Vulnerability Reportmetasploitframework/metasploit-framework:6.3.34

metasploitframework/metasploit-framework:6.3.34
DIGESTsha256:4818a53ec8d1709cbd3b9d38318677db619af68b20a6ca35c21fc7b366a16501

Executive Summary

Threat Score
100/100DANGEROUS
Reputation
UNVERIFIED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could execute arbitrary code via the zlib buffer overflow (CVE-2026-27820) or cause denial of service through HTTP/2 Rapid Reset (CVE-2023-44487). The image contains 137 known vulnerabilities and is from an unverified community source. Disabling HTTP/2 in any web services would fully mitigate CVE-2023-44487.

Vulnerabilities

Vulnerability Log

231 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-27820HIGH8.33
zlib
2.0.0
fixed in ~> 3.0.1, ~> 3.1.2, >= 3.2.3
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2023-44487HIGH7.8
nghttp2-libs
1.46.0-r1
fixed in 1.46.0-r2
100.0%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2024-49767HIGH7.5
Werkzeug
2.3.7
fixed in 3.0.6
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-27610HIGH7.5
rack
2.2.7
fixed in ~> 2.2.13, ~> 3.0.14, >= 3.1.12
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-56201HIGH7.48
Jinja2
3.1.2
fixed in 3.1.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-27516HIGH7.48
Jinja2
3.1.2
fixed in 3.1.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-25126MEDIUM6.9
rack
2.2.7
fixed in ~> 2.2.8, >= 2.2.8.1, >= 3.0.9.1
35.4%
High Exploitation Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-41316MEDIUM6.88
erb
2.2.0
fixed in ~> 4.0.3.1, ~> 4.0.4.1, ~> 6.0.1.1, >= 6.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-28103MEDIUM6.66
actionpack
7.0.5
fixed in ~> 6.1.7, >= 6.1.7.8, ~> 7.0.8, >= 7.0.8.4, ~> 7.1.3, >= 7.1.3.4, >= 7.2.0.beta2
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42257MEDIUM6.66
net-imap
0.1.1
fixed in ~> 0.4.24, ~> 0.5.14, >= 0.6.4
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42258MEDIUM6.66
net-imap
0.1.1
fixed in ~> 0.4.24, ~> 0.5.14, >= 0.6.4
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42257MEDIUM6.66
net-imap
0.3.7
fixed in ~> 0.4.24, ~> 0.5.14, >= 0.6.4
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42258MEDIUM6.66
net-imap
0.3.7
fixed in ~> 0.4.24, ~> 0.5.14, >= 0.6.4
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2023-40175MEDIUM6.66
puma
6.3.0
fixed in ~> 5.6.7, >= 6.3.1
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-25184MEDIUM6.5
rack
2.2.7
fixed in ~> 2.2.11, ~> 3.0.12, >= 3.1.10
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-43804MEDIUM6.48
py3-urllib3
1.26.7-r0
fixed in 1.26.17-r0
1.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-26130MEDIUM6.38
cryptography
41.0.3
fixed in 42.0.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-49083MEDIUM6.38
cryptography
41.0.3
fixed in 41.0.6
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-30922MEDIUM6.38
pyasn1
0.5.0
fixed in 0.6.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33176MEDIUM6.38
activesupport
7.0.5
fixed in ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33306MEDIUM6.38
bcrypt
3.1.18
fixed in >= 3.1.22
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-27219MEDIUM6.38
cgi
0.2.2
fixed in ~> 0.3.5.1, ~> 0.3.7, >= 0.4.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-27220MEDIUM6.38
cgi
0.2.2
fixed in ~> 0.3.5.1, ~> 0.3.7, >= 0.4.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42245MEDIUM6.38
net-imap
0.1.1
fixed in ~> 0.4.24, ~> 0.5.14, >= 0.6.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42245MEDIUM6.38
net-imap
0.3.7
fixed in ~> 0.4.24, ~> 0.5.14, >= 0.6.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-21647MEDIUM6.38
puma
6.3.0
fixed in ~> 5.6.8, >= 6.4.2
1.0%
Theoretical Threat
Directly Exposed
CVE-2025-27111MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.12, ~> 3.0.13, >= 3.1.11
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-46727MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.14, ~> 3.0.16, >= 3.1.14
