Vulnerability Reportmaven:4.0.0-rc-5-amazoncorretto-17

maven:4.0.0-rc-5-amazoncorretto-17
digestsha256:b387fce90c2c940b9483566ce20f3aabb1d1a7cd52e093f05adad630b4b67ca3

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. While the image contains 12 exposed vulnerabilities and 28 post-exploit vulnerabilities, all are rated low severity (maximum CVSS score 5.98) and none pose a realistic threat. The image is official, widely used, and pinned by digest, ensuring integrity and trust.

Vulnerabilities

Vulnerability Log

40 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-67030MEDIUM5.98
org.codehaus.plexus:plexus-utils
4.0.2
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-56132MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.7
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-52858LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-52860LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-55693LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-55895LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57456LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-52858LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-52860LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-55693LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-55895LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57456LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW3.4
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-6653LOW3
libxml2
2.9.1-6.amzn2.5.24
fixed in 2.9.1-6.amzn2.5.25
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-58016LOW2.78
glib2
2.56.1-9.amzn2.0.13
fixed in 2.56.1-9.amzn2.0.14
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-7598LOW2.78
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-47167LOW2.7
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-47167LOW2.7
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-47162LOW2.69
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-47162LOW2.69
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-58050LOW2.29
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58051LOW1.99
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python
2.7.18-1.amzn2.0.19
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python-libs
2.7.18-1.amzn2.0.19
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python
2.7.18-1.amzn2.0.19
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python-libs
2.7.18-1.amzn2.0.19
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW1.62
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11850LOW1.53
krb5-libs
1.15.1-55.amzn2.2.9
fixed in 1.15.1-55.amzn2.2.10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-56407NONE0
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
libblkid
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libfdisk
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libmount
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libsmartcols
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libuuid
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
util-linux
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.