper:zookeeper 3.8.4 fixed in 3.8.6, 3.9.5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-13009 | MEDIUM6.12 | org.eclipse.jetty:jetty-server 9.4.54.v20240208 fixed in 9.4.57.v20241219 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 30.1.1-jre fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 31.1-jre fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-7254 | MEDIUM6 | com.google.protobuf:protobuf-java 3.21.7 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-7254 | MEDIUM6 | com.google.protobuf:protobuf-java 3.23.4 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-7254 | MEDIUM6 | com.google.protobuf:protobuf-java 3.25.2 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-45292 | MEDIUM6 | io.opentelemetry:opentelemetry-api 1.23.1 fixed in 1.62.0 | 1.1% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-45673 | MEDIUM5.78 | io.netty:netty-resolver-dns 4.1.109.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-35554 | MEDIUM5.78 | org.apache.kafka:kafka-clients 3.8.0 fixed in 3.9.2, 4.0.2, 4.1.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.16.2 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59900 | MEDIUM5.52 | io.netty:netty-codec-http2 4.1.110.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-11143 | MEDIUM5.52 | org.eclipse.jetty:jetty-http 9.4.54.v20240208 fixed in 12.0.31, 12.1.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | org.lz4:lz4-java 1.8.0 fixed in 1.8.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-45674 | MEDIUM5.1 | io.netty:netty-resolver-dns 4.1.109.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-47691 | MEDIUM5.1 | io.netty:netty-resolver-dns 4.1.109.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-59921 | MEDIUM4.84 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-47535 | MEDIUM4.67 | io.netty:netty-common 4.1.110.Final fixed in 4.1.115.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-25193 | MEDIUM4.67 | io.netty:netty-common 4.1.110.Final fixed in 4.1.118.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42579 | MEDIUM4.64 | io.netty:netty-codec-dns 4.1.109.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42584 | MEDIUM4.64 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-24970 | MEDIUM4.5 | io.netty:netty-handler 4.1.110.Final fixed in 4.1.118.Final | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.16.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.16.2 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59898 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.110.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.110.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-6763 | MEDIUM4.5 | org.eclipse.jetty:jetty-http 9.4.54.v20240208 fixed in 12.0.12 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.11.0 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.12.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.14.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.1.109.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.1.110.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-48734 | LOW3.17 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-27727 | LOW3 | com.mchange:mchange-commons-java 0.2.19 fixed in 0.4.0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-42581 | LOW3 | io.netty:netty-codec-http 4.1.110.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 30.1.1-jre fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 31.1-jre fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-55163 | LOW2.7 | io.grpc:grpc-netty-shaded 1.49.0 fixed in 1.75.0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-55163 | LOW2.7 | io.netty:netty-codec-http2 4.1.110.Final fixed in 4.2.4.Final, 4.1.124.Final | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-33871 | LOW2.7 | io.netty:netty-codec-http2 4.1.110.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-24308 | LOW2.7 | org.apache.zookeeper:zookeeper 3.8.4 fixed in 3.9.5, 3.8.6 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-67030 | LOW2.69 | org.codehaus.plexus:plexus-utils 3.5.1 fixed in 4.0.3, 3.6.1 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-54512 | LOW2.48 | com.fasterxml.jackson.core:jackson-databind 2.16.2 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-44249 | LOW2.48 | io.netty:netty-handler 4.1.110.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Post-Exploit |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.16.2 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.16.2 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-mfg7-5gfp-c4w3 | NONE0 | io.netty:netty-codec-dns 4.1.109.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Not Applicable |
| CVE-2026-33558 | NONE0 | org.apache.kafka:kafka-clients 3.8.0 fixed in 3.9.2, 4.0.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty:jetty-security 9.4.54.v20240208 fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-6790 | NONE0 | org.eclipse.jetty:jetty-server 9.4.54.v20240208 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-56740 | NONE0 | org.jline:jline-remote-telnet 3.25.1 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-56741 | NONE0 | org.jline:jline-remote-telnet 3.25.1 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-59949 | NONE0 | org.lz4:lz4-java 1.8.0 No fix yet | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.