Vulnerability Reportkibana:8.19.16

kibana:8.19.16
DIGESTsha256:88844108397f3f1c0049a01216789eb2e03e6da102fd286f0b77f91affa7528b

Executive Summary

Threat Score
50/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could cause denial of service via CVE-2026-44496 or CVE-2026-45149, or bypass path-based security policies via CVE-2026-6321. However, CVE-2026-44496 only applies to client-side browser environments, not server-side Node.js usage. No post-exploit vulnerabilities were found, and the image is from an official source. Updating the affected packages to patched versions is the only complete mitigation.

Vulnerabilities

Vulnerability Log

125 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-44496MEDIUM6.38
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45149MEDIUM6.38
brace-expansion
5.0.5
fixed in 5.0.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6321MEDIUM6.38
fast-uri
3.0.3
fixed in 3.1.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6322MEDIUM6.38
fast-uri
3.0.3
fixed in 3.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42012MEDIUM6.03
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-2236MEDIUM5.9
libgcrypt20
1.10.3-2build1
No fix yet
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-42014MEDIUM5.61
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42013MEDIUM5.58
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4437MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-8769MEDIUM5.52
@ai-sdk/provider-utils
3.0.17
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33532MEDIUM5.52
yaml
1.10.2
fixed in 2.8.3, 1.10.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33532MEDIUM5.52
yaml
2.3.4
fixed in 2.8.3, 1.10.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libsystemd0
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libudev1
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-44665MEDIUM5.18
fast-xml-builder
1.1.5
fixed in 1.1.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-44664MEDIUM5.18
fast-xml-builder
1.1.5
fixed in 1.1.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9679MEDIUM5.02
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-66382MEDIUM4.67
libexpat1
2.6.1-2ubuntu0.4
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41650MEDIUM4.59
fast-xml-parser
5.5.7
fixed in 5.7.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-53382MEDIUM4.59
prismjs
1.27.0
fixed in 1.30.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-bin
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.6.1+really5.4.5-1ubuntu0.2
fixed in 5.6.1+really5.4.5-1ubuntu0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44489MEDIUM4.5
axios
1.15.2
fixed in 1.16.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-2739MEDIUM4.5
bn.js
4.11.9
fixed in 4.12.3, 5.2.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5260MEDIUM4.18
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3832LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-11525LOW3.15
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6733LOW3.15
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42010LOW3
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-45582LOW2.86
tar
1.35+dfsg-3build1
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-26280LOW2.81
systeminformation
5.30.3
fixed in 5.30.8
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-40228LOW2.8
libsystemd0
255.4-1ubuntu8.15
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
255.4-1ubuntu8.15
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33845LOW2.78
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-33846LOW2.7
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-42009LOW2.7
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-26318LOW2.69
systeminformation
5.30.3
fixed in 5.31.0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-44494LOW2.66
axios
1.15.2
fixed in 1.16.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-44492LOW2.63
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW2.55
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-44490LOW2.51
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-44724LOW2.39
systeminformation
5.30.3
fixed in 5.31.6
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-41989LOW2.29
libgcrypt20
1.10.3-2build1
fixed in 1.10.3-2ubuntu0.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-44486LOW2.29
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-44487LOW2.29
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-44488LOW2.29
axios
1.15.2
fixed in 1.16.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-12151LOW2.29
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
10.0.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
11.1.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
13.0.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
8.3.2
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
9.0.1
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
passwd
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW1.81
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2024-56433NONE0
login
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-48068NONE0
@grpc/grpc-js
1.14.3
fixed in 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4
Not Applicable
CVE-2026-48069NONE0
@grpc/grpc-js
1.14.3
fixed in 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4
Not Applicable
CVE-2026-44974NONE0
@hapi/content
6.0.1
fixed in 6.0.2
Not Applicable
CVE-2026-48049NONE0
@hapi/inert
7.1.0
fixed in 7.1.1
Not Applicable
CVE-2026-44979NONE0
@hapi/wreck
18.1.0
fixed in 18.1.1
Not Applicable
CVE-2026-48022NONE0
@hapi/wreck
18.1.0
fixed in 18.1.2
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
1.26.0
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
1.30.1
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
2.6.0
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
2.7.1
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-44902NONE0
@opentelemetry/exporter-prometheus
0.213.0
fixed in 0.217.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-44902NONE0
@opentelemetry/sdk-node
0.213.0
fixed in 0.217.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-49458NONE0
dompurify
3.4.1
fixed in 3.4.6
Not Applicable
CVE-2026-49459NONE0
dompurify
3.4.1
fixed in 3.4.6
Not Applicable
CVE-2026-49978NONE0
dompurify
3.4.1
fixed in 3.4.7
Not Applicable
GHSA-76mc-f452-cxcmNONE0
dompurify
3.4.1
fixed in 3.4.7
Not Applicable
GHSA-cmwh-pvxp-8882NONE0
dompurify
3.4.1
fixed in 3.4.11
Not Applicable
GHSA-gvmj-g25r-r7wrNONE0
dompurify
3.4.1
fixed in 3.4.8
Not Applicable
GHSA-vxr8-fq34-vvx9NONE0
dompurify
3.4.1
fixed in 3.4.9
Not Applicable
GHSA-x4vx-rjvf-j5p4NONE0
dompurify
3.4.1
No fix yet
Not Applicable
CVE-2026-12143NONE0
form-data
4.0.5
fixed in 2.5.6, 3.0.5, 4.0.6
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46625NONE0
js-cookie
2.2.1
fixed in 3.0.7
0.4%
Theoretical Threat
Not Applicable
CVE-2026-53550NONE0
js-yaml
4.1.1
fixed in 4.2.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-48988NONE0
markdown-it
14.1.1
fixed in 14.2.0
0.3%
Theoretical Threat
Not Applicable
GHSA-p6gq-j5cr-w38fNONE0
nodemailer
8.0.7
fixed in 9.0.1
Not Applicable
GHSA-268h-hp4c-crq3NONE0
nodemailer
8.0.7
fixed in 8.0.9
Not Applicable
GHSA-r7g4-qg5f-qqm2NONE0
nodemailer
8.0.7
fixed in 8.0.8
Not Applicable
GHSA-wqvq-jvpq-h66fNONE0
nodemailer
8.0.7
fixed in 8.0.9
Not Applicable
CVE-2026-55388NONE0
piscina
3.2.0
fixed in 5.2.0, 4.9.3, 6.0.0-rc.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-48712NONE0
protobufjs
7.5.8
fixed in 7.6.1, 8.4.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54269NONE0
protobufjs
7.5.8
fixed in 7.6.3, 8.6.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-53655NONE0
tar
7.5.11
fixed in 7.5.16
0.1%
Theoretical Threat
Not Applicable
CVE-2026-48779NONE0
ws
8.20.1
fixed in 5.2.5, 6.2.4, 7.5.11, 8.21.0
0.5%
Theoretical Threat
Not Applicable