Vulnerability Reporteclipse-temurin:21.0.12_8-jre

eclipse-temurin:21.0.12_8-jreeclipse-temurin:21-jre
digestsha256:a80c51f2d09a3e7e00d521f1c817bbceb6b3be94109b4a784d46078099882dda

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. It does carry findings — 30 on the exposed surface and 48 restricted to post-exploit scenarios — but their maximum severities are 5.87 and 3.16 respectively, and nothing reaches the 6.0 threshold that would require attention. In practice, the issues inherited by images built on top of this Java runtime are low-severity and would not realistically enable remote code execution, authentication bypass, or data exposure in a normal build. The image's strong trust posture (Docker Official, digest-pinned, very widely used) reinforces this verdict. Standard hygiene — rebuilding regularly to pick up upstream patches — is sufficient here. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

88 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-56132MEDIUM5.87
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56404MEDIUM5.87
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-72522MEDIUM5.27
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-13757MEDIUM5.27
libp11-kit0
0.26.2-2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-13757MEDIUM5.27
p11-kit-modules
0.26.2-2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-50219MEDIUM5.02
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-66382MEDIUM4.67
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-18374MEDIUM4.17
libc-bin
2.43-2ubuntu2.4
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-18374MEDIUM4.17
libc-gconv-modules-extra
2.43-2ubuntu2.4
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-18374MEDIUM4.17
libc6
2.43-2ubuntu2.4
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56131LOW3.82
libexpat1
2.7.4-1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-13757LOW3.16
p11-kit
0.26.2-2
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-41080LOW3.15
libexpat1
2.7.4-1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-15534LOW2.91
perl-base
5.40.1-7ubuntu0.1
fixed in 5.40.1-7ubuntu0.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-35373LOW2.8
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-40228LOW2.8
libsystemd0
259.5-0ubuntu3.4
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
259.5-0ubuntu3.4
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-13221LOW2.78
perl-base
5.40.1-7ubuntu0.1
fixed in 5.40.1-7ubuntu0.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-12087LOW2.7
perl-base
5.40.1-7ubuntu0.1
fixed in 5.40.1-7ubuntu0.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-57432LOW2.57
perl-base
5.40.1-7ubuntu0.1
fixed in 5.40.1-7ubuntu0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-76957LOW2.39
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45186LOW2.29
libexpat1
2.7.4-1
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-57433LOW2.29
perl-base
5.40.1-7ubuntu0.1
fixed in 5.40.1-7ubuntu0.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-18477LOW2.24
tar
1.35+dfsg-4ubuntu0.4
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-18508LOW2.24
tar
1.35+dfsg-4ubuntu0.4
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2021-31879LOW2.2
wget
1.25.0-2ubuntu4.4
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-19487LOW1.99
perl-base
5.40.1-7ubuntu0.1
fixed in 5.40.1-7ubuntu0.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
passwd
1:4.17.4-2ubuntu3
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-57062LOW1.48
gpgv
2.4.8-4ubuntu3
fixed in 2.4.8-4ubuntu3.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39821NONE0
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.7%
Theoretical Threat
Not Applicable
CVE-2026-56858NONE0
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-33818NONE0
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
stdlib
v1.26.5
fixed in 1.26.6, 1.27.0-rc.3
0.5%
Theoretical Threat
Not Applicable
CVE-2026-56853NONE0
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-56859NONE0
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-56860NONE0
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.5%
Theoretical Threat
Not Applicable
CVE-2026-56862NONE0
stdlib
v1.26.5
fixed in 1.25.13, 1.26.6, 1.27.0-rc.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-18374NONE0
locales
2.43-2ubuntu2.4
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2024-56433NONE0
login.defs
1:4.17.4-2ubuntu3
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-13608NONE0
curl
8.18.0-1ubuntu2.5
No fix yet
0.5%
Theoretical Threat
Not Applicable
CVE-2026-18924NONE0
curl
8.18.0-1ubuntu2.5
No fix yet
0.6%
Theoretical Threat
Not Applicable
CVE-2026-19931NONE0
curl
8.18.0-1ubuntu2.5
No fix yet
0.8%
Theoretical Threat
Not Applicable
CVE-2026-80229NONE0
curl
8.18.0-1ubuntu2.5
No fix yet
0.6%
Theoretical Threat
Not Applicable
CVE-2026-80230NONE0
curl
8.18.0-1ubuntu2.5
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-80255NONE0
curl
8.18.0-1ubuntu2.5
No fix yet
0.5%
Theoretical Threat
Not Applicable
CVE-2026-82209NONE0
curl
8.18.0-1ubuntu2.5
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-13608NONE0
libcurl4t64
8.18.0-1ubuntu2.5
No fix yet
0.5%
Theoretical Threat
Not Applicable
CVE-2026-18924NONE0
libcurl4t64
8.18.0-1ubuntu2.5
No fix yet
0.6%
Theoretical Threat
Not Applicable
CVE-2026-19931NONE0
libcurl4t64
8.18.0-1ubuntu2.5
No fix yet
0.8%
Theoretical Threat
Not Applicable
CVE-2026-80229NONE0
libcurl4t64
8.18.0-1ubuntu2.5
No fix yet
0.6%
Theoretical Threat
Not Applicable
CVE-2026-80230NONE0
libcurl4t64
8.18.0-1ubuntu2.5
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-80255NONE0
libcurl4t64
8.18.0-1ubuntu2.5
No fix yet
0.5%
Theoretical Threat
Not Applicable
CVE-2026-82209NONE0
libcurl4t64
8.18.0-1ubuntu2.5
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56408NONE0
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat1
2.7.4-1
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-66046NONE0
libexpat1
2.7.4-1
No fix yet
0.6%
Theoretical Threat
Not Applicable
CVE-2026-76641NONE0
libexpat1
2.7.4-1
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39113NONE0
libsqlite3-0
3.46.1-9ubuntu0.2
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-35341NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-35344NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35345NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35348NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35350NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35351NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35352NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35354NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35357NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35359NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35360NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35363NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-35364NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35367NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35368NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35370NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35371NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-35374NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-35377NONE0
rust-coreutils
0.8.0-0ubuntu3
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-85091NONE0
zlib1g
1:1.3.dfsg+really1.3.1-1ubuntu3.1
No fix yet
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.