Vulnerability Reportkibana:9.3.5

kibana:9.3.5
DIGESTsha256:5e64881ac2736d141b6bc2ce5c3aa1ca97ebba248a748a052411a6fff31a476d

Executive Summary

Threat Score
50/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could crash the service via crafted XML/XSD documents (CVE-2026-6732) or oversize requests (CVE-2026-44488), or bypass path-based security controls via fast-uri normalization issues (CVE-2026-6321). Note: The undici SOCKS5 vulnerabilities only apply if a SOCKS5 proxy is configured; the brace-expansion issue requires untrusted user input to be processed. Restricting external access and disabling unnecessary features can reduce the attack surface.

Vulnerabilities

Vulnerability Log

294 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-6732MEDIUM6.38
libxml2
2.9.13-14.el9_7
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-44488MEDIUM6.38
axios
1.15.2
fixed in 1.16.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44496MEDIUM6.38
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45149MEDIUM6.38
brace-expansion
5.0.5
fixed in 5.0.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6321MEDIUM6.38
fast-uri
3.0.3
fixed in 3.1.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6322MEDIUM6.38
fast-uri
3.0.3
fixed in 3.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6734MEDIUM6.38
undici
7.24.4
fixed in 7.28.0, 8.2.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-9697MEDIUM6.29
undici
7.24.4
fixed in 7.28.0, 8.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-44604MEDIUM5.95
rpm-libs
4.16.1.3-40.el9
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.16.0-9.el9
No fix yet
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-41996MEDIUM5.9
openssl-libs
1:3.5.5-4.el9_8
No fix yet
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.5.0-6.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22185MEDIUM5.78
openldap
2.6.8-4.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4105MEDIUM5.7
systemd-libs
252-67.el9_8.2
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-5915MEDIUM5.61
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-5918MEDIUM5.61
libarchive
3.5.3-9.el9_7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-common
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4426MEDIUM5.52
libarchive
3.5.3-9.el9_7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9149MEDIUM5.52
libsolv
0.7.24-5.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9150MEDIUM5.52
libsolv
0.7.24-5.el9_8
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-45322MEDIUM5.52
libxml2
2.9.13-14.el9_7
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-7531MEDIUM5.52
nspr
4.36.0-8.el9_4
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-7531MEDIUM5.52
nss
3.112.0-8.el9_4
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-7531MEDIUM5.52
nss-softokn
3.112.0-8.el9_4
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-7531MEDIUM5.52
nss-softokn-freebl
3.112.0-8.el9_4
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-7531MEDIUM5.52
nss-sysinit
3.112.0-8.el9_4
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-7531MEDIUM5.52
nss-util
3.112.0-8.el9_4
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-fips-provider
3.0.7-8.el9
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-fips-provider-so
3.0.7-8.el9
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-8769MEDIUM5.52
@ai-sdk/provider-utils
3.0.17
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-47673MEDIUM5.52
hono
4.12.19
fixed in 4.12.21
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41311MEDIUM5.52
liquidjs
10.25.6
fixed in 10.25.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33532MEDIUM5.52
yaml
1.10.2
fixed in 2.8.3, 1.10.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33532MEDIUM5.52
yaml
2.3.4
fixed in 2.8.3, 1.10.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM5.5
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2024-34459MEDIUM5.5
libxml2
2.9.13-14.el9_7
No fix yet
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-1757MEDIUM5.27
libxml2
2.9.13-14.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-64506MEDIUM5.18
libpng
2:1.6.37-15.el9_8
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-44665MEDIUM5.18
fast-xml-builder
1.1.5
fixed in 1.1.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-44664MEDIUM5.18
fast-xml-builder
1.1.5
fixed in 1.1.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-28388MEDIUM5.1
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-50219MEDIUM5.02
expat
2.5.0-6.el9_8.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc
2.34-270.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.34-270.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.34-270.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-0990MEDIUM5.02
libxml2
2.9.13-14.el9_7
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2020-12413MEDIUM5.02
nspr
4.36.0-8.el9_4
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2020-12413MEDIUM5.02
nss
3.112.0-8.el9_4
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2020-12413MEDIUM5.02
nss-softokn
3.112.0-8.el9_4
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2020-12413MEDIUM5.02
nss-softokn-freebl
3.112.0-8.el9_4
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2020-12413MEDIUM5.02
nss-sysinit
3.112.0-8.el9_4
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2020-12413MEDIUM5.02
nss-util
3.112.0-8.el9_4
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-fips-provider
3.0.7-8.el9
fixed in 3.0.7-11.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-fips-provider-so
