Vulnerability Reporteclipse-temurin:17-jre

eclipse-temurin:17-jre
digestsha256:e4f018a55645ad204892e44eb35437518d7e108ba2a2dce305024ab371d24876

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. While the image has 11 exposed and 33 post-exploit findings, all are low severity (max 5.27 and 2.8 respectively), so they pose little practical risk to images built on top. The image is officially published and pinned by digest, ensuring supply chain integrity. No high-impact findings were reported in the top findings lists. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

47 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-13757MEDIUM5.27
libp11-kit0
0.26.2-2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-13757MEDIUM5.27
p11-kit
0.26.2-2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-13757MEDIUM5.27
p11-kit-modules
0.26.2-2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-66382MEDIUM4.67
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg+really1.3.1-1ubuntu3
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.41.3-3ubuntu2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.41.3-3ubuntu2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.41.3-3ubuntu2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.41.3-3ubuntu2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-35373LOW2.8
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-40228LOW2.8
libsystemd0
259.5-0ubuntu3
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
259.5-0ubuntu3
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3184LOW2.7
bsdutils
1:2.41.3-3ubuntu2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
mount
2.41.3-3ubuntu2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux
2.41.3-3ubuntu2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.41.3-3ubuntu2
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.41.3-3ubuntu2
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.41.3-3ubuntu2
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2021-31879LOW2.2
wget
1.25.0-2ubuntu4.3
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-2236LOW2.12
libgcrypt20
1.12.0-2ubuntu1
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW1.84
passwd
1:4.17.4-2ubuntu3
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW1.62
libblkid1
2.41.3-3ubuntu2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW1.62
libmount1
2.41.3-3ubuntu2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW1.62
libsmartcols1
2.41.3-3ubuntu2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW1.62
libuuid1
2.41.3-3ubuntu2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3184NONE0
login
1:4.16.0-2+really2.41.3-3ubuntu2
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27456NONE0
login
1:4.16.0-2+really2.41.3-3ubuntu2
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2024-56433NONE0
login.defs
1:4.17.4-2ubuntu3
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-35341NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-35344NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35345NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35348NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35350NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35351NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35352NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35354NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35357NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35359NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35360NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35363NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-35364NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35367NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35368NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35370NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35371NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35374NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35377NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.