Vulnerability Reportkibana:8.19.15

kibana:8.19.15
DIGESTsha256:659c9e7cf3ce70ab53ac8274fa57b8199d2bd336867229bb674e5e634dc96a7c

Executive Summary

Threat Score
75/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could achieve remote code execution via CVE-2026-4800 if the application passes untrusted input to lodash template functions. Disabling any usage of lodash _.template with untrusted input would fully eliminate this vulnerability. Note that CVE-2026-4800 requires the application to pass untrusted input as key names in options.imports. Additionally, multiple axios vulnerabilities (e.g., CVE-2026-44486) can leak proxy credentials during redirects, which may be relevant if Kibana uses an authenticated proxy.

Vulnerabilities

Vulnerability Log

185 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-4800HIGH7.84
lodash
4.17.23
fixed in 4.18.0
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-42010MEDIUM6.66
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33636MEDIUM6.46
libpng16-16t64
1.6.43-5ubuntu0.5
fixed in 1.6.43-5ubuntu0.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-41989MEDIUM6.38
libgcrypt20
1.10.3-2build1
fixed in 1.10.3-2ubuntu0.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2-14
1.59.0-1ubuntu0.2
fixed in 1.59.0-1ubuntu0.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-44486MEDIUM6.38
axios
1.15.0
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44487MEDIUM6.38
axios
1.15.0
fixed in 1.16.0, 0.32.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44488MEDIUM6.38
axios
1.15.0
fixed in 1.16.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44496MEDIUM6.38
axios
1.15.0
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42038MEDIUM6.38
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42039MEDIUM6.38
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45149MEDIUM6.38
brace-expansion
5.0.5
fixed in 5.0.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6321MEDIUM6.38
fast-uri
3.0.3
fixed in 3.1.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6322MEDIUM6.38
fast-uri
3.0.3
fixed in 3.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45740MEDIUM6.38
protobufjs
7.5.5
fixed in 7.5.8, 8.2.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-12151MEDIUM6.38
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41907MEDIUM6.38
uuid
10.0.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41907MEDIUM6.38
uuid
11.1.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41907MEDIUM6.38
uuid
13.0.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41907MEDIUM6.38
uuid
8.3.2
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41907MEDIUM6.38
uuid
9.0.1
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45736MEDIUM6.38
ws
8.20.0
fixed in 8.20.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42033MEDIUM6.29
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42035MEDIUM6.29
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42012MEDIUM6.03
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33416MEDIUM6
libpng16-16t64
1.6.43-5ubuntu0.5
fixed in 1.6.43-5ubuntu0.6
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-4878MEDIUM5.95
libcap2
1:2.66-5ubuntu2.2
fixed in 1:2.66-5ubuntu2.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-44495MEDIUM5.95
axios
1.15.0
fixed in 1.15.2, 0.31.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-2236MEDIUM5.9
libgcrypt20
1.10.3-2build1
No fix yet
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-41238MEDIUM5.78
dompurify
3.3.2
fixed in 3.4.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41239MEDIUM5.78
dompurify
3.3.2
fixed in 3.4.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42014MEDIUM5.61
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42013MEDIUM5.58
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5260MEDIUM5.58
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4437MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-8769MEDIUM5.52
@ai-sdk/provider-utils
3.0.17
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42041MEDIUM5.52
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33532MEDIUM5.52
yaml
1.10.2
fixed in 2.8.3, 1.10.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33532MEDIUM5.52
yaml
2.3.4
fixed in 2.8.3, 1.10.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libsystemd0