3.0.7-8.el9
fixed in 3.0.7-11.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-9679MEDIUM5.02
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9678MEDIUM5.02
undici
7.24.4
fixed in 7.28.0, 8.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9679MEDIUM5.02
undici
7.24.4
fixed in 6.27.0, 7.28.0, 8.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-5916MEDIUM4.76
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
expat
2.5.0-6.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
expat
2.5.0-6.el9_8.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
expat
2.5.0-6.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-66382MEDIUM4.67
expat
2.5.0-6.el9_8.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-60753MEDIUM4.67
libarchive
3.5.3-9.el9_7
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5745MEDIUM4.67
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-1632MEDIUM4.67
libarchive
3.5.3-9.el9_7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libgcc
11.5.0-14.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc
11.5.0-14.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libstdc++
11.5.0-14.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libstdc++
11.5.0-14.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2024-0232MEDIUM4.67
sqlite-libs
3.34.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.11-40.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-1489MEDIUM4.59
glib2
2.68.4-19.el9_8.1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41650MEDIUM4.59
fast-xml-parser
5.5.7
fixed in 5.7.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-53382MEDIUM4.59
prismjs
1.27.0
fixed in 1.30.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
freetype
2.10.4-10.el9_5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22693MEDIUM4.5
harfbuzz
2.7.4-10.el9
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-30571MEDIUM4.5
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
xz-libs
5.2.5-8.el9_0
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44489MEDIUM4.5
axios
1.15.2
fixed in 1.16.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-2739MEDIUM4.5
bn.js
4.11.9
fixed in 4.12.3, 5.2.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-47675MEDIUM4.5
hono
4.12.19
fixed in 4.12.21
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42250MEDIUM4.25
bzip2-libs
1.0.8-11.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.34-270.el9_8
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.34-270.el9_8
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.34-270.el9_8
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.34-270.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-libs
1.21.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-5917MEDIUM4.25
libarchive
3.5.3-9.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-28164MEDIUM4.25
libpng
2:1.6.37-15.el9_8
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM4.17
expat
2.5.0-6.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-41989LOW3.83
libgcrypt
1.10.0-11.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-28389LOW3.83
openssl-libs
1:3.5.5-4.el9_8
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-5773LOW3.82
curl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
libcurl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW3.82
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python3
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW3.82
python3
3.9.25-7.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python3-libs
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW3.82
python3-libs
3.9.25-7.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-64505LOW3.74
libpng
2:1.6.37-15.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34757LOW3.74
libpng
2:1.6.37-15.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-4156LOW3.62
gawk
5.1.0-6.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-44604LOW3.57
rpm
4.16.1.3-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1484LOW3.57
glib2
2.68.4-19.el9_8.1
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-11053LOW3.54
curl-minimal
7.76.1-40.el9
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-11053LOW3.54
libcurl-minimal
7.76.1-40.el9
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2025-13034LOW3.47
curl-minimal
7.76.1-40.el9
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-13034LOW3.47
libcurl-minimal
7.76.1-40.el9
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2021-3572LOW3.42
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-3784LOW3.31
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl-minimal
7.76.1-40.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl-minimal
7.76.1-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
libcurl-minimal
7.76.1-40.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
libcurl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl-minimal
7.76.1-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
curl-minimal
7.76.1-40.el9
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
libcurl-minimal
7.76.1-40.el9
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-5958LOW3.21
sed
4.8-10.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-41080LOW3.15
expat
2.5.0-6.el9_8.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-3360LOW3.15
glib2
2.68.4-19.el9_8.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-7039LOW3.15
glib2
2.68.4-19.el9_8.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0988LOW3.15
glib2
2.68.4-19.el9_8.1
