Vulnerability Reporteclipse-temurin:17-jre

eclipse-temurin:17-jre
DIGESTsha256:8016378253033ebd971c237f6580f108b4afac11a188d3fc3b982497bbe55c65

Executive Summary

DANGEROUS

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could spoof legitimate services or intercept sensitive information by bypassing certificate validation due to critical flaws like CVE-2026-42013 and CVE-2026-42011. These GnuTLS vulnerabilities, many with high context importance, directly impact the container's likely TLS validation activities. While an authentication bypass (CVE-2026-42010) requires specific RSA-PSK server configuration, other severe issues do not. Immediate remediation is mandatory before any production deployment.

Threat Score
100/100
DANGEROUS
Reputation
TRUSTED
Docker Official
BaseImage/
eclipse-temurin:17-jre
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

93 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42013HIGH8.2
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Directly ExposedContext importance: HIGH
CVE-2026-42010HIGH7.84
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Directly ExposedContext importance: MEDIUM
CVE-2026-42011HIGH7.4
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Directly ExposedContext importance: HIGH
CVE-2026-42012HIGH7.1
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Directly ExposedContext importance: HIGH
CVE-2026-3833MEDIUM6.29
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-7598MEDIUM6.18
libssh2-1t64
1.11.1-1build2
fixed in 1.11.1-1ubuntu0.26.04.1
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4437MEDIUM5.52
libc-bin
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-4437MEDIUM5.52
libc-gconv-modules-extra
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-6238MEDIUM5.52
libc-gconv-modules-extra
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libc6
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-6238MEDIUM5.52
libc6
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM5.3
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Directly Exposed
CVE-2026-41989MEDIUM5.1
libgcrypt20
1.12.0-2
fixed in 1.12.0-2ubuntu0.1
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5435MEDIUM5.02
libc-bin
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc-gconv-modules-extra
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-2236MEDIUM5.02
libgcrypt20
1.12.0-2
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-5260MEDIUM4.92
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Directly Exposed
CVE-2025-66382MEDIUM4.67
libexpat1
2.7.4-1
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33845MEDIUM4.64
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42009MEDIUM4.5
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Directly Exposed
CVE-2026-3184MEDIUM4.5
libblkid1
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-bin
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-gconv-modules-extra
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libmount1
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libsmartcols1
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184MEDIUM4.5
libuuid1
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33846LOW3.83
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.7
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Directly Exposed
CVE-2026-4438LOW3.4
libc-bin
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc-gconv-modules-extra
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6238LOW3.31
libc-bin
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5958LOW3.21
sed
4.9-2build3
fixed in 4.9-2ubuntu1
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3832LOW3.15
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-45582LOW2.86
tar
1.35+dfsg-4
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-35373LOW2.8
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.8
tar
1.35+dfsg-4
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-41990LOW2.8
libgcrypt20
1.12.0-2
fixed in 1.12.0-2ubuntu0.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libsystemd0
259.5-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
259.5-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3184LOW2.7
bsdutils
1:2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
login
1:4.16.0-2+really2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
mount
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3184LOW2.7
util-linux
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
login
1:4.16.0-2+really2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.41.3-3ubuntu2
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW2.16
passwd
1:4.17.4-2ubuntu3
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2021-31879LOW1.87
wget
1.25.0-2ubuntu4
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33811NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
Not Applicable
CVE-2026-33814NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
Not Applicable
CVE-2026-39820NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
Not Applicable
CVE-2026-39836NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
Not Applicable
CVE-2026-4437NONE0
locales
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-6238NONE0
locales
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-5435NONE0
locales
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-39826NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
Not Applicable
CVE-2026-4046NONE0
locales
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-4438NONE0
locales
2.43-2ubuntu2
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2024-56433NONE0
login.defs
1:4.17.4-2ubuntu3
No fix yet
4.5%
Low-Moderate Risk
Not Applicable
CVE-2026-42014NONE0
libgnutls30t64
3.8.12-2ubuntu1
fixed in 3.8.12-2ubuntu1.1
Not Applicable
CVE-2026-35341NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35344NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35345NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35348NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35350NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35351NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35352NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35354NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35357NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35359NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35360NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35363NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35364NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35367NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35368NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35370NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35371NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35374NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35377NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
Not Applicable