Last scanned:
This base/runtime image is a clean foundation for building production images. It does carry findings — 30 on the exposed surface and 48 restricted to post-exploit scenarios — but their maximum severities are 5.87 and 3.16 respectively, and nothing reaches the 6.0 threshold that would require attention. In practice, the issues inherited by images built on top of this Java runtime are low-severity and would not realistically enable remote code execution, authentication bypass, or data exposure in a normal build. The image's strong trust posture (Docker Official, digest-pinned, very widely used) reinforces this verdict. Standard hygiene — rebuilding regularly to pick up upstream patches — is sufficient here. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-56132 | MEDIUM5.87 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56404 | MEDIUM5.87 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56407 | MEDIUM5.87 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-72522 | MEDIUM5.27 | libexpat1 2.7.4-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.26.2-2 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | p11-kit-modules 0.26.2-2 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | libexpat1 2.7.4-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | libexpat1 2.7.4-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-66382 | MEDIUM4.67 | libexpat1 2.7.4-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32776 | MEDIUM4.67 | libexpat1 2.7.4-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32777 | MEDIUM4.67 | libexpat1 2.7.4-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32778 | MEDIUM4.67 | libexpat1 2.7.4-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc-bin 2.43-2ubuntu2.4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc-gconv-modules-extra 2.43-2ubuntu2.4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-18374 | MEDIUM4.17 | libc6 2.43-2ubuntu2.4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56131 | LOW3.82 | libexpat1 2.7.4-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | LOW3.16 | p11-kit 0.26.2-2 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41080 | LOW3.15 | libexpat1 2.7.4-1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-15534 | LOW2.91 | perl-base 5.40.1-7ubuntu0.1 fixed in 5.40.1-7ubuntu0.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-35373 | LOW2.8 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-40228 | LOW2.8 | libsystemd0 259.5-0ubuntu3.4 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 259.5-0ubuntu3.4 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13221 | LOW2.78 | perl-base 5.40.1-7ubuntu0.1 fixed in 5.40.1-7ubuntu0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-12087 | LOW2.7 | perl-base 5.40.1-7ubuntu0.1 fixed in 5.40.1-7ubuntu0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-57432 | LOW2.57 | perl-base 5.40.1-7ubuntu0.1 fixed in 5.40.1-7ubuntu0.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-76957 | LOW2.39 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-45186 | LOW2.29 | libexpat1 2.7.4-1 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-57433 | LOW2.29 | perl-base 5.40.1-7ubuntu0.1 fixed in 5.40.1-7ubuntu0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-18477 | LOW2.24 | tar 1.35+dfsg-4ubuntu0.4 No fix yet | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-18508 | LOW2.24 | tar 1.35+dfsg-4ubuntu0.4 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2021-31879 | LOW2.2 | wget 1.25.0-2ubuntu4.4 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-19487 | LOW1.99 | perl-base 5.40.1-7ubuntu0.1 fixed in 5.40.1-7ubuntu0.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.17.4-2ubuntu3 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-57062 | LOW1.48 | gpgv 2.4.8-4ubuntu3 fixed in 2.4.8-4ubuntu3.1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-39821 | NONE0 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-56858 | NONE0 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-33818 | NONE0 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-46600 | NONE0 | stdlib v1.26.5 fixed in 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-56853 | NONE0 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-56859 | NONE0 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-56860 | NONE0 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-56862 | NONE0 | stdlib v1.26.5 fixed in 1.25.13, 1.26.6, 1.27.0-rc.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-18374 | NONE0 | locales 2.43-2ubuntu2.4 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2024-56433 | NONE0 | login.defs 1:4.17.4-2ubuntu3 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-13608 | NONE0 | curl 8.18.0-1ubuntu2.5 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-18924 | NONE0 | curl 8.18.0-1ubuntu2.5 No fix yet | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-19931 | NONE0 | curl 8.18.0-1ubuntu2.5 No fix yet | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-80229 | NONE0 | curl 8.18.0-1ubuntu2.5 No fix yet | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-80230 | NONE0 | curl 8.18.0-1ubuntu2.5 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-80255 | NONE0 | curl 8.18.0-1ubuntu2.5 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-82209 | NONE0 | curl 8.18.0-1ubuntu2.5 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-13608 | NONE0 | libcurl4t64 8.18.0-1ubuntu2.5 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-18924 | NONE0 | libcurl4t64 8.18.0-1ubuntu2.5 No fix yet | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-19931 | NONE0 | libcurl4t64 8.18.0-1ubuntu2.5 No fix yet | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-80229 | NONE0 | libcurl4t64 8.18.0-1ubuntu2.5 No fix yet | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-80230 | NONE0 | libcurl4t64 8.18.0-1ubuntu2.5 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-80255 | NONE0 | libcurl4t64 8.18.0-1ubuntu2.5 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-82209 | NONE0 | libcurl4t64 8.18.0-1ubuntu2.5 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-56408 | NONE0 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat1 2.7.4-1 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-66046 | NONE0 | libexpat1 2.7.4-1 No fix yet | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-76641 | NONE0 | libexpat1 2.7.4-1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39113 | NONE0 | libsqlite3-0 3.46.1-9ubuntu0.2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-35341 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-35344 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35345 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35348 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35350 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35351 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35352 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35354 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35357 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35359 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35360 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35363 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-35364 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35367 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35368 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35370 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35371 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35374 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-35377 | NONE0 | rust-coreutils 0.8.0-0ubuntu3 No fix yet | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-85091 | NONE0 | zlib1g 1:1.3.dfsg+really1.3.1-1ubuntu3.1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.