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0989LOW3.15
libxml2
2.9.13-14.el9_7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-11525LOW3.15
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6733LOW3.15
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-11525LOW3.15
undici
7.24.4
fixed in 6.27.0, 7.28.0, 8.5.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6733LOW3.15
undici
7.24.4
fixed in 6.27.0, 7.28.0, 8.5.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6019LOW3.11
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-50181LOW3.11
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-50182LOW3.11
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW3.1
openssl-libs
1:3.5.5-4.el9_8
No fix yet
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-5713LOW3.06
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5713LOW3.06
python3
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5713LOW3.06
python3-libs
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-32284LOW3.01
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3783LOW2.91
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3783LOW2.91
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-26280LOW2.81
systeminformation
5.30.3
fixed in 5.30.8
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-24883LOW2.8
gnupg2
2.3.3-5.el9_7
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-13837LOW2.8
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42308LOW2.8
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-13837LOW2.8
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42308LOW2.8
python3
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-13837LOW2.8
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42308LOW2.8
python3-libs
3.9.25-7.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-25645LOW2.8
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-41990LOW2.8
libgcrypt
1.10.0-11.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-70873LOW2.8
sqlite-libs
3.34.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-27113LOW2.7
libxml2
2.9.13-14.el9_7
No fix yet
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-4873LOW2.7
curl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl-minimal
7.76.1-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
libcurl-minimal
7.76.1-40.el9
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
libcurl-minimal
7.76.1-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
libcurl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-12781LOW2.7
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3276LOW2.7
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-12781LOW2.7
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3276LOW2.7
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-12781LOW2.7
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3276LOW2.7
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-26318LOW2.69
systeminformation
5.30.3
fixed in 5.31.0
1.0%
Theoretical Threat
Post-Exploit
CVE-2024-7264LOW2.69
curl-minimal
7.76.1-40.el9
No fix yet
16.2%
High Exploitation Risk
Post-Exploit
CVE-2024-7264LOW2.69
libcurl-minimal
7.76.1-40.el9
No fix yet
16.2%
High Exploitation Risk
Post-Exploit
CVE-2026-44494LOW2.66
axios
1.15.2
fixed in 1.16.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-44492LOW2.63
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-4516LOW2.6
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-4516LOW2.6
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-4516LOW2.6
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-44490LOW2.51
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
curl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
libcurl-minimal
7.76.1-40.el9
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0992LOW2.46
libxml2
2.9.13-14.el9_7
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-14017LOW2.45
curl-minimal
7.76.1-40.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl-minimal
7.76.1-40.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python3
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python3-libs
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
curl-minimal
7.76.1-40.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg2
2.3.3-5.el9_7
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-30258LOW2.4
gnupg2
2.3.3-5.el9_7
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
libcurl-minimal
7.76.1-40.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.24-5.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-44724LOW2.39
systeminformation
5.30.3
fixed in 5.31.6
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1485LOW2.38
glib2
2.68.4-19.el9_8.1
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-9681LOW2.34
curl-minimal
7.76.1-40.el9
No fix yet
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-9681LOW2.34
libcurl-minimal
7.76.1-40.el9
No fix yet
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-32636LOW2.29
glib2
2.68.4-19.el9_8.1
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2022-41409LOW2.29
pcre2
10.40-6.el9
No fix yet
1.0%
Theoretical Threat
Post-Exploit
CVE-2022-41409LOW2.29
pcre2-syntax
10.40-6.el9
No fix yet
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW2.29
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW2.29
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW2.29
python3
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW2.29
python3-libs
3.9.25-7.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-44486LOW2.29
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-44487LOW2.29
axios