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-59830MEDIUM6.38
rack
2.2.7
fixed in >= 2.2.18
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61770MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.19, ~> 3.1.17, >= 3.2.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61771MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.19, ~> 3.1.17, >= 3.2.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61919MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.20, ~> 3.1.18, >= 3.2.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-22860MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.22, ~> 3.1.20, >= 3.2.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34785MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34829MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34230MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34826MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34830MEDIUM6.38
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-61921MEDIUM6.38
sinatra
3.0.6
fixed in >= 4.2.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61594MEDIUM6.38
uri
0.10.1
fixed in ~> 0.12.5, ~> 0.13.3, >= 1.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-47220MEDIUM6.38
webrick
1.8.1
fixed in >= 1.8.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-12790MEDIUM6.29
mqtt
0.6.0
fixed in >= 0.7.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42246MEDIUM6.29
net-imap
0.1.1
fixed in ~> 0.3.10, ~> 0.4.24, ~> 0.5.14, >= 0.6.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42246MEDIUM6.29
net-imap
0.3.7
fixed in ~> 0.3.10, ~> 0.4.24, ~> 0.5.14, >= 0.6.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-26143MEDIUM6.1
actionpack
7.0.5
fixed in ~> 7.0.8, >= 7.0.8.1, >= 7.1.3.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-50782MEDIUM6
cryptography
41.0.3
fixed in 42.0.0
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-26141MEDIUM6
rack
2.2.7
fixed in ~> 2.2.8, >= 2.2.8.1, >= 3.0.9.1
1.6%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-26146MEDIUM6
rack
2.2.7
fixed in ~> 2.0.9, >= 2.0.9.4, ~> 2.1.4, >= 2.1.4.4, ~> 2.2.8, >= 2.2.8.1, >= 3.0.9.1
2.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-49761MEDIUM6
rexml
3.2.5
fixed in >= 3.3.9
1.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-41123MEDIUM6
rexml
3.2.5
fixed in >= 3.3.3
1.3%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-41946MEDIUM6
rexml
3.2.5
fixed in >= 3.3.3
1.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2023-29483MEDIUM5.9
dnspython
2.4.2
fixed in 2.6.1
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-43398MEDIUM5.9
rexml
3.2.5
fixed in >= 3.3.6
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-26007MEDIUM5.52
cryptography
41.0.3
fixed in 46.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-35611MEDIUM5.52
addressable
2.8.4
fixed in >= 2.9.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33637MEDIUM5.52
faraday
2.7.6
fixed in >= 2.14.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-43857MEDIUM5.52
net-imap
0.1.1
fixed in ~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-25186MEDIUM5.52
net-imap
0.3.7
fixed in ~> 0.3.8, ~> 0.4.19, >= 0.5.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-43857MEDIUM5.52
net-imap
0.3.7
fixed in ~> 0.2.5, ~> 0.3.9, ~> 0.4.20, >= 0.5.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34786MEDIUM5.52
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34831MEDIUM5.52
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-0727MEDIUM5.5
cryptography
41.0.3
fixed in 42.0.2
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-56326MEDIUM5.35
Jinja2
3.1.2
fixed in 3.1.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2023-5678MEDIUM5.3
libcrypto1.1
1.1.1v-r0
fixed in 1.1.1w-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
libssl1.1
1.1.1v-r0
fixed in 1.1.1w-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
openssl-dev
1.1.1v-r0
fixed in 1.1.1w-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2024-35176MEDIUM5.3
rexml
3.2.5
