Vulnerability Reportjetty:12.1.10-jdk17-al2023-amazoncorretto

jetty:12.1.10-jdk17-al2023-amazoncorrettojetty:12.1-jdk17-al2023-amazoncorrettojetty:12-jdk17-al2023-amazoncorretto
digestsha256:4a82afceaeeefdff63a0862de48e081ecf0d5edc42ed8f48e5bb1817f7a9893f

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The top findings (CVE-2026-42011, CVE-2026-34182) affect TLS libraries (gnutls, openssl) and could allow an attacker to bypass certificate validation or perform man-in-the-middle attacks. While the image is official and trusted, the high volume of vulnerabilities (55 exposed, 5 with severity >=6) increases the attack surface. No specific compensating controls are provided; updating the base image to include patched versions is recommended.

Vulnerabilities

Vulnerability Log

91 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42011MEDIUM6.29
gnutls
3.8.3-8.amzn2023.0.3
fixed in 3.8.10-4.amzn2023.0.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42012MEDIUM6.03
gnutls
3.8.3-8.amzn2023.0.3
fixed in 3.8.10-4.amzn2023.0.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-54369MEDIUM6.03
libacl
2.3.1-2.amzn2023.0.2
fixed in 2.4.0-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56132MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-9149MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9150MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-11972MEDIUM5.52
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.3.1-2.amzn2023.0.2
fixed in 2.4.0-1.amzn2023.0.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6019MEDIUM5.18
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9669MEDIUM5.02
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-23679MEDIUM4.67
libusbx
1.0.24-2.amzn2023.0.2
fixed in 1.0.24-2.amzn2023.0.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0864MEDIUM4.67
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-3276MEDIUM4.5
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-3446MEDIUM4.5
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-libs
1.21.3-7.amzn2023.0.1
fixed in 1.21.3-8.amzn2023.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
gnutls
3.8.3-8.amzn2023.0.3
fixed in 3.8.10-4.amzn2023.0.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6653LOW3
libxml2
2.10.4-1.amzn2023.0.18
fixed in 2.10.4-1.amzn2023.0.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-0864LOW2.8
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-8643LOW2.8
python3-pip-wheel
21.3.1-2.amzn2023.0.19
fixed in 21.3.1-2.amzn2023.0.20
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW2.8
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3479LOW2.8
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-58016LOW2.78
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-33845LOW2.78
gnutls
3.8.3-8.amzn2023.0.3
fixed in 3.8.3-8.amzn2023.0.4
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-48863LOW2.7
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
Post-Exploit
CVE-2026-3276LOW2.7
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3446LOW2.7
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-58014LOW2.63
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58010LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58012LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58013LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42013LOW2.51
gnutls
3.8.3-8.amzn2023.0.3
fixed in 3.8.10-4.amzn2023.0.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-26740LOW2.29
giflib
5.2.1-9.amzn2023.0.3
fixed in 5.2.1-9.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-58011LOW2.29
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58015LOW2.29
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW2.29
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW2.29
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9669LOW1.81
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57062LOW1.48
gnupg2
2.3.7-1.amzn2023.0.8
fixed in 2.3.7-1.amzn2023.0.9
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-57062LOW1.48
gnupg2-smime
2.3.7-1.amzn2023.0.8
fixed in 2.3.7-1.amzn2023.0.9
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-56407NONE0
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Not Applicable
CVE-2026-50593NONE0
graphite2
1.3.14-7.amzn2023.0.2
fixed in 1.3.14-7.amzn2023.0.3
0.1%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
libblkid
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libfdisk
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libmount
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libsmartcols
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libuuid
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-11940NONE0
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11940NONE0
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11822NONE0
sqlite-libs
3.40.0-1.amzn2023.0.7
fixed in 3.40.0-1.amzn2023.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-11824NONE0
sqlite-libs
3.40.0-1.amzn2023.0.7
fixed in 3.40.0-1.amzn2023.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
util-linux
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
util-linux-core
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.