Vulnerability Reportmaven:4.0.0-rc-5-amazoncorretto

maven:4.0.0-rc-5-amazoncorretto-25maven:4.0.0-rc-5-amazoncorretto
digestsha256:da2282f3caf16855f50cc6d6953c6dc24b8176d02bb69b61da49b2bc1680347c

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker controlling a remote Maven repository could exploit CVE-2025-67030 to execute arbitrary code on the build node during dependency resolution, while CVE-2026-6653 could cause denial of service via malicious XML. If the image is used only in a controlled CI/CD pipeline with restricted outbound connections to trusted repositories, the risk from remote attacks is mitigated, but internal archive processing remains vulnerable. Note that these vulnerabilities are exploitable under default configuration, as Maven routinely fetches dependencies and parses XML from remote sources.

Vulnerabilities

Vulnerability Log

85 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-67030HIGH7.48
org.codehaus.plexus:plexus-utils
4.0.2
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-6653MEDIUM6.66
libxml2
2.10.4-1.amzn2023.0.18
fixed in 2.10.4-1.amzn2023.0.19
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-56132MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-libs
1.21.3-7.amzn2023.0.1
fixed in 1.21.3-8.amzn2023.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45447LOW2.92
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-0864LOW2.8
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-0864LOW2.8
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-8643LOW2.8
python3-pip-wheel
21.3.1-2.amzn2023.0.19
fixed in 21.3.1-2.amzn2023.0.20
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58016LOW2.78
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3276LOW2.7
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3446LOW2.7
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3276LOW2.7
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-3446LOW2.7
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-58014LOW2.63
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58010LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58012LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58013LOW2.51
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-26740LOW2.29
giflib
5.2.1-9.amzn2023.0.3
fixed in 5.2.1-9.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-58011LOW2.29
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58015LOW2.29
glib2
2.82.2-769.amzn2023
fixed in 2.82.2-770.amzn2023
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW2.29
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW2.29
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42764LOW1.81
openssl-fips-provider-latest
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42764LOW1.81
openssl-libs
1:3.5.5-1.amzn2023.0.4
fixed in 1:3.5.5-1.amzn2023.0.5
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-9669LOW1.81
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9669LOW1.81
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57062LOW1.48
gnupg2-minimal
2.3.7-1.amzn2023.0.8
fixed in 2.3.7-1.amzn2023.0.9
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-48864NONE0
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-48863NONE0
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
Not Applicable
CVE-2026-54369NONE0
libacl
2.3.1-2.amzn2023.0.2
fixed in 2.4.0-1.amzn2023.0.1
0.1%
Theoretical Threat
Not Applicable
CVE-2026-9149NONE0
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-9150NONE0
libsolv
0.7.22-1.amzn2023.0.3
fixed in 0.7.22-1.amzn2023.0.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-54370NONE0
libacl
2.3.1-2.amzn2023.0.2
fixed in 2.4.0-1.amzn2023.0.1
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-56407NONE0
expat
2.6.3-1.amzn2023.0.4
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Not Applicable
CVE-2026-50593NONE0
graphite2
1.3.14-7.amzn2023.0.2
fixed in 1.3.14-7.amzn2023.0.3
0.1%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
libblkid
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libfdisk
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libmount
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libsmartcols
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libuuid
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-11940NONE0
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python3
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11940NONE0
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python3-libs
3.9.25-1.amzn2023.0.5
fixed in 3.9.25-1.amzn2023.0.7
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11822NONE0
sqlite-libs
3.40.0-1.amzn2023.0.7
fixed in 3.40.0-1.amzn2023.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-11824NONE0
sqlite-libs
3.40.0-1.amzn2023.0.7
fixed in 3.40.0-1.amzn2023.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
util-linux
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
util-linux-core
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.