This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The two medium-severity CVEs (CVE-2026-42010 and CVE-2026-33845) affect the GnuTLS library and are only exploitable if non-default configurations (RSA-PSK or DTLS) are enabled. Since Manticore Search typically uses TCP-based protocols, the practical risk is low. Ensuring that the default configuration does not enable RSA-PSK or DTLS will fully mitigate these issues. The image is widely used and trusted, but updating the base image to include patched GnuTLS versions would further strengthen security.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-42010 | MEDIUM6.66 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33845 | MEDIUM6.18 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42014 | MEDIUM5.61 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42013 | MEDIUM5.58 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-5260 | MEDIUM5.58 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2017-13716 | MEDIUM5.5 | libbinutils 2.42-4ubuntu2.10 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2017-13716 | MEDIUM5.5 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2017-13716 | MEDIUM5.5 | libctf0 2.42-4ubuntu2.10 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2017-13716 | MEDIUM5.5 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2017-13716 | MEDIUM5.5 | libsframe1 2.42-4ubuntu2.10 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2026-41989 | MEDIUM5.1 | libgcrypt20 1.10.3-2build1 fixed in 1.10.3-2ubuntu0.1 | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33846 | MEDIUM5.1 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.9% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42009 | MEDIUM5.1 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-3833 | MEDIUM5.03 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42011 | MEDIUM5.03 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42012 | MEDIUM4.82 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2024-2236 | MEDIUM4.72 | libgcrypt20 1.10.3-2build1 No fix yet | 1.1% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-69651 | MEDIUM4.67 | libbinutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69651 | MEDIUM4.67 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69651 | MEDIUM4.67 | libctf0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-66382 | MEDIUM4.67 | libexpat1 2.6.1-2ubuntu0.4 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69651 | MEDIUM4.67 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69651 | MEDIUM4.67 | libsframe1 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libfdisk1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | libc6 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | LOW3.31 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | LOW3.31 | libc6 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2017-13716 | LOW3.3 | binutils 2.42-4ubuntu2.10 No fix yet | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2017-13716 | LOW3.3 | binutils-common 2.42-4ubuntu2.10 No fix yet | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2017-13716 | LOW3.3 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2025-1152 | LOW3.15 | libbinutils 2.42-4ubuntu2.10 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-1152 | LOW3.15 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-1152 | LOW3.15 | libctf0 2.42-4ubuntu2.10 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-3832 | LOW3.15 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5419 | LOW3.15 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-1152 | LOW3.15 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-1152 | LOW3.15 | libsframe1 2.42-4ubuntu2.10 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-45582 | LOW2.86 | tar 1.35+dfsg-3build1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69651 | LOW2.8 | binutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69651 | LOW2.8 | binutils-common 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69651 | LOW2.8 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69647 | LOW2.8 | libbinutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69648 | LOW2.8 | libbinutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69652 | LOW2.8 | libbinutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69647 | LOW2.8 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69648 | LOW2.8 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69652 | LOW2.8 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69647 | LOW2.8 | libctf0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69648 | LOW2.8 | libctf0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69652 | LOW2.8 | libctf0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69647 | LOW2.8 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69648 | LOW2.8 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69652 | LOW2.8 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69647 | LOW2.8 | libsframe1 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69648 | LOW2.8 | libsframe1 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69652 | LOW2.8 | libsframe1 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd-shared 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd0 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | LOW2.7 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | LOW2.7 | libc6 2.39-0ubuntu8.7 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42015 | LOW2.7 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-69644 | LOW2.38 | libbinutils 2.42-4ubuntu2.10 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69645 | LOW2.38 | libbinutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69646 | LOW2.38 | libbinutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69644 | LOW2.38 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69645 | LOW2.38 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69646 | LOW2.38 | libctf-nobfd0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69644 | LOW2.38 | libctf0 2.42-4ubuntu2.10 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69645 | LOW2.38 | libctf0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69646 | LOW2.38 | libctf0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69644 | LOW2.38 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69645 | LOW2.38 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69646 | LOW2.38 | libgprofng0 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69644 | LOW2.38 | libsframe1 2.42-4ubuntu2.10 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69645 | LOW2.38 | libsframe1 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69646 | LOW2.38 | libsframe1 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2021-31879 | LOW2.2 | wget 1.21.4-1ubuntu4.1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6238 | LOW1.99 | libc6 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-1152 | LOW1.89 | binutils 2.42-4ubuntu2.10 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-1152 | LOW1.89 | binutils-common 2.42-4ubuntu2.10 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-1152 | LOW1.89 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | login 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW1.81 | libc6 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69647 | LOW1.68 | binutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69648 | LOW1.68 | binutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69652 | LOW1.68 | binutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69647 | LOW1.68 | binutils-common 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69648 | LOW1.68 | binutils-common 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69652 | LOW1.68 | binutils-common 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69647 | LOW1.68 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69648 | LOW1.68 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69652 | LOW1.68 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69644 | LOW1.43 | binutils 2.42-4ubuntu2.10 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-69645 | LOW1.43 | binutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69646 | LOW1.43 | binutils 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69644 | LOW1.43 | binutils-common 2.42-4ubuntu2.10 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-69645 | LOW1.43 | binutils-common 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69646 | LOW1.43 | binutils-common 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69644 | LOW1.43 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-69645 | LOW1.43 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69646 | LOW1.43 | binutils-x86-64-linux-gnu 2.42-4ubuntu2.10 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-4437 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-6238 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-5435 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-4046 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-4438 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-40228 | NONE0 | systemd 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-40228 | NONE0 | systemd-dev 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Not Applicable |