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libudev1
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42042MEDIUM5.18
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41240MEDIUM5.18
dompurify
3.3.2
fixed in 3.4.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44665MEDIUM5.18
fast-xml-builder
1.1.4
fixed in 1.1.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42338MEDIUM5.18
ip-address
9.0.5
fixed in 10.1.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41324MEDIUM5.02
basic-ftp
5.2.1
fixed in 5.3.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9679MEDIUM5.02
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-66382MEDIUM4.67
libexpat1
2.6.1-2ubuntu0.4
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41650MEDIUM4.59
fast-xml-parser
5.5.7
fixed in 5.7.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-53382MEDIUM4.59
prismjs
1.27.0
fixed in 1.30.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-bin
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.6.1+really5.4.5-1ubuntu0.2
fixed in 5.6.1+really5.4.5-1ubuntu0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44288MEDIUM4.5
@protobufjs/utf8
1.1.0
fixed in 1.1.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42034MEDIUM4.5
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42036MEDIUM4.5
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42037MEDIUM4.5
axios
1.15.0
fixed in 1.15.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-2739MEDIUM4.5
bn.js
4.11.9
fixed in 4.12.3, 5.2.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-2950MEDIUM4.5
lodash
4.17.23
fixed in 4.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44288MEDIUM4.5
protobufjs
7.5.5
fixed in 7.5.6, 8.0.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34757LOW3.74
libpng16-16t64
1.6.43-5ubuntu0.5
fixed in 1.6.43-5ubuntu0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3449LOW3.4
@tootallnate/once
2.0.0
fixed in 3.0.1, 2.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6429LOW3.31
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-5958LOW3.21
sed
4.9-2build1
fixed in 4.9-2ubuntu0.24.04.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3832LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-11525LOW3.15
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6733LOW3.15
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42043LOW3.06
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-45582LOW2.86
tar
1.35+dfsg-3build1
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-26280LOW2.81
systeminformation
5.30.3
fixed in 5.30.8
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-40228LOW2.8
libsystemd0
255.4-1ubuntu8.15
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
255.4-1ubuntu8.15
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33845LOW2.78
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42264LOW2.78
axios
1.15.0
fixed in 1.15.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42044LOW2.78
axios
1.15.0
fixed in 1.15.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-33846LOW2.7
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-42009LOW2.7
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-44293LOW2.69
protobufjs
7.5.5
fixed in 7.5.6, 8.0.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-26318LOW2.69
systeminformation
5.30.3
fixed in 5.31.0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-44494LOW2.66
axios
1.15.0
fixed in 1.16.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-44492LOW2.63
axios
1.15.0
fixed in 1.16.0, 0.32.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW2.55
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-44490LOW2.51
axios
1.15.0
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-44724LOW2.39
systeminformation
5.30.3
fixed in 5.31.6
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW2.29
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW2.29
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW1.99
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW1.99
curl
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW1.99
libcurl4t64
8.5.0-2ubuntu10.8
fixed in 8.5.0-2ubuntu10.9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
passwd
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-56433NONE0