fixed in >= 3.2.7
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-28756MEDIUM5.3
time
0.1.0
fixed in ~> 0.1.1, >= 0.2.2
2.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-28755MEDIUM5.3
uri
0.10.1
fixed in ~> 0.10.0.1, ~> 0.10.2, ~> 0.11.1, >= 0.12.1
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-36617MEDIUM5.3
uri
0.10.1
fixed in ~> 0.10.0.3, ~> 0.10.3, ~> 0.11.2, >= 0.12.2
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2024-5569MEDIUM5.27
zipp
3.16.2
fixed in 3.19.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-22195MEDIUM5.18
Jinja2
3.1.2
fixed in 3.1.3
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-33170MEDIUM5.18
activesupport
7.0.5
fixed in ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-53985MEDIUM5.18
rails-html-sanitizer
1.6.0
fixed in >= 1.6.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-53986MEDIUM5.18
rails-html-sanitizer
1.6.0
fixed in >= 1.6.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-53987MEDIUM5.18
rails-html-sanitizer
1.6.0
fixed in >= 1.6.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-53988MEDIUM5.18
rails-html-sanitizer
1.6.0
fixed in >= 1.6.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-53989MEDIUM5.18
rails-html-sanitizer
1.6.0
fixed in >= 1.6.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2023-52323MEDIUM5.02
pycryptodomex
3.18.0
fixed in 3.19.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-6442MEDIUM5.02
webrick
1.8.1
fixed in >= 1.8.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-25765MEDIUM4.93
faraday
2.7.6
fixed in ~> 1.10.5, >= 2.14.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-34064MEDIUM4.59
Jinja2
3.1.2
fixed in 3.1.4
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-33168MEDIUM4.59
actionview
7.0.5
fixed in ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-45614MEDIUM4.59
puma
6.3.0
fixed in ~> 5.6.9, >= 6.4.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-25500MEDIUM4.59
rack
2.2.7
fixed in ~> 2.2.22, ~> 3.1.20, >= 3.2.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-21510MEDIUM4.59
sinatra
3.0.6
fixed in >= 4.1.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2023-38545MEDIUM4.58
curl
8.2.1-r0
fixed in 8.4.0-r0
78.5%
Actively Exploited
Post-Exploit
CVE-2023-38545MEDIUM4.58
libcurl
8.2.1-r0
fixed in 8.4.0-r0
78.5%
Actively Exploited
Post-Exploit
CVE-2024-49766MEDIUM4.5
Werkzeug
2.3.7
fixed in 3.0.6
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-66221MEDIUM4.5
Werkzeug
2.3.7
fixed in 3.1.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-21860MEDIUM4.5
Werkzeug
2.3.7
fixed in 3.1.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27199MEDIUM4.5
Werkzeug
2.3.7
fixed in 3.1.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34073MEDIUM4.5
cryptography
41.0.3
fixed in 46.0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27448MEDIUM4.5
pyOpenSSL
23.2.0
fixed in 26.0.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33169MEDIUM4.5
activesupport
7.0.5
fixed in ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-14762MEDIUM4.5
aws-sdk-s3
1.123.1
fixed in >= 1.208.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-61772MEDIUM4.5
rack
2.2.7
fixed in ~> 2.2.19, ~> 3.1.17, >= 3.2.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61780MEDIUM4.5
rack
2.2.7
fixed in ~> 2.2.20, ~> 3.1.18, >= 3.2.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34763MEDIUM4.5
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-26961MEDIUM4.5
rack
2.2.7
fixed in ~> 2.2.23, ~> 3.1.21, >= 3.2.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-24294MEDIUM4.5
resolv
0.2.1
fixed in ~> 0.2.2, ~> 0.3.0, >= 0.6.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-27221MEDIUM4.5
uri
0.10.1
fixed in ~> 0.11.3, ~> 0.12.4, ~> 0.13.2, >= 1.0.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2023-5870MEDIUM4.4
libecpg
14.9-r0
fixed in 14.10-r0
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-5870MEDIUM4.4
libpq
14.9-r0
fixed in 14.10-r0
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-5868MEDIUM4.3
