This image is safe for production use. It has one low-severity post-exploit vulnerability (severity 2.78) that requires local access and does not pose a risk to network-facing deployments. The image is officially maintained, widely used, and pinned by digest, ensuring a trusted and immutable artifact.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-7598 | LOW2.78 | libssh2 1.4.3-12.amzn2.2.6 fixed in 1.4.3-12.amzn2.2.7 | 0.4% Theoretical Threat | Post-Exploit |