login
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-2219NONE0
dpkg
1.22.6ubuntu6.5
fixed in 1.22.6ubuntu6.6
0.4%
Theoretical Threat
Not Applicable
CVE-2026-48068NONE0
@grpc/grpc-js
1.14.3
fixed in 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4
Not Applicable
CVE-2026-48069NONE0
@grpc/grpc-js
1.14.3
fixed in 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4
Not Applicable
CVE-2026-44974NONE0
@hapi/content
6.0.1
fixed in 6.0.2
Not Applicable
CVE-2026-48049NONE0
@hapi/inert
7.1.0
fixed in 7.1.1
Not Applicable
CVE-2026-44979NONE0
@hapi/wreck
18.1.0
fixed in 18.1.1
Not Applicable
CVE-2026-48022NONE0
@hapi/wreck
18.1.0
fixed in 18.1.2
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
1.26.0
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
1.30.1
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
2.6.0
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-44902NONE0
@opentelemetry/exporter-prometheus
0.213.0
fixed in 0.217.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-44902NONE0
@opentelemetry/sdk-node
0.213.0
fixed in 0.217.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42040NONE0
axios
1.15.0
fixed in 1.15.1, 0.31.1
0.2%
Theoretical Threat
Not Applicable
CVE-2026-44240NONE0
basic-ftp
5.2.1
fixed in 5.3.1
0.5%
Theoretical Threat
Not Applicable
GHSA-6v7q-wjvx-w8wgNONE0
basic-ftp
5.2.1
fixed in 5.2.2
Not Applicable
CVE-2026-49458NONE0
dompurify
3.3.2
fixed in 3.4.6
Not Applicable
CVE-2026-49459NONE0
dompurify
3.3.2
fixed in 3.4.6
Not Applicable
CVE-2026-49978NONE0
dompurify
3.3.2
fixed in 3.4.7
Not Applicable
GHSA-39q2-94rc-95cpNONE0
dompurify
3.3.2
fixed in 3.4.0
Not Applicable
GHSA-76mc-f452-cxcmNONE0
dompurify
3.3.2
fixed in 3.4.7
Not Applicable
GHSA-cmwh-pvxp-8882NONE0
dompurify
3.3.2
fixed in 3.4.11
Not Applicable
GHSA-gvmj-g25r-r7wrNONE0
dompurify
3.3.2
fixed in 3.4.8
Not Applicable
GHSA-vxr8-fq34-vvx9NONE0
dompurify
3.3.2
fixed in 3.4.9
Not Applicable
GHSA-x4vx-rjvf-j5p4NONE0
dompurify
3.3.2
No fix yet
Not Applicable
GHSA-r4q5-vmmm-2653NONE0
follow-redirects
1.15.11
fixed in 1.16.0
Not Applicable
CVE-2026-12143NONE0
form-data
4.0.5
fixed in 2.5.6, 3.0.5, 4.0.6
0.3%
Theoretical Threat
Not Applicable
CVE-2026-48038NONE0
joi
18.0.2
fixed in 18.2.1, 17.13.4
Not Applicable
CVE-2026-46625NONE0
js-cookie
2.2.1
fixed in 3.0.7
0.4%
Theoretical Threat
Not Applicable
CVE-2026-53550NONE0
js-yaml
4.1.1
fixed in 4.2.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-45134NONE0
langsmith
0.5.7
fixed in 0.6.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-40190NONE0
langsmith
0.5.7
fixed in 0.5.18
0.2%
Theoretical Threat
Not Applicable
CVE-2026-41182NONE0
langsmith
0.5.7
fixed in 0.5.19
0.2%
Theoretical Threat
Not Applicable
CVE-2026-48988NONE0
markdown-it
14.1.1
fixed in 14.2.0
0.3%
Theoretical Threat
Not Applicable
GHSA-p6gq-j5cr-w38fNONE0
nodemailer
7.0.11
fixed in 9.0.1
Not Applicable
GHSA-268h-hp4c-crq3NONE0
nodemailer
7.0.11
fixed in 8.0.9
Not Applicable
GHSA-r7g4-qg5f-qqm2NONE0
nodemailer
7.0.11
fixed in 8.0.8
Not Applicable
GHSA-vvjj-xcjg-gr5gNONE0
nodemailer
7.0.11
fixed in 8.0.5
Not Applicable
GHSA-wqvq-jvpq-h66fNONE0
nodemailer
7.0.11
fixed in 8.0.9
Not Applicable
GHSA-c7w3-x93f-qmm8NONE0
nodemailer
7.0.11
fixed in 8.0.4
Not Applicable
CVE-2026-55388NONE0
piscina
3.2.0
fixed in 5.2.0, 4.9.3, 6.0.0-rc.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44289NONE0
protobufjs
7.5.5
fixed in 7.5.6, 8.0.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-44290NONE0
protobufjs
7.5.5
fixed in 7.5.6, 8.0.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-44291NONE0
protobufjs
7.5.5
fixed in 7.5.6, 8.0.2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-48712NONE0
protobufjs
7.5.5
fixed in 7.6.1, 8.4.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44292NONE0
protobufjs
7.5.5
fixed in 7.5.6, 8.0.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44294NONE0
protobufjs
7.5.5
fixed in 7.5.6, 8.0.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-54269NONE0
protobufjs
7.5.5
fixed in 7.6.3, 8.6.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-53655NONE0
tar
7.5.11
fixed in 7.5.16
0.1%
Theoretical Threat
Not Applicable
CVE-2026-48779NONE0
ws
8.20.0
fixed in 5.2.5, 6.2.4, 7.5.11, 8.21.0
0.5%
Theoretical Threat
Not Applicable