1.15.2
fixed in 1.16.0, 0.32.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-12151LOW2.29
undici
6.24.1
fixed in 6.27.0, 7.28.0, 8.5.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-12151LOW2.29
undici
7.24.4
fixed in 6.27.0, 7.28.0, 8.5.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
10.0.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
11.1.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
13.0.0
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
8.3.2
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41907LOW2.29
uuid
9.0.1
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1502LOW2.29
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1502LOW2.29
python3
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1502LOW2.29
python3-libs
3.9.25-7.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.32-40.el9
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2023-45803LOW2.14
python3-pip-wheel
21.3.1-2.el9_8
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-24515LOW2.12
expat
2.5.0-6.el9_8.1
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-6170LOW2.12
libxml2
2.9.13-14.el9_7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2022-3219LOW1.68
gnupg2
2.3.3-5.el9_7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3-libs
3.9.25-7.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-1795LOW1.58
python-unversioned-command
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-1795LOW1.58
python3
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-1795LOW1.58
python3-libs
3.9.25-7.el9_8
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-50495NONE0
ncurses-base
6.2-12.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.2-12.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2026-22020NONE0
libpng
2:1.6.37-15.el9_8
No fix yet
Not Applicable
CVE-2026-48068NONE0
@grpc/grpc-js
1.14.3
fixed in 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4
Not Applicable
CVE-2026-48069NONE0
@grpc/grpc-js
1.14.3
fixed in 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4
Not Applicable
CVE-2026-48049NONE0
@hapi/inert
7.1.0
fixed in 7.1.1
Not Applicable
CVE-2026-48022NONE0
@hapi/wreck
18.1.1
fixed in 18.1.2
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
1.30.1
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
2.6.0
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54285NONE0
@opentelemetry/core
2.7.1
fixed in 2.8.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-44902NONE0
@opentelemetry/exporter-prometheus
0.213.0
fixed in 0.217.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-44902NONE0
@opentelemetry/sdk-node
0.213.0
fixed in 0.217.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-49458NONE0
dompurify
3.4.1
fixed in 3.4.6
Not Applicable
CVE-2026-49459NONE0
dompurify
3.4.1
fixed in 3.4.6
Not Applicable
CVE-2026-49978NONE0
dompurify
3.4.1
fixed in 3.4.7
Not Applicable
GHSA-76mc-f452-cxcmNONE0
dompurify
3.4.1
fixed in 3.4.7
Not Applicable
GHSA-cmwh-pvxp-8882NONE0
dompurify
3.4.1
fixed in 3.4.11
Not Applicable
GHSA-gvmj-g25r-r7wrNONE0
dompurify
3.4.1
fixed in 3.4.8
Not Applicable
GHSA-vxr8-fq34-vvx9NONE0
dompurify
3.4.1
fixed in 3.4.9
Not Applicable
GHSA-x4vx-rjvf-j5p4NONE0
dompurify
3.4.1
No fix yet
Not Applicable
CVE-2026-12143NONE0
form-data
4.0.5
fixed in 2.5.6, 3.0.5, 4.0.6
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54290NONE0
hono
4.12.19
fixed in 4.12.25
0.2%
Theoretical Threat
Not Applicable
CVE-2026-47674NONE0
hono
4.12.19
fixed in 4.12.21
0.2%
Theoretical Threat
Not Applicable
CVE-2026-47676NONE0
hono
4.12.19
fixed in 4.12.21
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54286NONE0
hono
4.12.19
fixed in 4.12.25
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54287NONE0
hono
4.12.19
fixed in 4.12.25
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54288NONE0
hono
4.12.19
fixed in 4.12.25
0.1%
Theoretical Threat
Not Applicable
CVE-2026-54289NONE0
hono
4.12.19
fixed in 4.12.25
0.1%
Theoretical Threat
Not Applicable
CVE-2026-46625NONE0
js-cookie
2.2.1
fixed in 3.0.7
0.4%
Theoretical Threat
Not Applicable
CVE-2026-53550NONE0
js-yaml
4.1.1
fixed in 4.2.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-45618NONE0
liquidjs
10.25.6
fixed in 10.26.0
Not Applicable
CVE-2026-45357NONE0
liquidjs
10.25.6
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-45617NONE0
liquidjs
10.25.6
fixed in 10.26.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-44644NONE0
liquidjs
10.25.6
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-44645NONE0
liquidjs
10.25.6
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44646NONE0
liquidjs
10.25.6
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-48988NONE0
markdown-it
14.1.1
fixed in 14.2.0
0.3%
Theoretical Threat
Not Applicable
GHSA-p6gq-j5cr-w38fNONE0
nodemailer
8.0.7
fixed in 9.0.1
Not Applicable
GHSA-268h-hp4c-crq3NONE0
nodemailer
8.0.7
fixed in 8.0.9
Not Applicable
GHSA-r7g4-qg5f-qqm2NONE0
nodemailer
8.0.7
fixed in 8.0.8
Not Applicable
GHSA-wqvq-jvpq-h66fNONE0
nodemailer
8.0.7
fixed in 8.0.9
Not Applicable
CVE-2026-55388NONE0
piscina
3.2.0
fixed in 5.2.0, 4.9.3, 6.0.0-rc.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-48712NONE0
protobufjs
7.5.8
fixed in 7.6.1, 8.4.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54269NONE0
protobufjs
7.5.8
fixed in 7.6.3, 8.6.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-53655NONE0
tar
7.5.11
fixed in 7.5.16
0.1%
Theoretical Threat
Not Applicable
CVE-2026-48779NONE0
ws
8.20.1
fixed in 5.2.5, 6.2.4, 7.5.11, 8.21.0
0.5%
Theoretical Threat
Not Applicable