libecpg
14.9-r0
fixed in 14.10-r0
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2023-5868MEDIUM4.3
libpq
14.9-r0
fixed in 14.10-r0
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2024-39908MEDIUM4.3
rexml
3.2.5
fixed in >= 3.3.2
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2023-28362MEDIUM4
actionpack
7.0.5
fixed in ~> 6.1.7.4, >= 7.0.5.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-41128LOW3.7
actionpack
7.0.5
fixed in ~> 6.1.7.9, ~> 7.0.8, >= 7.0.8.5, ~> 7.1.4, >= 7.1.4.1, >= 7.2.1.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-47887LOW3.7
actionpack
7.0.5
fixed in ~> 6.1.7.9, ~> 7.0.8, >= 7.0.8.5, ~> 7.1.4, >= 7.1.4.1, >= 7.2.1.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-27205LOW3.65
Flask
2.3.3
fixed in 3.1.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-54133LOW3.65
actionpack
7.0.5
fixed in ~> 7.0.8, >= 7.0.8.7, ~> 7.1.5, >= 7.1.5.1, ~> 7.2.2, >= 7.2.2.1, >= 8.0.0.1
1.0%
Theoretical Threat
Directly Exposed
CVE-2025-55193LOW3.65
activerecord
7.0.5
fixed in ~> 7.1.5, >= 7.1.5.2, ~> 7.2.2, >= 7.2.2.2, >= 8.0.2.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2023-45803LOW3.57
py3-urllib3
1.26.7-r0
fixed in 1.26.18-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-32441LOW3.57
rack
2.2.7
fixed in >= 2.2.14
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-38039LOW3.51
curl
8.2.1-r0
fixed in 8.3.0-r0
63.8%
Actively Exploited
Post-Exploit
CVE-2023-38039LOW3.51
libcurl
8.2.1-r0
fixed in 8.3.0-r0
63.8%
Actively Exploited
Post-Exploit
CVE-2023-46219LOW3.18
curl
8.2.1-r0
fixed in 8.5.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
libcurl
8.2.1-r0
fixed in 8.5.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2023-5678LOW3.18
openssl
1.1.1v-r0
fixed in 1.1.1w-r1
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2023-5869LOW3.17
libecpg
14.9-r0
fixed in 14.10-r0
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-5869LOW3.17
libpq
14.9-r0
fixed in 14.10-r0
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2020-36327LOW3.17
bundler
2.1.4
fixed in = 2.2.10, >= 2.2.18
6.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-27280LOW3.1
stringio
3.0.1
fixed in >= 3.0.1.1
2.4%
Low-Moderate Risk
Directly Exposed
CVE-2026-27459LOW3
pyOpenSSL
23.2.0
fixed in 26.0.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2024-58266LOW3
shlex
1.1.0
fixed in 1.3.0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-6357LOW2.96
pip
23.2.1
fixed in 26.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2023-24056LOW2.8
pkgconf
1.8.0-r0
fixed in 1.8.1-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-24049LOW2.8
wheel
0.41.2
fixed in 0.46.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-4016LOW2.8
libproc
3.3.17-r0
fixed in 3.3.17-r1
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-38037LOW2.8
activesupport
7.0.5
fixed in ~> 6.1.7, >= 6.1.7.5, >= 7.0.7.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-34069LOW2.7
Werkzeug
2.3.7
fixed in 3.0.3
3.4%
Low-Moderate Risk
Post-Exploit
CVE-2023-46136LOW2.7
Werkzeug
2.3.7
fixed in 3.0.1, 2.3.8
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-8869LOW2.7
pip
23.2.1
fixed in 25.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-27281LOW2.7
rdoc
6.3.3
fixed in ~> 6.3.4, >= 6.3.4.1, ~> 6.4.1, >= 6.4.1.1, >= 6.5.1.1
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-43809LOW2.63
bundler
2.1.4
fixed in >= 2.2.33
2.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-3219LOW2.55
pip
23.2.1
fixed in 26.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-54314LOW2.38
thor
1.2.2
fixed in >= 1.4.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2023-46218LOW2.34
curl
8.2.1-r0
fixed in 8.5.0-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-46218LOW2.34
libcurl
8.2.1-r0
fixed in 8.5.0-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-41493LOW2.29
yard
0.9.34
fixed in >= 0.9.42
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-38546LOW2.22
curl
8.2.1-r0
fixed in 8.4.0-r0
