Vulnerability Reporthyness/spring-cloud-config-server:5.0-jdk21

hyness/spring-cloud-config-server:jdk21hyness/spring-cloud-config-server:5.0.4-090f68d-jdk21hyness/spring-cloud-config-server:5.0-jdk21
digestsha256:554accdd6ab66853a4b47fa96fe961d38f838e99820922f236612c5b5bdfa578

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. It contains 17 low-severity exposed vulnerabilities (max CVSS 5.5) and 6 low-severity post-exploit issues (max 2.48), which pose minimal risk in typical deployment scenarios. The image is from a trusted community publisher and is pinned by digest, ensuring immutability.

Vulnerabilities

Vulnerability Log

23 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-54512MEDIUM5.5
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.18.8, 3.1.4, 2.21.4
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-54513MEDIUM5.5
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-22747MEDIUM5.5
org.springframework.security:spring-security-web
7.0.4
fixed in 7.0.5
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-22754MEDIUM5.1
org.springframework.security:spring-security-config
7.0.4
fixed in 7.0.5
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-27171MEDIUM4.67
zlib1g
1:1.3.dfsg-3.1ubuntu2.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54518MEDIUM4.42
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.21.4
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-0636MEDIUM4.42
org.bouncycastle:bcprov-jdk18on
1.81.1
fixed in 1.84
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-22753MEDIUM4.42
org.springframework.security:spring-security-config
7.0.4
fixed in 7.0.5
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-54514LOW3.6
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-54515LOW3.6
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-54516LOW3.6
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.21.4, 3.1.4
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-54517LOW3.6
com.fasterxml.jackson.core:jackson-databind
2.21.2
fixed in 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4438LOW3.4
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-kqueue
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22751LOW3.26
org.springframework.security:spring-security-core
7.0.4
fixed in 6.5.10, 7.0.5
0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-22746LOW3.15
org.springframework.security:spring-security-core
7.0.4
fixed in 6.5.10, 7.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-59250LOW2.48
com.microsoft.sqlserver:mssql-jdbc
13.2.1
fixed in 10.2.4.jre11, 11.2.4.jre11, 12.2.1.jre11, 12.6.5.jre11, 12.8.2.jre11, 12.10.2.jre11, 13.2.1.jre11
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42198LOW2.29
org.postgresql:postgresql
42.7.10
fixed in 42.7.11
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-4437LOW1.99
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4046LOW1.62
libc6
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Post-Exploit
GO-2026-5932NONE0
golang.org/x/crypto
v0.54.0
No fix yet
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.