Vulnerability Reportlogstash:8.19.16

logstash:8.19.16
DIGESTsha256:f50650a7c125c6b054631064ea353fabdb5a7258b2f8e8f7baffd88a6cdfc764

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
TRUSTED

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most notable vulnerability is CVE-2026-45447 in OpenSSL, which could allow remote code execution but only if the application processes crafted PKCS#7 messages, which is not a default Logstash behavior. The other exposed vulnerability (CVE-2026-45445) requires the non-standard AES-OCB one-shot API. Updating the libssl3t64 package to a patched version would fully address both issues. Post-exploit vulnerabilities are all low severity and pose negligible risk.

Vulnerabilities

Vulnerability Log

91 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45447MEDIUM6.48
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
1.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-45445MEDIUM6.18
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4437MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-4437MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-44249MEDIUM5.5
io.netty:netty-handler
4.1.134.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-40226MEDIUM5.44
libsystemd0
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libudev1
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM5.1
io.netty:netty-handler
4.1.134.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5588MEDIUM5.1
org.bouncycastle:bcpkix-jdk18on
1.78
fixed in 1.84
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-27219MEDIUM5.1
cgi
0.3.6
fixed in ~> 0.3.5.1, ~> 0.3.7, >= 0.4.2
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-27220MEDIUM5.1
cgi
0.3.6
fixed in ~> 0.3.5.1, ~> 0.3.7, >= 0.4.2
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34182MEDIUM5.03
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5435MEDIUM5.02
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-bin
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.6.1+really5.4.5-1ubuntu0.2
fixed in 5.6.1+really5.4.5-1ubuntu0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.134.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8916MEDIUM4.5
org.bouncycastle:bcpkix-jdk18on
1.78
fixed in 1.79
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14762MEDIUM4.5
aws-sdk-s3
1.192.0
fixed in >= 1.208.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-58767MEDIUM4.5
rexml
3.3.9
fixed in >= 3.4.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-27221MEDIUM4.5
uri
0.12.2
fixed in ~> 0.11.3, ~> 0.12.4, ~> 0.13.2, >= 1.0.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM4.02
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-27456MEDIUM4
libblkid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3t64
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-46551LOW3.15
rubygems:jruby-openssl
0.15.0
fixed in 0.15.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-46551LOW3.15
jruby-openssl
0.15.0
fixed in >= 0.15.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45447LOW2.92
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2025-45582LOW2.86
tar
1.35+dfsg-3build1
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-40228LOW2.8
libsystemd0
255.4-1ubuntu8.15
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
255.4-1ubuntu8.15
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45445LOW2.78
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-67030LOW2.69
org.codehaus.plexus:plexus-utils
3.5.1
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW2.55
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-41316LOW2.48
erb
2.2.3
fixed in ~> 4.0.3.1, ~> 4.0.4.1, ~> 6.0.1.1, >= 6.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-50010LOW2.29
io.netty:netty-handler
4.1.134.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-61594LOW2.29
uri
0.12.2
fixed in ~> 0.12.5, ~> 0.13.3, >= 1.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-2236LOW2.12
libgcrypt20
1.10.3-2ubuntu0.1
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-6238LOW1.99
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-0636LOW1.99
org.bouncycastle:bcprov-jdk18on
1.78
fixed in 1.84
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
login
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
passwd
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW1.81
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl
3.0.13-0ubuntu3.9
fixed in 3.0.13-0ubuntu3.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-4437NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6238NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-5435NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-4046NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-4438NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.15.0
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.16.2
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.17.2
fixed in 2.21.1, 2.18.6
Not Applicable
CVE-2026-54904NONE0
concurrent-ruby
1.1.9
fixed in 1.3.7
Not Applicable
CVE-2026-54905NONE0
concurrent-ruby
1.1.9
fixed in 1.3.7
Not Applicable
CVE-2026-54906NONE0
concurrent-ruby
1.1.9
fixed in 1.3.7
Not Applicable
CVE-2026-54297NONE0
faraday
2.14.2
fixed in >= 2.14.3
Not Applicable
CVE-2026-47240NONE0
net-imap
0.5.14
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
CVE-2026-47242NONE0
net-imap
0.5.14
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
CVE-2026-47241NONE0
net-imap
0.5.14
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
GHSA-c4rq-3m3g-8wgxNONE0
nokogiri
1.18.10
fixed in >= 1.19.3
Not Applicable
GHSA-5prr-v3j2-97mhNONE0
nokogiri
1.18.10
fixed in >= 1.19.4
Not Applicable
GHSA-v2fc-qm4h-8hqvNONE0
nokogiri
1.18.10
fixed in >= 1.19.3
Not Applicable
GHSA-wx95-c6cv-8532NONE0
nokogiri
1.18.10
fixed in >= 1.19.1
Not Applicable
GHSA-5v8h-3h3q-446pNONE0
nokogiri
1.18.10
fixed in >= 1.19.4
Not Applicable
GHSA-8678-w3jw-xfc2NONE0
nokogiri
1.18.10
fixed in >= 1.19.4
Not Applicable
GHSA-9cv2-cfxc-v4v2NONE0
nokogiri
1.18.10
fixed in >= 1.19.4
Not Applicable
GHSA-p67v-3w7g-wjg7NONE0
nokogiri
1.18.10
fixed in >= 1.19.4
Not Applicable
GHSA-phwj-rprq-35ppNONE0
nokogiri
1.18.10
fixed in >= 1.19.4
Not Applicable
GHSA-wfpw-mmfh-qq69NONE0
nokogiri
1.18.10
fixed in >= 1.19.4
Not Applicable
GHSA-wjv4-x9w8-wm3hNONE0
nokogiri
1.18.10
fixed in >= 1.19.4
Not Applicable
CVE-2026-47736NONE0
puma
6.6.1
fixed in ~> 7.2.1, >= 8.0.2
Not Applicable
CVE-2026-47737NONE0
puma
6.6.1
fixed in ~> 7.2.1, >= 8.0.2
Not Applicable