6.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-38546LOW2.22
libcurl
8.2.1-r0
fixed in 8.4.0-r0
6.2%
Low-Moderate Risk
Post-Exploit
CVE-2024-27285LOW2.2
yard
0.9.34
fixed in >= 0.9.36
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-1703LOW1.99
pip
23.2.1
fixed in 26.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-4016LOW1.68
procps
3.3.17-r0
fixed in 3.3.17-r1
0.2%
Theoretical Threat
Post-Exploit
CVE-2023-5752LOW1.68
pip
23.2.1
fixed in 23.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-68121NONE0
stdlib
v1.21.1
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Not Applicable
CVE-2024-24790NONE0
stdlib
v1.21.1
fixed in 1.21.11, 1.22.4
2.0%
Low-Moderate Risk
Not Applicable
CVE-2023-29491NONE0
ncurses-libs
6.3_p20211120-r1
fixed in 6.3_p20211120-r2
0.9%
Theoretical Threat
Not Applicable
CVE-2023-29491NONE0
ncurses-terminfo-base
6.3_p20211120-r1
fixed in 6.3_p20211120-r2
0.9%
Theoretical Threat
Not Applicable
CVE-2023-39325NONE0
stdlib
v1.21.1
fixed in 1.20.10, 1.21.3
3.8%
Low-Moderate Risk
Not Applicable
CVE-2023-45283NONE0
stdlib
v1.21.1
fixed in 1.20.11, 1.21.4, 1.20.12, 1.21.5
2.8%
Low-Moderate Risk
Not Applicable
CVE-2023-45288NONE0
stdlib
v1.21.1
fixed in 1.21.9, 1.22.2
92.0%
Actively Exploited
Not Applicable
CVE-2024-34156NONE0
stdlib
v1.21.1
fixed in 1.22.7, 1.23.1
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-61726NONE0
stdlib
v1.21.1
fixed in 1.24.12, 1.25.6
0.8%
Theoretical Threat
Not Applicable
CVE-2025-61729NONE0
stdlib
v1.21.1
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25679NONE0
stdlib
v1.21.1
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Not Applicable
CVE-2026-32280NONE0
stdlib
v1.21.1
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-32281NONE0
stdlib
v1.21.1
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32283NONE0
stdlib
v1.21.1
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-33811NONE0
stdlib
v1.21.1
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Not Applicable
CVE-2026-33814NONE0
stdlib
v1.21.1
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39820NONE0
stdlib
v1.21.1
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39836NONE0
stdlib
v1.21.1
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2025-58183NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Not Applicable
CVE-2025-61728NONE0
stdlib
v1.21.1
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Not Applicable
CVE-2025-47907NONE0
stdlib
v1.21.1
fixed in 1.23.12, 1.24.6
0.3%
Theoretical Threat
Not Applicable
CVE-2025-4673NONE0
stdlib
v1.21.1
fixed in 1.23.10, 1.24.4
0.6%
Theoretical Threat
Not Applicable
CVE-2024-24785NONE0
stdlib
v1.21.1
fixed in 1.21.8, 1.22.1
0.8%
Theoretical Threat
Not Applicable
CVE-2025-47906NONE0
stdlib
v1.21.1
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Not Applicable
CVE-2025-61727NONE0
stdlib
v1.21.1
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32282NONE0
stdlib
v1.21.1
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-32289NONE0
stdlib
v1.21.1
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2024-24783NONE0
stdlib
v1.21.1
fixed in 1.21.8, 1.22.1
0.7%
Theoretical Threat
Not Applicable
CVE-2024-24791NONE0
stdlib
v1.21.1
fixed in 1.21.12, 1.22.5
1.4%
Low-Moderate Risk
Not Applicable
CVE-2024-34155NONE0
stdlib
v1.21.1
fixed in 1.22.7, 1.23.1
0.8%
Theoretical Threat
Not Applicable
CVE-2024-34158NONE0
stdlib
v1.21.1
fixed in 1.22.7, 1.23.1
1.0%
Low-Moderate Risk
Not Applicable
CVE-2024-45336NONE0
stdlib
v1.21.1
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.6%
Theoretical Threat
Not Applicable
CVE-2024-24789NONE0
stdlib
v1.21.1
fixed in 1.21.11, 1.22.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-32288NONE0
stdlib
v1.21.1
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2024-24784NONE0
stdlib
v1.21.1
fixed in 1.21.8, 1.22.1
1.0%
Low-Moderate Risk
Not Applicable
CVE-2025-22871NONE0
stdlib
v1.21.1
fixed in 1.23.8, 1.24.2
0.7%
Theoretical Threat
Not Applicable
CVE-2026-27142NONE0
stdlib
v1.21.1
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39826NONE0
stdlib
v1.21.1
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2023-39326NONE0
stdlib
v1.21.1
fixed in 1.20.12, 1.21.5
1.2%
Low-Moderate Risk
Not Applicable
CVE-2023-45284NONE0
stdlib
v1.21.1
fixed in 1.20.11, 1.21.4
0.9%
Theoretical Threat
Not Applicable
CVE-2023-45289NONE0
stdlib
v1.21.1
fixed in 1.21.8, 1.22.1
1.1%
Low-Moderate Risk
Not Applicable
CVE-2023-45290NONE0
stdlib
v1.21.1
fixed in 1.21.8, 1.22.1
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-22866NONE0
stdlib
v1.21.1
fixed in 1.22.12, 1.23.6, 1.24.0-rc.3
0.3%
Theoretical Threat
Not Applicable
CVE-2025-22873NONE0
stdlib
v1.21.1
fixed in 1.23.9, 1.24.3
0.2%
Theoretical Threat
Not Applicable
CVE-2025-47912NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Not Applicable
CVE-2025-58185NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Not Applicable
CVE-2025-58187NONE0
stdlib
v1.21.1
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Not Applicable
CVE-2025-58188NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.3%
Theoretical Threat
Not Applicable
CVE-2025-58189NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Not Applicable
CVE-2025-61723NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Not Applicable
CVE-2025-61724NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Not Applicable
CVE-2025-61725NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Not Applicable
CVE-2025-61730NONE0
stdlib
v1.21.1
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Not Applicable
CVE-2025-58186NONE0
stdlib
v1.21.1
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Not Applicable
CVE-2025-22870NONE0
stdlib
v1.21.1
fixed in 1.23.7, 1.24.1
0.4%
Theoretical Threat
Not Applicable
CVE-2024-45341NONE0
stdlib
v1.21.1
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27139NONE0
stdlib
v1.21.1
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Not Applicable
GHSA-537c-gmf6-5ccfNONE0
cryptography
41.0.3
fixed in 48.0.1
Not Applicable
GHSA-h4gh-qq45-vh27NONE0
cryptography
41.0.3
fixed in 43.0.1
Not Applicable
GHSA-v8gr-m533-ghj9NONE0
cryptography
41.0.3
fixed in 41.0.4
Not Applicable
CVE-2026-47240NONE0
net-imap
0.1.1
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
CVE-2026-47242NONE0
net-imap
0.1.1
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
CVE-2026-47241NONE0
net-imap
0.1.1
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
CVE-2026-47240NONE0
net-imap
0.3.7
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
CVE-2026-47242NONE0
net-imap
0.3.7
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
CVE-2026-47241NONE0
net-imap
0.3.7
fixed in ~> 0.5.15, >= 0.6.4.1
Not Applicable
GHSA-353f-x4gh-cqq8NONE0
nokogiri
1.14.5
fixed in >= 1.18.9
Not Applicable
GHSA-c4rq-3m3g-8wgxNONE0
nokogiri
1.14.5
fixed in >= 1.19.3
Not Applicable
GHSA-mrxw-mxhj-p664NONE0
nokogiri
1.14.5
fixed in >= 1.18.4
Not Applicable
GHSA-v2fc-qm4h-8hqvNONE0
nokogiri
1.14.5
fixed in >= 1.19.3
Not Applicable
GHSA-wx95-c6cv-8532NONE0
nokogiri
1.14.5
fixed in >= 1.19.1
Not Applicable
GHSA-xc9x-jj77-9p9jNONE0
nokogiri
1.14.5
fixed in ~> 1.15.6, >= 1.16.2
Not Applicable
GHSA-5w6v-399v-w3ccNONE0
nokogiri
1.14.5
fixed in >= 1.18.8
Not Applicable
GHSA-r95h-9x8f-r3f7NONE0
nokogiri
1.14.5
fixed in >= 1.16.5
Not Applicable
GHSA-vvfq-8hwr-qm4mNONE0
nokogiri
1.14.5
fixed in >= 1.18.3
Not Applicable
CVE-2026-47736NONE0
puma
6.3.0
fixed in ~> 7.2.1, >= 8.0.2
Not Applicable
CVE-2026-47737NONE0
puma
6.3.0
fixed in ~> 7.2.1, >= 8.0.2
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.21.1
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.21.1
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.21.1
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.21.1
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2025-0913NONE0
stdlib
v1.21.1
fixed in 1.23.10, 1.24.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.21.1
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.21.1
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable